Ubuntu Forums ubuntu.com - launchpad.net - ubuntu help  

Go Back   Ubuntu Forums > The Ubuntu Forum Community > Forum Community Discussions > The Community Cafe > Recurring Discussions
Register Reset Password Forum Help Forum Council Search Today's Posts Mark Forums Read

Recurring Discussions
Some discussions seem to come up over and over. This is a place for those sorts of topics.

 
Thread Tools Display Modes
Old December 8th, 2009   #1
pbrane
Quad Shot of Ubuntu
 
Join Date: Dec 2007
Location: Gainesville, FL
My beans are hidden!
Ubuntu 10.04 Lucid Lynx
Social engineering (trojan) via gnome-look.org

Quote:
Originally Posted by Enlightened Shadow View Post
The point is that I was dumb enough to think that Ubuntu was secure enough out here in the Linux wonderland that I love so much that I ended up on gnome-look downloading everything that looked cool without examining everything first.
Ubuntu is secure. We are the ones who make it un-secure by installing something using our root password. I didn't think about the fact that a .deb file from a trusted site would be malicious. Thanks for the lesson.
pbrane is offline   Reply With Quote
Old December 8th, 2009   #2
meho_r
Quad Shot of Ubuntu
 
meho_r's Avatar
 
Join Date: Apr 2007
Location: BiH
My beans are hidden!
Ubuntu 10.04 Lucid Lynx
Send a message via ICQ to meho_r Send a message via MSN to meho_r Send a message via Yahoo to meho_r
Re: YOU THERE!! Malicios script installed as a DEB, please read!

Quote:
Originally Posted by pbrane View Post
Ubuntu is secure. We are the ones who make it un-secure by installing something using our root password. I didn't think about the fact that a .deb file from a trusted site would be malicious. Thanks for the lesson.
You consider gnome-look a trusted website? Stick with official repos and PPAs and you'll be fine.
__________________
...
meho_r is offline   Reply With Quote
Old December 8th, 2009   #3
hwttdz
Dipped in Ubuntu
 
Join Date: Oct 2006
Location: New York
Beans: 635
Ubuntu 9.10 Karmic Koala
Re: YOU THERE!! Malicios script installed as a DEB, please read!

Aren't PPA's only as far as you trust the owner, as in anyone can get one.
__________________
http://astoryworthtelling.wordpress.com/
Linux viruses list: https://help.ubuntu.com/community/Linuxvirus
If you would like a further response please pm me - I don't subscribe.
hwttdz is offline   Reply With Quote
Old December 8th, 2009   #4
pbrane
Quad Shot of Ubuntu
 
Join Date: Dec 2007
Location: Gainesville, FL
My beans are hidden!
Ubuntu 10.04 Lucid Lynx
Re: YOU THERE!! Malicios script installed as a DEB, please read!

Quote:
Originally Posted by meho_r View Post
You consider gnome-look a trusted website? Stick with official repos and PPAs and you'll be fine.
I didn't say I considered it a trusted site. I just meant it is a good idea not to assume it's safe to install debs. I think your advise is good.
pbrane is offline   Reply With Quote
Old December 8th, 2009   #5
MC707
A Carafe of Ubuntu
 
MC707's Avatar
 
Join Date: Jan 2009
Location: Quito, Ecuador Beans: 923
My beans are hidden!
Ubuntu 10.04 Lucid Lynx
Send a message via AIM to MC707 Send a message via MSN to MC707 Send a message via Yahoo to MC707
Re: YOU THERE!! Malicios script installed as a DEB, please read!

Muahaha could this be the first semi-massive Linux virus/trojan? Either way, I agree with pbrane, even for windows to a certain extent (at least in my PC):
Quote:
Originally Posted by pbrane View Post
Ubuntu is secure. We are the ones who make it un-secure by installing something using our root password. I didn't think about the fact that a .deb file from a trusted site would be malicious. Thanks for the lesson.
__________________
"The funny thing about common sense is that it is not that common." -A person with common sense
Download your favorite game soundtrack!
MC707 is offline   Reply With Quote
Old December 8th, 2009   #6
NoaHall
May the Ubuntu Be With You!
 
