Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.computer.security
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 01-23-2008, 11:20 PM
Rick Merrill
Guest
 
Posts: n/a
Default suspicious site

how do you check out something like this?

volny.cz/svhgjtt/dental-plan.html

Reply With Quote
  #2 (permalink)  
Old 01-23-2008, 11:39 PM
David H. Lipman
Guest
 
Posts: n/a
Default Re: suspicious site

From: "Rick Merrill" <rick0.merrill@NOSPAM.gmail.com>

| how do you check out something like this?
|
| volny.cz/svhgjtt/dental-plan.html

It is a malware related web site that uses VBS/Psyme to download a Renos trojan and a
ByteVerify exploit to install a rogue anti malware utility called Spy-Shredder.


--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Reply With Quote
  #3 (permalink)  
Old 01-24-2008, 04:17 PM
Rick Merrill
Guest
 
Posts: n/a
Default Re: suspicious site

David H. Lipman wrote:
> From: "Rick Merrill" <rick0.merrill@NOSPAM.gmail.com>
>
> | how do you check out something like this?
> |
> | volny.cz/svhgjtt/dental-plan.html
>
> It is a malware related web site that uses VBS/Psyme to download a Renos trojan and a
> ByteVerify exploit to install a rogue anti malware utility called Spy-Shredder.
>
>


I didn't know about 'byteverify' but it appears to be a highjacked site,
but 'from whom' it was highjacked i couldn't tell. Is the whole 'cz'
domain not to be trusted?


Reply With Quote
  #4 (permalink)  
Old 01-24-2008, 10:12 PM
David H. Lipman
Guest
 
Posts: n/a
Default Re: suspicious site

From: "Rick Merrill" <rick0.merrill@NOSPAM.gmail.com>


| I didn't know about 'byteverify' but it appears to be a highjacked site,
| but 'from whom' it was highjacked i couldn't tell. Is the whole 'cz'
| domain not to be trusted?

The ByteVerify is a Java exploit.

Example McAfee log...
5/5/2007 6:58:39 PM Deleted (Clean failed) DLIPMAN-1\lipman
D:\temp\jar_cache30809.tmp\JAR_CACHE30809.TMP Exploit-ByteVerify

It is NOT a hijacked site. It is purposefully malicious.
I can not state that all .CZ (Czech Republic) Domains can not be trusted.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Reply With Quote
  #5 (permalink)  
Old 01-24-2008, 11:12 PM
Sebastian G.
Guest
 
Posts: n/a
Default Re: suspicious site

David H. Lipman wrote:


> D:\temp\jar_cache30809.tmp\JAR_CACHE30809.TMP Exploit-ByteVerify
>
> It is NOT a hijacked site. It is purposefully malicious.
> I can not state that all .CZ (Czech Republic) Domains can not be trusted.


But what we can tell for sure is that the owner is horribly stupid. The Byte
Verifier vulnerability was, well, Java JDK 1.1? Even the similiar-to-Java-
but-not-actually-Java-VM that Microsoft shipped with Windows 2000 and XP was
already at JDK 1.2 level, not vulnerable to this thing.

I still wonder how this thing is still in usage, even though the most stupid
bad guy would recognize an infection rate of essentially zero.

Reply With Quote
  #6 (permalink)  
Old 01-24-2008, 11:35 PM
David H. Lipman
Guest
 
Posts: n/a
Default Re: suspicious site

From: "Sebastian G." <seppi@seppig.de>


|
| But what we can tell for sure is that the owner is horribly stupid. The Byte
| Verifier vulnerability was, well, Java JDK 1.1? Even the similiar-to-Java-
| but-not-actually-Java-VM that Microsoft shipped with Windows 2000 and XP was
| already at JDK 1.2 level, not vulnerable to this thing.
|
| I still wonder how this thing is still in usage, even though the most stupid
| bad guy would recognize an infection rate of essentially zero.

Exploit-ByteVerify is rather generic. Many newer versions of Sun Java were also vulnerable.
There have been many variants to ByteVerify and they seem to increase.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Reply With Quote
  #7 (permalink)  
Old 01-25-2008, 01:47 AM
Sebastian G.
Guest
 
Posts: n/a
Default Re: suspicious site

David H. Lipman wrote:


> | But what we can tell for sure is that the owner is horribly stupid. The Byte
> | Verifier vulnerability was, well, Java JDK 1.1? Even the similiar-to-Java-
> | but-not-actually-Java-VM that Microsoft shipped with Windows 2000 and XP was
> | already at JDK 1.2 level, not vulnerable to this thing.
> |
> | I still wonder how this thing is still in usage, even though the most stupid
> | bad guy would recognize an infection rate of essentially zero.
>
> Exploit-ByteVerify is rather generic. Many newer versions of Sun Java were also vulnerable.



Hm? I've followed through the release notes of every version of Sun's Java
VM since JDK 1.2 and I'm very sure that they never mentioned any security
vulnerability in the bytecode verifier. Not even after they changed the
class format for helping implement the much simpler and more secure
SSA-based verifier.

> There have been many variants to ByteVerify and they seem to increase.


According to my analysis, it's the same old disfunctional crap from '98.

Reply With Quote
  #8 (permalink)  
Old 01-26-2008, 05:32 PM
blackhat
Guest
 
Posts: n/a
Default Re: suspicious site

On Jan 23, 7:20*pm, Rick Merrill <rick0.merr...@NOSPAM.gmail.com>
wrote:
> how do you check out something like this?
>
> volny.cz/svhgjtt/dental-plan.html


You don't, just stay away from it

Reply With Quote
  #9 (permalink)  
Old 02-01-2008, 03:02 PM
Casper
Guest
 
Posts: n/a
Default Re: suspicious site

Rick Merrill brought next idea :
> how do you check out something like this?
>
> volny.cz/svhgjtt/dental-plan.html


I use a text browser like Lynx to go to suspicious sites
(there is also a lynx for windows)



Reply With Quote
  #10 (permalink)  
Old 02-01-2008, 03:25 PM
Todd H.
Guest
 
Posts: n/a
Default Re: suspicious site

Rick Merrill <rick0.merrill@NOSPAM.gmail.com> writes:

> how do you check out something like this?
>
> volny.cz/svhgjtt/dental-plan.html


Curl would pull the html down and dump it in a text file -- handy
commandline tool.

--
Todd H.
http://www.toddh.net/

Reply With Quote
  #11 (permalink)  
Old 02-05-2008, 02:50 AM
paul
Guest
 
Posts: n/a
Default Re: suspicious site

On Feb 1, 9:25 pm, comph...@toddh.net (Todd H.) wrote:
> Rick Merrill <rick0.merr...@NOSPAM.gmail.com> writes:
> > how do you check out something like this?

>
> > volny.cz/svhgjtt/dental-plan.html

>
> Curl would pull the html down and dump it in a text file -- handy
> commandline tool.
>
> --
> Todd H.http://www.toddh.net/


www.siteadvisor.com

Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
HOT DEAL !! 300 GIGS webspace for only $5.95/mnth bourbonix.com alt.cellular.nokia 0 12-24-2007 05:51 PM
Youth Nudity, Sex Free Photos And Movie Site, naked teenager, nude Nudist sex fotos grtrgrtgr5r5nri9@yahoo.com alt.cellular.cingular 0 10-26-2007 02:46 AM
Sex Story,Free Erotic Sex Letter Stories From Anal Bitch Porn List Dildos Hot sex udshfu7fw37ifue@yahoo.com alt.cellular.cingular 0 07-12-2007 06:07 AM
LIVE LESBIAN SEX SHOWS lesbian sex chat lesbian sex toys lesbian porn sex jamaican lesbian sdfiuhsdejkds8dsj@yahoo.com alt.cellular.cingular 0 07-07-2007 04:56 AM
Forwarding HTTPS site by IP address girardmj375@yahoo.com alt.computer.security 3 05-14-2007 01:17 PM


All times are GMT. The time now is 09:44 AM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0 RC8

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45