Page 1 of 1

Virus Alerts

Posted: Sun Jun 27, 2004 6:42 pm
by CaboWabo
no viruses have ever came from or have infected bitPimps sites or servers - so no worry there.

however, users do like to give updates to each other on the latest possible viruses / attacks / etc. - we're all on the same team and nobody wants to see another go down.


latest virus alert:
There's a new virus making it's rounds that is infecting many un-suspecting victims. Most likely, many users won't know they've just been infected, and with this particular virus - it's being embedded in websites that users visit.

more info here:
http://www.msnbc.msn.com/id/5290386/

though they claim the virus has been contained to a degree - it hasn't.
many network administrators are not on their game and probably haven't protected themselves against this attack. I went to a German site today that had it and it's been out for almost a week now. So I know not all network admins have caught it yet.

here's what happens:
1.) you visit a site that is infected, could be any site for now - though most major creditable sites have protected themselves from it.
2.) if site is infected, you're secretly redirected to a site hosted in Russia, a Trojan is installed and hackers are able to copy usernames, passwords, credit card info, etc.

normally, while visiting the infected site, all the sudden a small popup or popunder window would materialize to the site installing the virus.

where I work, one of our servers was infected and effected all hosted sites on that server. after a few hours of me and MadSamoan trouble-shooting, we found what was causing it and nullified it.

those of you hosting or even you web surfers - be aware, it's still happening on a much smaller scale than earlier this week - but still a concern, it's by no means over as indicated by the German site (about micros) I visited today.

Posted: Sun Jun 27, 2004 6:58 pm
by betty.k
i'm curious, does my geocities site come under the overall protection of yahoo? or do i need to sort this stuff out myself?

Posted: Sun Jun 27, 2004 10:10 pm
by CaboWabo
no - you're fine - you don't need to do anything.
the only people that can and need to do something is people who "host" sites to the "public" or "locally / internally" and have access or are admins of a server.

basically, in the best laymen's terms I can put (and I suck at that);
the virus attacks the "web server" specifically IIS.
it tells the ISS web server to attach a "footer" to each page.
in that footer lies the JavaScript to direct you to the site hosted in Russia that installs and exploits the virus.

Posted: Mon Jun 28, 2004 8:50 pm
by sg219
So I don't have to worry about my dumb little site (sg219.com) either? Being I'm not a host. :???:

Posted: Mon Jun 28, 2004 9:35 pm
by synj
YOU are not the host the company you bought it form is the host

Posted: Tue Mar 21, 2006 7:02 pm
by CaboWabo
Be aware of what images you link to!
A lot of us have an image in our signatures.
Be careful what site's you are linking to, to get the image/s from.

Recently, one of our users had been linking to a site in his signature, that tried to infect users' computers with an Internet worm.
I'm certain the user had no idea as he had been linking to that image for some time in his signature, with no harmful results.

The link to the infected site in that users signature has been completely removed.

You should still make certain your virus definitions are up-to-date.

As always, just like the original post reads:
No viruses have ever came from or have infected bitPimps sites or servers - so no worry there.