Join Date: Mar 2009
Beans: 1,562
Ubuntu 9.10 Karmic Koala
Social engineering (trojan) via gnome-look.org

Read this thread - http://ubuntuforums.org/showthread.php?t=1349678

Basically, there's someone who put a .deb on gnome-look, users installed it, and now he's hacked their systems to perform a DDoS attack.

Lesson : Don't install .deb files from unreliable sources. We have repos for a reason. Use them. And for crying out loud, screensavers don't use .deb files.

Oh, and here's the fix(in case someone browsing might want to check)
Code:
sudo rm -f /usr/bin/Auto.bash /usr/bin/run.bash /etc/profile.d/gnome.sh index.php run.bash && sudo dpkg -r app5552

Last edited by NoaHall; December 8th, 2009 at 06:00 PM..
NoaHall is offline   Reply With Quote
Old December 8th, 2009   #7
dragos240
Extra Foam Sugar Free Ubuntu
 
dragos240's Avatar
 
Join Date: Jul 2008
Location: GONE
Beans: 796
Ubuntu 10.04 Lucid Lynx
Re: To those of you who are unaware

Well crap!

EDIT: It's been removed.
__________________
I came, I saw, I overreacted, I returned. I left.
My blog.
NOTE TO CAFE USERS! If you see me, I'm not back. I'm visiting. To check your sanity.
dragos240 is offline   Reply With Quote
Old December 8th, 2009   #8
conorsulli
A Carafe of Ubuntu
 
conorsulli's Avatar
 
Join Date: Dec 2007
Beans: 107
Re: YOU THERE!! Malicios script installed as a DEB, please read!

Quote:
Originally Posted by running_rabbit07 View Post
This is what this link (http://05748.t35.com/) says when opened via FF.
well I dont want a congrats...

Keep viruses in the windows world

Thank you

Last edited by dmizer; December 9th, 2009 at 05:50 AM.. Reason: removed hyperlink
conorsulli is offline   Reply With Quote
Old December 8th, 2009   #9
doas777
Iced Blended Vanilla Crème Ubuntu
 
doas777's Avatar
 
Join Date: Dec 2007
Location: The last place I look
My beans are hidden!
Ubuntu 9.10 Karmic Koala
Re: YOU THERE!! Malicios script installed as a DEB, please read!

Quote:
Originally Posted by conorsulli View Post
well I dont want a congrats...

Keep viruses in the windows world

Thank you
just a point of terminology (not trying to be a jerk), but this is not a "virus". viruses spread, and exploit vulns in applications to perform their dirtywork.
what yo have there is a trojan.

sorry, it's jsut that everytime the word "virus" is used on this forum, it gets ugly from there. everyone would alternate between telling you that your issue never happened, or that you are the problem (neither of which is constructive.). i hate those threads...zealots vs zealots
doas777 is offline   Reply With Quote
Old December 8th, 2009   #10
running_rabbit07
Chocolate Ubuntu Mocha Blend
 
Join Date: May 2009
Beans: 1,934
Ubuntu Studio 9.10 Karmic Koala
Re: YOU THERE!! Malicios script installed as a DEB, please read!

Quote:
Originally Posted by doas777 View Post
just a point of terminology (not trying to be a jerk), but this is not a "virus". viruses spread, and exploit vulns in applications to perform their dirtywork.
what yo have there is a trojan.

sorry, it's jsut that everytime the word "virus" is used on this forum, it gets ugly from there. everyone would alternate between telling you that your issue never happened, or that you are the problem (neither of which is constructive.). i hate those threads...zealots vs zealots
Do you think the referenced link could have a negative effect when visited via FF? I've been watching conky since the visit and haven't seen anything new happening, but I am not the brightest at spotting orc mischief in Linux, yet.
running_rabbit07 is offline   Reply With Quote

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 10:32 PM.


vBulletin ©2000 - 2010, Jelsoft Enterprises Ltd. Ubuntu Logo, Ubuntu and Canonical © Canonical Ltd. Tango Icons © Tango Desktop Project. bilberry