Page 12 of 15 FirstFirst ... 21011121314 ... LastLast
Results 111 to 120 of 142

Thread: YOU THERE!! Malicios script installed as a DEB, please read!

  1. #111
    Join Date
    May 2006
    Location
    Amsterdam
    Beans
    1,731
    Distro
    Ubuntu 10.10 Maverick Meerkat

    Re: YOU THERE!! Malicios script installed as a DEB, please read!

    Dunno if someone looked further, but the script is HARMFULL, it contains an rm -f /*.* entry (which will match only files containing dots, so it will leave most binaries unharmed), but run as root that script could hose your system.

    I would remove it ASAP.
    Last edited by slakkie; December 9th, 2009 at 12:28 AM.
    Upgrade Ubuntu | Upgrade unsupported Ubuntu versions | Always backup | Howto upgrade flash
    Minimal CD install | Remove old kernels | My blog | Linux user #462801 | Conscience doth make cowards of us all. -- Shakespeare

  2. #112
    Join Date
    Nov 2006
    Location
    Belgium
    Beans
    3,025
    Distro
    Ubuntu 10.04 Lucid Lynx

    Re: YOU THERE!! Malicios script installed as a DEB, please read!

    Quote Originally Posted by slakkie View Post
    Dunno if someone looked further, but the script is HARMFULL, it contains an rm -f /*.* entry (which will match only files containing dots, so it will leave most binaries unharmed), but run as root that script could hose your system.

    I would remove it ASAP.
    see post 121

  3. #113
    Join Date
    May 2006
    Location
    Amsterdam
    Beans
    1,731
    Distro
    Ubuntu 10.10 Maverick Meerkat

    Re: YOU THERE!! Malicios script installed as a DEB, please read!

    Quote Originally Posted by koenn View Post
    see post 121
    Yes, i saw it after i posted.
    Upgrade Ubuntu | Upgrade unsupported Ubuntu versions | Always backup | Howto upgrade flash
    Minimal CD install | Remove old kernels | My blog | Linux user #462801 | Conscience doth make cowards of us all. -- Shakespeare

  4. #114
    Join Date
    Apr 2008
    Location
    California Republic
    Beans
    2,657

    Re: YOU THERE!! Malicios script installed as a DEB, please read!

    one of the first successful social engineering malware/botnet was reported here 4 hours ago.

    within 3 hours, a community member has created a Trojan Horse Detector.

    <3

    edit: let's assume the bad guy is also reading this thread.

    lets assume there are still folks out there affected by this, who will not have read this thread between now and the next time his botnets all 'calls home' for directions.

    my prediction of his next move in the wargame...

    he has his botnet all copy the binaries for wget and ping to "tegw" and "gnip" or something else to obfuscate the process name. the botnet no longer uses wget and ping. now it uses "tegw" and "gnip". so that the script posted above will no longer detect infection.

    in fact, we need to go ahead and assume the script above will no longer function as of 6 hours from now.

    posting this now as i think of our next move in this little ballet.
    Last edited by earthpigg; December 9th, 2009 at 12:49 AM.
    Semper Fi

    My Non-Ubuntu Blog.
    All posts by me are Public Domain.

  5. #115
    Join Date
    Dec 2007
    Beans
    124

    Exclamation Re: YOU THERE!! Malicios script installed as a DEB, please read!

    People, please report the issue to T35.com,

    abuse@t35.net

    We need this issue to be raised with the Host. here is an example of what I wrote:

    http://05748.t35.com/ is being used as a point to carry out malicious attacks Debian based Linux desktops...

    Please follow this thread where we are trying to resolve the issue and where I would request after you read the forum this account be promptly banned or the files removed.

    http://ubuntuforums.org/showthread.php?t=1349678

    The account also seems to be used for phishing
    Myself and others affected by the issue would appreciate a prompt response.

    Thank you

    -----------------------------------------------

    Please report back if you have done so so I may keep a tab on weather the complaint is being listened to. The only way we can truly remove this threat is to remove the threat from it's source.

    All help appreciated we need to kill this nonsense fast.


    E-mail = abuse@t35.net
    Last edited by dmizer; December 9th, 2009 at 11:56 AM. Reason: removed hyperlink

  6. #116
    Join Date
    Sep 2009
    Location
    Pennsylvania, USA
    Beans
    523
    Distro
    Ubuntu 20.04 Focal Fossa

    Re: YOU THERE!! Malicios script installed as a DEB, please read!

