Page 14 of 15 FirstFirst ... 412131415 LastLast
Results 131 to 140 of 142

Thread: YOU THERE!! Malicios script installed as a DEB, please read!

  1. #131
    Join Date
    Dec 2007
    Beans
    124

    Re: YOU THERE!! Malicios script installed as a DEB, please read!

    Thanks to all the people that shared their knowledge and created scripts advice etc, Just goes to show how quickly a rogue can be squished here.

    I'm off to bed now (it's like 6.05am here) but I'll check back in the morning to see if any response was received from t35.com. Hopefully the whole thing just died away.

    Talk Later

    Conor.

  2. #132
    NoaHall is offline May the Ubuntu Be With You!
    Join Date
    Mar 2009
    Beans
    1,562
    Distro
    Ubuntu 9.10 Karmic Koala

    Re: YOU THERE!! Malicios script installed as a DEB, please read!

    Quote Originally Posted by witeshark17 View Post
    Has everyone affected removed this script and sorted the issue?
    Yes, as far as I can tell. IF there are any more problems, we'll get them fixed as soon as possible

  3. #133
    Join Date
    Oct 2009
    Location
    North Carolina US
    Beans
    54
    Distro
    Ubuntu 11.04 Natty Narwhal

    Re: YOU THERE!! Malicios script installed as a DEB, please read!

    I was the first one to download this thing and install it. I have obviously been following this thread. I went to bed around 8:00 PM est. Has their been anything new figured out that I should remove from my computer since then?

    I have already run this:
    sudo rm -f /usr/bin/Auto.bash /usr/bin/run.bash /etc/profile.d/gnome.sh index.php run.bash && sudo dpkg -r app5552
    Another day has passed and I'm just a little bit smarter.

  4. #134
    Join Date
    Oct 2009
    Location
    North Carolina US
    Beans
    54
    Distro
    Ubuntu 11.04 Natty Narwhal

    Re: YOU THERE!! Malicios script installed as a DEB, please read!

    Guys I just attempted run the above code a second time and I received this warning message:

    dpkg: warning: ignoring request to remove app5552, only the config
    files of which are on the system. Use --purge to remove them too.

    Should I purge them or just leave it alone?
    Another day has passed and I'm just a little bit smarter.

  5. #135
    Join Date
    Feb 2007
    Location
    Romania
    Beans
    Hidden!
    Distro
    Ubuntu Development Release

    Re: YOU THERE!! Malicios script installed as a DEB, please read!

    Quote Originally Posted by Enlightened Shadow View Post
    Guys I just attempted run the above code a second time and I received this warning message:

    dpkg: warning: ignoring request to remove app5552, only the config
    files of which are on the system. Use --purge to remove them too.

    Should I purge them or just leave it alone?
    Well, the package doesn't install any config files, but just in case run:
    Code:
    sudo dpkg -P app5552
    for more info see:
    Code:
    man dpkg | less --pattern\= "--purge"
    Last edited by sisco311; December 9th, 2009 at 02:57 PM. Reason: command fixed

  6. #136
    Join Date
    Oct 2009
    Location
    North Carolina US
    Beans
    54
    Distro
    Ubuntu 11.04 Natty Narwhal

    Re: YOU THERE!! Malicios script installed as a DEB, please read!

    OK I went ahead and purged the thing. It wouldn't let me do both -r and -P at the same time because of conflicts, which makes sense seeing how they do the same thing except Purge is more thorough.
    Another day has passed and I'm just a little bit smarter.

  7. #137
    Join Date
    Dec 2007
    Location
    The last place I look
    Beans
    Hidden!
    Distro
    Ubuntu 10.04 Lucid Lynx

    Re: YOU THERE!! Malicios script installed as a DEB, please read!

    Quote Originally Posted by 3rdalbum View Post
    I'm wondering whether this trojan has been added to any anti-virus definitions for (say) AVG... it would be interesting to see if the AV vendors have the same response time on Linux as they do on Windows!

    Also, about the firewall: The script tells Wget to request a page on port 80. All your web page requests come through port 80, which I imagine is not blocked. Even if your firewall can block specific applications, I'd be very surprised if you haven't already unblocked Wget.

    And I'd like to correct myself. I said "A firewall would not do diddly squat". I meant to say "A firewall would do diddly squat".
    what would you detect? this file has no disctict executable footprint since it itself is not executable. it just uses parts of the OS to do it's job. I think it would take behavioral detection to turn it up, and any app that uses wget on a timed loop would probably be detected as well.

  8. #138
    Join Date
    Jun 2007
    Location
    North London; England
    Beans
    697
    Distro
    Ubuntu 9.10 Karmic Koala

    Re: YOU THERE!! Malicios script installed as a DEB, please read!

    Its a scary thought that as the script could of been updated to do anything bad at any time , i think the rm command was done wrong on purpose just to prove a point.

    if he had included a screen saver with this file then people wouldnt of noticed atal, then he could of just changed the download script in 5 or 6 months, causing problems , by which time most people would of forgot about the screen saver they installed.

    even if the update he did didnt cause problems on the computer, he could of used it to do illegal things droping users in the ****.

    he could of used it to add a user to the system, and install ssh.
    Desktop:i7 875k|4gb OCZ platinum ddr3 2000|Evga P55 LE mobo|OCZ RevoDrive 50gb|ATI 5850 Black Edition|Silverstone FT02|corsair tx650
    Portable: 13" Macbook Pro 2.8ghz i7 16gb RAM | Asus EEE TF101 | Samsung Galaxy S2

  9. #139
    Join Date
    Aug 2009
    Location
    Bogotá, Colombia
    Beans
    227
    Distro
    Kubuntu Development Release

    Re: YOU THERE!! Malicios script installed as a DEB, please read!

    Same attack with "Ninja Theme" from gnome-look.org, the bad boys seems to keep trying...

    Theme already delete, please verify the "includes files" tab when you are going to install an untrusted deb.

  10. #140
    NoaHall is offline May the Ubuntu Be With You!
    Join Date
    Mar 2009
    Beans
    1,562
    Distro
    Ubuntu 9.10 Karmic Koala

    Re: YOU THERE!! Malicios script installed as a DEB, please read!

    Quote Originally Posted by Enlightened Shadow View Post
    Guys I just attempted run the above code a second time and I received this warning message:

    dpkg: warning: ignoring request to remove app5552, only the config
    files of which are on the system. Use --purge to remove them too.

    Should I purge them or just leave it alone?
    It should be fine. All fixed now

Page 14 of 15 FirstFirst ... 412131415 LastLast

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •