AVAST forum hacked!

lusher

Member
Aug 17, 2007
86
0
0
According to http://www.wilderssecurity.com/showthread.php?t=183634

The AVAST forum was hacked and an iframe was inserted to some malicious site that was using a security exploit to install malware!

They pulled the forum offline now, but I was nearly hit, when I visited the forum yesteday, I got a message from my antivirus, I thought it was a FP , but just quarantined it anyway and thought nothing of it and then continued on my way. But I guess I was wrong!

I guess you must never let your guard down, even in 'trusted' sites. If you can't trust antivirus sites, who can you trust?

Oh yeah they pulled the forum down now. But it was on there for at least 24 hours...
 

jadinolf

Lifer
Oct 12, 1999
20,952
3
81
Yep.

It's back in business.

It's a forum I seldom visit because I never have problems with avast!
 

John

Moderator Emeritus<br>Elite Member
Oct 9, 1999
33,944
1
0
Maybe they'll stop using the unsecure phpBB and switch to vBulletin.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
non-Admin user accounts FTW! (again)


(sorry, could not stop myself)


That's pretty interesting, thanks for the heads-up lusher. Looking at the thread, I see the mediacount.net domain is involved, which probably means a combination StormWorm aka Zhelatin spambot infection, plus BraveSentry, plus a pr0n dialer (pic 1, pic 2).
 

Mem

Lifer
Apr 23, 2000
21,476
13
81
Their thread here on the subject apperantly Opera and Firefox owners were safe .


Basically something hacked the forum Simple Machines PHP software injecting an iframe tag in to each page as it was loaded, that page tried to infect users with the storm worm. Those with Firefox or Opera weren't vulnerable but those with IE or a clone were vulnerable to attack, however the web shield blocked that attack.

See this topic where I documented the problem, http://forum.avast.com/index.php?topic=30118.0.
.


 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Since the mediacount.net gang use batteries of exploits that adapt to what you're using, I wouldn't be too sure that FF/Opera users are arbitrarily immune Based on what I've observed from these guys in the past (<-- NSFW), my suggestions for Windows users would be to

1) eliminate all unnecessary software from your computers completely, including Sun Java, all versions. If you don't actually use something, get rid of it.

2) check your remaining software for known vulnerabilities at least monthly, using Secunia's Personal Software Inspector, Microsoft Update and Office Update.

3) use a non-Admin user account.

4) enable full Data Execution Prevention :camera:.

5) don't let anyone else onto your system's Adminstrator-class user accounts.

6) if you have Vista, leave User Account Control enabled.

7) Whether you routinely use Internet Explorer or not, upgrade to IE7 for better system security.


Now use any browser you prefer
 

surikas

Junior Member
Aug 7, 2007
15
0
0
Lol. Never thought such a site/forum could be hacked!
And mechBgon thanks for the tips!
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |