• The move to the new server is done. There are some software and database maintenance updates in process. This has us passing the hat around to help out. We appreciate any donations. Seriously, even a dollar helps. The payment page may be found here - https://www.audiokarma.org/support.html

Virus attack after log in

I will avoid using Chrome to prevent Google collecting data on my web use as long as I can. They get enough from my droid enabled phone.

Every web site you visit tracks data. It's unavoidable. It's part of being on the internet.

Chrome has the "sandboxing" referred to in the previous post built in. Chrome was designed, from its inception, for security.

Whatever browser you use is, obviously, entirely your choice. However, as far as we've been able to tell, nobody using Chrome has been bit.
 
Every web site you visit tracks data. It's unavoidable. It's part of being on the internet.

Chrome has the "sandboxing" referred to in the previous post built in. Chrome was designed, from its inception, for security.

Whatever browser you use is, obviously, entirely your choice. However, as far as we've been able to tell, nobody using Chrome has been bit.

I am using Chrome now until I can get my netbrick unbricked (DVD drive should arrive tomorrow from Newegg). Seems to be OK. I am proceeding with caution.
 
Chrome has NoScript type functionality built in and I think that's why its users have been immune. If you do allow Chrome to run Java applets, you are still subject to whatever vulnerabilities exist in your JRE. AFAIK, Chrome does not do anything to sandbox Java.
 
Yes - I imagine Google has the best info on where some of the crap originates from their ad network - making Chrome a safer bet :)

In any case I haven't seen anything lately with FF8 - but obviously others are still getting hit.
 
For anyone who's interested in Windows security in general, this presentation about Microsoft's investigation of Stuxnet might be an eye-opener.

Stuxnet is the malware/cyberweapon that destroyed centrifuges at Iranian uranium enrichment plants.

http://www.youtube.com/watch?v=fVNHX1Hrr6w

It's a long video but highlights are at 19:25, 32:19 and 38:30.
 
Just had avast give me the following two warnings one after the other while browsing pages at AK.
 

Attachments

  • v1.gif
    v1.gif
    63.8 KB · Views: 37
  • v2.gif
    v2.gif
    63.8 KB · Views: 34
I got hammered by something on AK too. I run Vista 64 and IE, always updated with the latest patches. Used the bleepingcomputer instructions to get running again. Found a website that recommended using JavaRa to get rid off all the different old versions of Java on my machine, then reinstalled the most current Java. The site said the older versions of Java contain numerous vulnerabilities. I never knew that my computer still had all those old versions still on it. After I cleaned off the old Javas, I ran Malware Bytes again and the Microsoft Security scan, seem to be running ok now.
 
TURN OFF JAVA - how hard is that to understand?

I don't think it's that hard to understand. But I also think a lot of folks are posting about their problems in this thread after having trouble and then finding the thread; so they didn't know ahead of time. I certainly didn't. Hindsight being 20/20, it's easy to say after the fact, but in reality, most people who are not having their PC melt down are not reading "my PC just melted down" threads.

It seems many boards that are running vBulletin software are having the same issue.

And many are not. This is not the only vBulletin-based discussion forum I frequent; and I've spoken to the other admins; they don't seem to be having the issue. So, although I'm sure as you say 'some' are, it can also be said that some are not.

I'm much calmer than I was several days ago when my netbook became a netbrick due to something that happened whilst perusing AK, and I do not blame AK in any way for it, the simple fact is that I've now spent several hundred dollars I did not have to spend to get my netbrick unbricked. I'm sorry if my tone up to now has expressed frustration, but frankly, I think I'm entitled to feel that way.
 
TURN OFF JAVA - how hard is that to understand?

It seems many boards that are running vBulletin software are having the same issue.

That would disable the AK chat, many games I play, and alot of website features. Not an option.
 
Just had an exploit blocked by Avast while browsing threads.

Object: www.ticheria.com/spotrjoin/...[>[embedded DeanEdwards.exe]]

Infection: JS:Dowloader-gen@bhv[Expl]

I thought I had turned off scripting a few days ago when someone posted instructions to find those controls in IE, but I'll have to go back and check. I dunno why people are getting snippy about that, some of us aren't that familiar with those controls and it's not like there's a big ol' button that says "turn off Java". It requires digging.
 
That would disable the AK chat, many games I play, and alot of website features. Not an option.

I think you're confusing Java with JavaScript. They're two completely different things.

I'm not familiar with AK chat, but all of the web-based chat I've seen uses JavaScript, not Java. Many of them are just browser-bases clients for IRC

Anyway, you don't have to disable either of them completely if you use something like NoScript. You can allow/disallow them on a domain by domain basis. i.e. you can allow audiokarma.org but disallow the domains that are hosting the evil banner ads.


Edit: Now I see that AK chat is indeed Java and uses an applet from addonchat.com. My advice is still to make sure your Java is up to date and use something like NoScript to selectively allow the domains you trust, e.g. addonchat.com.

This is what it looks like when you go to the chat with NoScript. Clicking on the snake gives the applet permission to run.

attachment.php
 

Attachments

  • noscript.jpg
    noscript.jpg
    18.3 KB · Views: 97
Last edited:
I've been watching this thread with interest, as it seems like this issue is wide spread, and hitting those who have taken some trouble to keep it from getting through. I'm sure the moderators and site admins are doing their best to figure out what the problem is, hopefully a solution can soon be realized. :thmbsp:

I've not seen anything here on Mac OS X or Windows (knock on wood), but I do run AdblockPlus on some of my machines and Flashblock on all of them. Most of my AK activity is done on a Macintosh, but I'm posting right now from a WinXP machine. Most of the time, I am using Google DNS or OpenDNS, both of which have some ability to block DNS lookups to sites known to be distributing malware.

A lot of the problem is that this sort of crap is only getting more sophisticated. After reading the diverse reports, I really think that the attack is multi-pronged...that it tries various things to infest your system until one finally works (if any do).

The very first thing to do is to update all of your software to its latest release. I wouldn't necessarily trust the auto-update mechanisms to do it, especially for Flash player. No piece of software should be overlooked, as many programs can plug into a web browser, even if it doesn't seem like there should be a logical reason for a program to do so. Any security settings the program offers should be looked over. (For example, did you know that Adobe Reader can and will execute JavaScript by default?) Every little bit, every hole that you can close, will help.

I would definitely also recommend looking at your browser settings or add-ons that disable things like scripting and Flash content.

Yet there is one more thing that I would recommend doing, especially if you're on Windows. Use the security model built into the operating system! By default, everyone who is running Windows on their system is basically a computer administrator and can do anything to their system--or have a malicious program do what it wants if it is run.

Make yourself a user account with limited rights (or use the "guest" account, possibly Windows XP and later only) and do your web browsing from there. On Windows 2000 and later, you could create such an account from the Control Panel and then run your browser software under it using the "Run As..." option. This may not stop the malware from posting its annoying messages, but it does significantly reduce the toehold it can get in your system when the user account your browser is running under simply doesn't have the rights to modify the operating system's core. And you can always trash the user account if something bad happens.
 
Here's something interesting about this. . part of what installed on my computer was a bitcoin miner... anything people can do to make a buck, and screw you for getting in the way.. .but screw them.. I'm clean again.. :thmbsp:
 
I'm on the computer at work because of it's high level of security, I'm afraid to open this site at home because of constant attacks. If I install Goggle Chrome as my browser on my Windows XP at home will that stop the Java attacks? I have Norton security at home and it has blocked everything so far but the attacks have changed, first it said website 9 virus or something like that and now the Java icon pops up in the lower right corner and i get warnings about some different virus.
 
I'm on the computer at work because of it's high level of security, I'm afraid to open this site at home because of constant attacks. If I install Goggle Chrome as my browser on my Windows XP at home will that stop the Java attacks? I have Norton security at home and it has blocked everything so far but the attacks have changed, first it said website 9 virus or something like that and now the Java icon pops up in the lower right corner and i get warnings about some different virus.

I have not had a problem since switching to Google Chrome.

If you are getting warnings, and the warnings are NOT coming from Norton Security but from some 'Java popup' then you are infected already; the virus is a 'fake antivirus' that is designed to fool people into thinking it's a real virus alert from a real anti-virus program.

The point of it all is to scare you; it tells you that you have all sorts of viruses on your PC and then offers to make them all go away if you pay a fee and click on the website they offer. However, you don't have the viruses they claim you have; you have the virus THEY GAVE YOU and you can't do anything with your PC anymore, you have to restore or install from scratch or do some very complicated removal procedures. It's frankly too complicated for a non computer expert; I've been trying to explain this to one of my relatives for a couple days now; they cannot comprehend that they could get a virus pop up warning and the warning IS the virus. As far as they are concerned, if it pops up and looks like their anti virus program, it IS their anti virus program. I'm trying desperately to convince them not to give their credit card number to the virus people in Russia who are running the scam; they're bound and determined to do it because they think their anti-virus program is telling them to. Argh.
 
No these are Norton alerts and when I bring up my security history it shows the blocked attack along with the IP addresses which I had shown in earlier posts. I have seen the things your talking about where they say "quick click here to remove 50 viruses that you have". I haven't seen that here on AK.
 
Make yourself a user account with limited rights (or use the "guest" account, possibly Windows XP and later only) and do your web browsing from there.

"guest" might actually be a bad idea, especially of you have other Windows computers on your network.

Until very recently there were bugs in the network printing software that gave "guest" the ability to write files ANYWHERE on a remote print host, including the system folders. Microsoft has patched a few different problems in this area but I wouldn't be surprised if others are still lurking.
 
Back
Top Bottom