Stories - possible virus

bella (imported)
Articles: 0
Posts: 853
Joined: Sat Jan 26, 2002 2:55 pm

Posting Rank

Stories - possible virus

Post by bella (imported) »

I am getting this error reported on the story site

"eunuchworld.org/s_index.php";"Exploit Blackhole Exploit Kit (type 2704)";"Object was blocked"

Blackhole Exploit Kit

AVG Detects This Highly Active Webthreat And Its 157 Known Variants.

The most popular variants of Blackhole Exploit Kit are Blackhole Exploit Kit (type 2704), Blackhole Exploit Kit (type 2292), Blackhole Exploit Kit (type 2709) more ...

What is Blackhole Exploit Kit?

Blackhole Exploit Kit is caused by a code that can be hacked into a webpage. When you browse to a webpage with Blackhole Exploit Kit, it will identify and make use of the vulnerabilities in your internet browser/plugins and force adware, phishing programs or any other type of fraudulent software to be installed on your device.
Riverwind (imported)
Articles: 0
Posts: 7558
Joined: Sun Dec 30, 2001 1:58 pm

Posting Rank

Re: Stories - possible virus

Post by Riverwind (imported) »

bella (imported) wrote: Tue May 28, 2013 12:26 pm I am getting this error reported on the story site

"eunuchworld.org/s_index.php";"Exploit Blackhole Exploit Kit (type 2704)";"Object was blocked"

Blackhole Exploit Kit

AVG Detects This Highly Active Webthreat And Its 157 Known Variants.

The most popular variants of Blackhole Exploit Kit are Blackhole Exploit Kit (type 2704), Blackhole Exploit Kit (type 2292), Blackhole Exploit Kit (type 2709) more ...

What is Blackhole Exploit Kit?

Blackhole Exploit Kit is caused by a code that can be hacked into a webpage. When you browse to a webpage with Blackhole Exploit Kit, it will identify and make use of the vulnerabilities in your internet browser/plugins and force adware, phishing programs or any other type of fraudulent software to be installed on your device.

I believe its being looked at, Thanks,

River
Paolo
Articles: 0
Posts: 9709
Joined: Wed May 16, 2001 8:53 am

Posting Rank

Re: Stories - possible virus

Post by Paolo »

The site wanted to execute a script from millszimer.co.il, which I have no idea what it is.

A Google search yields what looks like sites with descriptions in Arabic characters.

It's gone now.

Note: Israel? Have we somehow pissed off the Jews now???
talula
Articles: 0
Posts: 940
Joined: Tue Jun 03, 2025 7:42 am

Posting Rank

Re: Stories - possible virus

Post by talula »

The bastards! Yes. There is something. I'm testing. It might be something wierd.

Done with testing. I can trace it but eunuchworld is going down for a couple of days. Sorry.
Paolo
Articles: 0
Posts: 9709
Joined: Wed May 16, 2001 8:53 am

Posting Rank

Re: Stories - possible virus

Post by Paolo »

Dammit anyway.

Someone in Israel is pissed at us.
Cainanite (imported)
Articles: 0
Posts: 1069
Joined: Sun Apr 24, 2011 12:54 am

Posting Rank

Re: Stories - possible virus

Post by Cainanite (imported) »

Paolo wrote: Tue May 28, 2013 4:38 pm Dammit anyway.

Someone in Israel is pissed at us.

Was it my post on circumcision restoration? 😄

Uhh.... Oops.
talula
Articles: 0
Posts: 940
Joined: Tue Jun 03, 2025 7:42 am

Posting Rank

Re: Stories - possible virus

Post by talula »

Yep. That was it hehehe. Eunuchworld.org is officially down for maintenance.
speedvogel (imported)
Articles: 0
Posts: 202
Joined: Sun Aug 24, 2008 9:46 am

Posting Rank

Re: Stories - possible virus

Post by speedvogel (imported) »

talula wrote: Tue May 28, 2013 6:04 pm Yep. That was it hehehe. Eunuchworld.org is officially down for maintenance.

Good catch. It gives me a warm fuzzy to know that you devote your time to caring for the flock.

Speed
Prudence (imported)
Articles: 0
Posts: 256
Joined: Fri Apr 13, 2007 5:29 pm

Posting Rank

Re: Stories - possible virus

Post by Prudence (imported) »

Try using NMAP or ZENMAP (Google those if you are unfamiliar with them) -- these tools might be able to tell you what plugins/components of the web server are open for exploits.

Also, if you are using any flavor of "the-thing-that-should-not-be" (ie: Java) make sure to un-install any old versions (no matter what it breaks -- uninstall them, period) and install the very latest version. Even versions of Java that are just a few months old are so full of holes you might as well put the Admin Password on your Home Page...
talula
Articles: 0
Posts: 940
Joined: Tue Jun 03, 2025 7:42 am

Posting Rank

Re: Stories - possible virus

Post by talula »

Prudence (imported) wrote: Tue May 28, 2013 10:18 pm Try using NMAP or ZENMAP (Google those if you are unfamiliar with them) -- these tools might be able to tell you what plugins/components of the web server are open for exploits.

No. I use them every day of the week. You use it and let me know in private if you find something I missed. 4 eyes are better than 2.
Prudence (imported) wrote: Tue May 28, 2013 10:18 pm Also, if you are using any flavor of "the-thing-that-should-not-be" (ie: Java) make sure to un-install any old versions (no matter what it breaks -- uninstall them, period) and install the very latest version. Even versions of Java that are just a few months old are so full of holes you might as well put the Admin Password on your Home Page...

We don't run a tomcat server. There are no java packages installed.

I spent most of the day going through the logs and tightening down some aspects. The damage isn't really that bad but it is enough I'll be doing some writing for the index page. Good news is though that within minutes of tightening stuff down I caught someone trying to break in and is now banned:

person: Evgeniy German

address: 30 Smirnova Street, Tomsk, Russia

phone: +7 3822 76-53-20

mnt-by: TOMLINE-MNT

Lessoned learned? Read your logs 24 hours a day, 7 days a week and never sleep. hehehehe.
Post Reply

Return to “Archive Technical Help”