    Report this to the host
    Emailed them an abuse email, hopefully they read it.
    Last edited by teward; December 9th, 2009 at 01:22 AM.

  7. #117
    Join Date
    Feb 2009
    Location
    Southwest N.H.
    Beans
    352
    Distro
    Ubuntu 10.04 Lucid Lynx

    Re: YOU THERE!! Malicios script installed as a DEB, please read!

    Quote Originally Posted by earthpigg View Post
    one of the first successful social engineering malware/botnet was reported here 4 hours ago.

    within 3 hours, a community member has created a Trojan Horse Detector.

    <3

    edit: let's assume the bad guy is also reading this thread.

    lets assume there are still folks out there affected by this, who will not have read this thread between now and the next time his botnets all 'calls home' for directions.

    my prediction of his next move in the wargame...

    he has his botnet all copy the binaries for wget and ping to "tegw" and "gnip" or something else to obfuscate the process name. the botnet no longer uses wget and ping. now it uses "tegw" and "gnip". so that the script posted above will no longer detect infection.

    in fact, we need to go ahead and assume the script above will no longer function as of 6 hours from now.

    posting this now as i think of our next move in this little ballet.
    +1 earthpigg - This is another reason why Ubuntu is separate from the other "mainstream" operating systems. A similar attack on Windows would have resulted in a security update in the next "Update Tuesday," or whenever they decided to release a security update. The Forum has made it possible for word to get out almost immediately, and some solutions to be posted within a short time.

    I'm glad that I don't download (or use) screen savers, but I realize that the possibility now exists for .DEB packages to carry malicious code. Thanks to all who have posted this vital information.
    Dell XPS M1330, 2GB RAM, Intel Duo-Core Processor 1.5 GHz
    Ubuntu 11.04, Win XP in Virtual Box
    Proud (but inactive) Member of the Ubuntu Manual Team
    Registered Linux User #490335 / Registered Ubuntu User #27482

  8. #118
    scouser73's Avatar
    scouser73 is offline Iced Blended Vanilla Crème Ubuntu
    Join Date
    Mar 2008
    Beans
    1,663
    Distro
    Ubuntu 22.04 Jammy Jellyfish

    Wink Re: YOU THERE!! Malicios script installed as a DEB, please read!

    Quote Originally Posted by tacantara View Post
    +1 earthpigg - This is another reason why Ubuntu is separate from the other "mainstream" operating systems. A similar attack on Windows would have resulted in a security update in the next "Update Tuesday," or whenever they decided to release a security update. The Forum has made it possible for word to get out almost immediately, and some solutions to be posted within a short time.

    I'm glad that I don't download (or use) screen savers, but I realize that the possibility now exists for .DEB packages to carry malicious code. Thanks to all who have posted this vital information.
    +1, I don't download screen-savers myself but this issue has certainly made me think about the security of my computer.

  9. #119
    Join Date
    May 2009
    Beans
    1,934
    Distro
    Ubuntu Studio 9.10 Karmic Koala

    Re: YOU THERE!! Malicios script installed as a DEB, please read!

    Actually it would probably be up to the AV provider to catch and block the Trojan.

    Quote Originally Posted by scouser73 View Post
    +1, I don't download screen-savers myself but this issue has certainly made me think about the security of my computer.
    Same here. I always run NoScript in FF, but things like this could happen to me just as well, being I thought of gnome-look as being trusted. Other than themes from that site, all other software I get comes from known safe sites, such as cisco.netacad.net and mozilla.com.
    Last edited by running_rabbit07; December 9th, 2009 at 02:13 AM.

  10. #120
    Join Date
    Dec 2007
    Location
    Gainesville, Florida
    Beans
    Hidden!
    Distro
    Xubuntu 12.04 Precise Pangolin

    Re: YOU THERE!! Malicios script installed as a DEB, please read!

    Quote Originally Posted by conorsulli View Post
    People, please report the issue to T35.com,

    abuse@t35.net
    When I whois the site I get abuse@trouble-free.net

    05748.t35.com is hosted by Interserver, Inc

    if abuse@t35.net is the right one I'll email that too.

Page 12 of 15 FirstFirst ... 21011121314 ... LastLast

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •