English Amiga Board    


Go Back   English Amiga Board > » Main > Amiga scene

Closed Thread
 
Thread Tools
Old 11 May 2012, 23:34   #1
FOL
UltimateAmiga Ruler
 
FOL's Avatar
 
Join Date: Nov 2006
Location: Wales
Age: 34
Posts: 3,850
Send a message via MSN to FOL Send a message via Skype™ to FOL
Amibay Hacked?

It appears amibay has been hacked, anyone going there should scan for malware / viruses.

Web Attack: Malicious Website Accessed dsyoylhbg.usa.cc (146.185.255.235, 80),dsyoylhbg.usa.cc/d/404.php?go=1

Im guessing they have worked out by now its been hacked.
__________________
Quote:
Resolute and Industrious
Grand ruler of the yellow people and the Ultimate Amiga Empire
__________________
Customer Help & Support: http://www.amigakit.com/help

www.amigakit.com
- the Amiga store

new products
FOL is offline  
Old 12 May 2012, 00:07   #2
scrappysphinx
Registered User
 
scrappysphinx's Avatar
 
Join Date: Jan 2008
Location: Nottingham
Age: 28
Posts: 391
You can still access Amibay if you go directly to a thread or post and then click the new posts button but the main homepage has been attacked and contains some redirct or java exploit or something along those lines.

Click here to read the thread
__________________
Me & My First Child.
Theo McLaughlin Born: 02:53am 10/09/08.
scrappysphinx is offline  
Old 12 May 2012, 01:08   #3
rockape
Registered User
 
rockape's Avatar
 
Join Date: Feb 2010
Location: Lincolnshire, England.
Age: 64
Posts: 84
Exclamation "Amibay Hacked Beware ! "

Hi,

I tried logging into Amibay using an A1200 and got:

"Unable to add cookies, header already sent.
File: /homepages/1/d277227762/htdocs/amibay/forum/index.php(1) : eval()'d code
Line: 7"

Regards, Michael

aka rockape
rockape is offline  
Old 12 May 2012, 01:13   #4
jabsy
Yeah Hup!
 
jabsy's Avatar
 
Join Date: May 2006
Location: Australia
Age: 43
Posts: 327
I just checked and NOD32 popped up with:

12/05/2012 8:42:35 AM HTTP filter file http://ysavlxaw.usa.cc/main.php?page=c69bd02e93e6957c JS/Kryptik.NN trojan connection terminated - quarantined Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.

Bastards.
__________________
Love kills your mind
Love kills your time
Love kills the film on your eyes
jabsy is offline  
Old 12 May 2012, 01:33   #5
prowler
Global Moderator
 
prowler's Avatar
 
Join Date: Aug 2008
Location: Sidcup, England
Posts: 8,696
@rockape, jabsy:

There was already an EAB thread started on this subject. I have merged them.
prowler is offline  
Old 12 May 2012, 09:55   #6
I.Did
in retromode
 
Join Date: Feb 2012
Location: Scandinavia
Posts: 72
Quote:
Originally Posted by scrappysphinx View Post
You can still access Amibay if you go directly to a thread or post and then click the new posts button but the main homepage has been attacked and contains some redirct or java exploit or something along those lines.

Click here to read the thread
I'm not a member over at Amibay. What I get using your link is the reg. screen. Guess they are still working on it, the poor guys
__________________
Config:

5 x A500
1 x A1011
3 x A1200
2 x A1200 KS 3.0 w/ 84 Mb HD and Blizzard 1230 Mk-IV w/ 128 Mb RAM the other w/Blizzard 1230 Mk-IV w/ 8 Mb RAM.
1 x A2000
Several 4 and 8 GB SanDisk CF Cards.
Several other external FD's, both 3.5" and 5.25"
Some 5500+ floppy's for Amiga.

3 x C=128D.
2 x C=128 w/ 2 x 1571.
3 x C64 w/ 4 x 1541.
1 x C=1581
Some 3900+ floppy's for C=64/C=128.

Collecting stuff for an A1000 now...

Who said Commodore-Fan-Boy? ... I'll punch your nose !!
I.Did is offline  
Old 12 May 2012, 13:16   #7
ElectroBlaster
Junior Member
 
ElectroBlaster's Avatar
 
Join Date: Mar 2002
Location: Exeter, Devon, UK
Age: 38
Posts: 1,174
Send a message via ICQ to ElectroBlaster
Brilliant! So thats where my little bug came from! ZoneAlarm came up with this:

Exploit.JS.Pdfka.fof

This happend late last night/early hours of the morning and mainly because I tend to leave the machine running with certain pages up and just forget about it if im busy.

Why would anyone hack Amibay??? disgruntled kid? somebody jealous?
__________________
A1200 3.1roms WB3.1 CF IDE 200w psu Catweasel Mk4 Twin Sid Chips Registered WHDLoad
ElectroBlaster is offline  
Old 12 May 2012, 14:50   #8
DDNI
Targ Explorer
 
DDNI's Avatar
 
Join Date: Mar 2006
Location: Northern Ireland
Age: 38
Posts: 4,534
Send a message via ICQ to DDNI Send a message via MSN to DDNI
Quote:
Originally Posted by ElectroBlaster View Post
Brilliant! So thats where my little bug came from! ZoneAlarm came up with this:

Exploit.JS.Pdfka.fof

This happend late last night/early hours of the morning and mainly because I tend to leave the machine running with certain pages up and just forget about it if im busy.

Why would anyone hack Amibay??? disgruntled kid? somebody jealous?
Hmmm top three suspects.

Bill McEwan
Hans (doomy)
Some moobunny moron

Outside guess CUSA
__________________
A1200D Blizzard 1230 MKIV 50Mhz 32mb RAM, 4GB HDD, CWB Full.
AmigaOne X1000

_/-| |\/| | (-, |-\_
DDNI is offline  
Old 12 May 2012, 15:46   #9
Leffmann
Leffmann with two n's
 
Leffmann's Avatar
 
Join Date: Jul 2008
Location: Sweden
Posts: 1,189
It's a widespread attack all over the Internet, Amibay hasn't been specifically targetted.
Leffmann is offline  
Old 12 May 2012, 15:46   #10
desiv
Registered User
 
Join Date: Oct 2009
Location: Salem, OR
Posts: 849
Quote:
Originally Posted by ElectroBlaster View Post
Why would anyone hack Amibay??? disgruntled kid? somebody jealous?
Apparently it's not just Amibay and it's not just Amiga sites...

Life on the Internet....

desiv
(Actually, life on the Internet is generally very kual; this just happens..)
desiv is offline  
Old 12 May 2012, 17:34   #11
discomeats
Just add brown sauce.
 
discomeats's Avatar
 
Join Date: May 2008
Location: North East Englandland
Posts: 164
Quote:
Originally Posted by DDNI View Post
Hmmm top three suspects.

Bill McEwan
Hans (doomy)
Some moobunny moron

Outside guess CUSA
But surely Doomy would use a non detectable milspec attack using nasa gear
__________________
Pump it full of strawberry puree, that'll show it!
discomeats is offline  
Old 12 May 2012, 18:43   #12
1time
Amiga Lover
 
1time's Avatar
 
Join Date: Jan 2010
Location: Stockholm / Sweden
Age: 35
Posts: 475
http://www.classicamiga.com/ is down.

Getting
Exploit:Java/CVE-2012-0507.BB
Exploit:JS/BLACOLE.DG
1time is offline  
Old 12 May 2012, 18:46   #13
spannernick
Zone Friend
 
spannernick's Avatar
 
Join Date: Aug 2004
Location: IN THE CLOULD
Posts: 646
If you have tapatalk on you phone you can access the site fine ..
spannernick is offline  
Old 12 May 2012, 19:27   #14
AmiNeo
AmiSonicNeo
 
AmiNeo's Avatar
 
Join Date: Feb 2012
Location: Wallasey, UK
Posts: 7
AMIBAY down?

