Author Topic: incgamers virus issue  (Read 425 times)

0 Members and 1 Guest are viewing this topic.

Online Daffyd

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 5,590
  • Facial adornment +60/-7
incgamers virus issue
« on: October 18, 2007, 07:07:35 AM »
Scum sucking bottom feeders (chinese gold sellers) have been at it again, if you recently download any addons from wowui.incgamers.com (ui.worldofwar.net redirects here) then a full virus scan, replacement of all your addons, and an accoutn password change are in order.  System restore or reinstall would be even better.
Quote
Ok an update on this as we have spent the last 3  hours sifting through server logs and finally found the problem. The  attackers did not circumvent the virus scanner, we know that. They are  Chinese gold sellers once again and we have found the exploit they have  used to bypass the scanner. This hole has been plugged. All files that  were infected are removed and replaced with clean files. Business as  usual.  
 
They have obviously spent a lot of time poking around the site to  see how it functions and found something that did not come up in  testing internally. As with everything these days, when it comes to  gold sellers they are persistent and annoying for everyone here causing  a lot of work for us and annoyance for users. We take these attacks  very seriously and will be following up on this as far as we can with  the perpetrators.  
 
Thanks to Juergen for sending over great detailed information on  this when his scanner picked it up. It really helps us spot things  quickly and act if need be to prevent any further issues with users.
"I don't mean to sound bitter, cold, or cruel, but I am, so that's how it comes out."     - Bill Hicks

Offline Splishy

  • jam is teh win!
  • Administrator
  • Hero Member
  • *****
  • Posts: 9,067
  • Facial adornment +82/-12
    • Seeds of Glory
incgamers virus issue
« Reply #1 on: October 18, 2007, 08:48:07 AM »
Joygasm. This leaves me with just about all the addon sites blacklisted...
Hope you're enjoying being a member of the Seeds Of Glory - any donations towards the running costs of the site are gladly recieved!

Offline Altrurian

  • Guild Officers
  • Hero Member
  • *****
  • Posts: 868
  • Facial adornment +7/-0
incgamers virus issue
« Reply #2 on: October 18, 2007, 08:54:33 AM »
Crappit, downloaded updates for mobinfo and recipie radar from there in the last couple of days, oh well, gives me something to do when I get home I suppose!

Online Daffyd

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 5,590
  • Facial adornment +60/-7
incgamers virus issue
« Reply #3 on: October 18, 2007, 08:57:10 AM »
I updated a load of stuff the other day, mostly from Curse but some from other places.  Going to be a full scan for me too.  AVG is known to not find the infection, Kaspersky is confirmed to find it (fortunately for me I use the latter).
"I don't mean to sound bitter, cold, or cruel, but I am, so that's how it comes out."     - Bill Hicks

Offline Splishy

  • jam is teh win!
  • Administrator
  • Hero Member
  • *****
  • Posts: 9,067
  • Facial adornment +82/-12
    • Seeds of Glory
incgamers virus issue
« Reply #4 on: October 18, 2007, 09:16:04 AM »
Sadly Curse is already on my shitlist for exactly the same reason.
Hope you're enjoying being a member of the Seeds Of Glory - any donations towards the running costs of the site are gladly recieved!

Offline Mordwin

  • Guild Officers
  • Hero Member
  • *****
  • Posts: 788
  • Facial adornment +7/-0
incgamers virus issue
« Reply #5 on: October 18, 2007, 11:55:24 AM »
Seems like a healthy bit of paranoia would have prevented you being infected here, downloading an exe rather than a zip or a zip containing an exe should have set off more than a few alarm bells.

I doubt any site can be completely secure, so just be careful out there

Offline Splishy

  • jam is teh win!
  • Administrator
  • Hero Member
  • *****
  • Posts: 9,067
  • Facial adornment +82/-12
    • Seeds of Glory
incgamers virus issue
« Reply #6 on: October 18, 2007, 12:01:15 PM »
The infected file was an .exe? In that case I'm fine. I suppose I'd better go and read more on this...
Hope you're enjoying being a member of the Seeds Of Glory - any donations towards the running costs of the site are gladly recieved!

Online Daffyd

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 5,590
  • Facial adornment +60/-7
incgamers virus issue
« Reply #7 on: October 18, 2007, 12:51:26 PM »
Quote from: Splishy
The infected file was an .exe? In that case I'm fine. I suppose I'd better go and read more on this...
Not sure, I know all the files I downloaded were .zips though.
"I don't mean to sound bitter, cold, or cruel, but I am, so that's how it comes out."     - Bill Hicks

Offline Choleric

  • Guild Officers
  • Hero Member
  • *****
  • Posts: 2,714
  • Facial adornment +22/-0
incgamers virus issue
« Reply #8 on: October 18, 2007, 01:44:44 PM »
Quote
Scum sucking bottom feeders (chinese gold sellers)

Speaking of which, I noticed last night they have started using emotes to broadcast along with /say as well now, so double the spammage.  Does ignoring them also ignore their emotes? I didn't have an opportunity to test it.

Haven't downloaded an addon in at least a fortnight, and they were .zips, so I should be safe.

Offline Mordwin

  • Guild Officers
  • Hero Member
  • *****
  • Posts: 788
  • Facial adornment +7/-0
incgamers virus issue
« Reply #9 on: October 18, 2007, 01:57:25 PM »
Quote from: Splishy
The infected file was an .exe? In that case I'm fine. I suppose I'd better go and read more on this...