Sorry to post this here guys but since many of Amibays members are present here I have only this site as a means of contacting people.


It appears that Amibay has disappeared from the interwebs


www.amibay.com


Anyone know what's up? It has been down since this morning and now appears to have disappeared altogether.

Last edited by AmiNeo; 12 May 2012 at 19:33.
AmiNeo is offline  
Old 12 May 2012, 19:40   #15
lilalurl
T32
 
lilalurl's Avatar
 
Join Date: Aug 2001
Location: France
Age: 33
Posts: 2,123
Send a message via ICQ to lilalurl
Hacked it seems:
http://eab.abime.net/showthread.php?t=64277
__________________
"Dancing plants are immortal" (s2325)
"I don't want my drumsticks and dragon steaks to vanish" (Thorham)
lilalurl is offline  
Old 12 May 2012, 19:46   #16
johnim
Amibay Mod/Staff
 
johnim's Avatar
 
Join Date: Jun 2010
Location: birmingham uk
Age: 37
Posts: 807
not down just use a link from thead
http://www.amibay.com/showthread.php?t=29442

not the main page
__________________
A1200T 1d4:blizzard 1260/50/192mb/scsi kit:mediator 1200:radeon 9250:sb128:100mb net:spider usb clone:fastata-iv:amiga to ps2 mouse:80gb hd:zip100 ide:a4000 keyboard
A1200D 1d4:blizzard1230mk4/50/scsikit/128mb:indy mk ii:fastata mk ii:40gb
A1200 rev 2b*2 x A1200 1d4*A1200 1b*A600 2mb 4gb*A500*cd32 x2*cdtv=
sfs cf guide http://eab.abime.net/showthread.php?t=61048 cwb3.9 guidehttp://eab.abime.net/showthread.php?t=61180
johnim is offline  
Old 12 May 2012, 19:46   #17
fitzsteve
Professional slacker!
 
fitzsteve's Avatar
 
Join Date: Jul 2009
Location: Kent, UK
Age: 33
Posts: 4,727
Send a message via MSN to fitzsteve
Don't click on the link in post 1 as the index page is forwarding to a virus ridden link, you can still access Amibay via all other url's, just the index page is affected by this hack.

This link will give you new posts:

http://www.amibay.com/search.php?searchid=2178832

Steve.
__________________
A500+ 4mb SupraRam500xp/SCSI-IDE - A600, ACA630/64, A604, IndiECS - A4000D, Mirage Pro Tower, CSPPC 060/330, Mediator, DenebUSB, ZorRam - A4000D, WarpEngine040, Toccata, DenebUSB, CV64/3D - A1200D, ACA1232/33, IndiAGA MkII - A1200D Magic Pack +ACA1220 - A1200T, 060/PPC330, G-RexPCI, SubwayUSB - CD32 + SX32, IndiMkII - uA1 800mhz My Retr0 Blog
fitzsteve is offline  
Old 12 May 2012, 19:49   #18
keitha1200
Registered User
 
Join Date: Feb 2012
Location: Tayside
Posts: 181
Noticed that lastnight Gee I can think of hundreds of other sites which deserved to be hacked! but amibay!!!

Suspects:

Crayons USA lack the technical knowledge!
Bill's too busy cutting out coupons from the newspaper
The others??? watching the Disney channel?

Last edited by keitha1200; 12 May 2012 at 19:59. Reason: didn't realise it was a www attack
keitha1200 is offline  
Old 12 May 2012, 19:50   #19
johnim
Amibay Mod/Staff
 
johnim's Avatar
 
Join Date: Jun 2010
Location: birmingham uk
Age: 37
Posts: 807
Sadly a lot of sites have been targeted over the last few days - those that are running VB forum / Joomla and other CMS systems

The attack was at a site root level and has modified some of the templates of the site (namely the index.html) and injects a small line of code that uses a Jscript redirect to the place you were sent.

Please be advised my friend that this site attempts to install MalWare onto ones Windows PC.

Please check your system, and ensure that your JavaScript settings are secure.
__________________
A1200T 1d4:blizzard 1260/50/192mb/scsi kit:mediator 1200:radeon 9250:sb128:100mb net:spider usb clone:fastata-iv:amiga to ps2 mouse:80gb hd:zip100 ide:a4000 keyboard
A1200D 1d4:blizzard1230mk4/50/scsikit/128mb:indy mk ii:fastata mk ii:40gb
A1200 rev 2b*2 x A1200 1d4*A1200 1b*A600 2mb 4gb*A500*cd32 x2*cdtv=
sfs cf guide http://eab.abime.net/showthread.php?t=61048 cwb3.9 guidehttp://eab.abime.net/showthread.php?t=61180
johnim is offline  
Old 12 May 2012, 20:10   #20
Jimbo
Registered User
 
Jimbo's Avatar
 
Join Date: Jul 2006
Location: Colchester Essex
Age: 33
Posts: 822
Quote:
Originally Posted by johnim View Post
Sadly a lot of sites have been targeted over the last few days - those that are running VB forum / Joomla and other CMS systems

The attack was at a site root level and has modified some of the templates of the site (namely the index.html) and injects a small line of code that uses a Jscript redirect to the place you were sent.

Please be advised my friend that this site attempts to install MalWare onto ones Windows PC.

Please check your system, and ensure that your JavaScript settings are secure.
Yeah my antivirus (microsoft security essentials) went mental and stuck stuff into quarantine from classicamiga and amibay websites when I tried to load said pages.
__________________
A1200D 3.1 roms, Blizzard MkIV 1230/@50mhz 64 meg FPU@40mhz. PSU @140w. Internal cdrom. 60gig HD. OS 3.9/3.1. Connected to the interweb. External Scan Magic with 22inch Widescreen LCD monitor.
PSX/PS2/Snes/GameCube/Xbox/Xbox 360/C64C
Jimbo is offline  
Old 12 May 2012, 21:20   #21
Merlin
AmiBay MegaMod
 
Merlin's Avatar
 
Join Date: Mar 2007
Location: Manchester, UK
Age: 51
Posts: 1,122
The home page has been repaired now.

It's a variant of the Blackhole Exploit that's doing the rounds. It messes up the home page then tries to download malware using Javascript.

We've removed the malicious code, so everything's back to normal now.
__________________
Author of the Retr0bright Wiki: http://www.retr0bright.wikispaces.com

Last edited by prowler; 12 May 2012 at 22:45. Reason: Back-to-back posts merged after threads merged.
Merlin is offline  
Old 12 May 2012, 22:50   #22
prowler
Global Moderator
 
prowler's Avatar
 
Join Date: Aug 2008
Location: Sidcup, England
Posts: 8,696
Thanks for the update, Merlin!

As this thread has served its purpose, and I've had to remove some trolling, I'm closing it now.
prowler is offline  
Closed Thread


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
EAB hacked? No! oRBIT project.EAB 13 18 January 2012 22:47
DungeonMaster 2.0 (hacked for HD) with KS 3.1 Gaula92 support.Games 10 08 October 2011 16:13
BBOAH Hacked?!?! Fingerlickin_B Amiga scene 8 14 November 2008 18:25
Dream17 hacked squirminator2k Amiga scene 8 07 September 2008 10:22
Amiga.com hacked ! RCK Amiga scene 34 29 December 2002 01:01


All times are GMT +2. The time now is 03:16.

-->

Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Page generated in 0.78459 seconds with 9 queries