From what I can make out it was either an exe pretending to be a self-extracter, or a zip of same. I'm not aware of any way you could get an infection just from opening/extracting a normal zip (not saying it wouldn't be possible mind you), so you should be fine. Be aware that Curse may have been affected too.

Offline Splishy

  • jam is teh win!
  • Administrator
  • Hero Member
  • *****
  • Posts: 9,067
  • Facial adornment +82/-12
    • Seeds of Glory
incgamers virus issue
« Reply #10 on: October 18, 2007, 02:08:00 PM »
*hugs Vista UAC*
Hope you're enjoying being a member of the Seeds Of Glory - any donations towards the running costs of the site are gladly recieved!

Online Daffyd

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 5,590
  • Facial adornment +60/-7
incgamers virus issue
« Reply #11 on: October 18, 2007, 02:26:36 PM »
Quote from: Mordwin


From what I can make out it was either an exe pretending to be a self-extracter, or a zip of same. I'm not aware of any way you could get an infection just from opening/extracting a normal zip (not saying it wouldn't be possible mind you), so you should be fine. Be aware that Curse may have been affected too.
 
I wasn't aware of any way either, but I also don't have 100% faith in the LUA restrictions of Blizzard.
Quote
*hugs Vista UAC*
It's possible I may have got pissed off with it and disabled it...

*whistle*
« Last Edit: October 18, 2007, 04:21:23 PM by Daffyd »
"I don't mean to sound bitter, cold, or cruel, but I am, so that's how it comes out."     - Bill Hicks

Offline Splishy

  • jam is teh win!
  • Administrator
  • Hero Member
  • *****
  • Posts: 9,067
  • Facial adornment +82/-12
    • Seeds of Glory
incgamers virus issue
« Reply #12 on: October 18, 2007, 02:39:51 PM »
Quote from: Daffyd
It's possible I may have got pissed off with it and disabled it...

*whistle*

*feels all smug*

Seriously - this just goes to prove that the "I know what I'm doing, so I don't need UAC" argument holds precisely no water.
Hope you're enjoying being a member of the Seeds Of Glory - any donations towards the running costs of the site are gladly recieved!

Offline Altrurian

  • Guild Officers
  • Hero Member
  • *****
  • Posts: 868
  • Facial adornment +7/-0
incgamers virus issue
« Reply #13 on: October 18, 2007, 02:50:04 PM »
Haven't downloaded anything individually, all add-ons have been updated recently with the wowace updater or the uicentral updater, will have to read further to see how or if the uicentral updater was affected.

Offline Mordwin

  • Guild Officers
  • Hero Member
  • *****
  • Posts: 788
  • Facial adornment +7/-0
incgamers virus issue
« Reply #14 on: October 18, 2007, 03:10:14 PM »
it was stated that the uicentral updater will not run exe's, so you should be safe on that front at least.
« Last Edit: October 18, 2007, 03:10:29 PM by Mordwin »

Offline Phred

  • Guild Officers
  • Hero Member
  • *****
  • Posts: 1,254
  • Facial adornment +27/-2
incgamers virus issue
« Reply #15 on: October 18, 2007, 03:16:16 PM »
Hmm with various addons i have never had any issues.
May i suggest to use AceAddons and the AceUpdater? it seems to be a pretty topace site and very secure. And the Updater is a real boni, no bloddy surfing, just activate it and search for addons in that little tool
Quote
on: October 17, 2006 ยป
Heya Ppl, I got an invitation to join this Board throug Amberley.
 

Offline Splishy

  • jam is teh win!
  • Administrator
  • Hero Member
  • *****
  • Posts: 9,067
  • Facial adornment +82/-12
    • Seeds of Glory
incgamers virus issue
« Reply #16 on: October 18, 2007, 03:19:14 PM »
In all honesty I'm dubious of anything that requires an .exe for ingame addins that DOESN'T offer a non-executable alternative
Hope you're enjoying being a member of the Seeds Of Glory - any donations towards the running costs of the site are gladly recieved!

Elendor

  • Guest
incgamers virus issue
« Reply #17 on: October 18, 2007, 04:00:37 PM »
Quote from: Splishy
In all honesty I'm dubious of anything that requires an .exe for ingame addins that DOESN'T offer a non-executable alternative
i agree. it isn't like we don't know where to extract the files to, also with EXE formats you don't know exactly what you're getting and where you're getting it unless your AV software alerts you of a virus or whatever.

Online Daffyd

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 5,590
  • Facial adornment +60/-7
incgamers virus issue
« Reply #18 on: October 18, 2007, 04:22:28 PM »
Quote from: Splishy
Seriously - this just goes to prove that the "I know what I'm doing, so I don't need UAC" argument holds precisely no water.
The "I ALREADY TOLD YOU TWICE JUST FUCKING DO IT!" argument, however, is more persuasive.
"I don't mean to sound bitter, cold, or cruel, but I am, so that's how it comes out."     - Bill Hicks

Offline Choleric

  • Guild Officers
  • Hero Member
  • *****
  • Posts: 2,714
  • Facial adornment +22/-0
incgamers virus issue
« Reply #19 on: October 18, 2007, 04:40:11 PM »
Quote from: Splishy
In all honesty I'm dubious of anything that requires an .exe for ingame addins that DOESN'T offer a non-executable alternative

Indeed, I don't download anything at all that is a .exe unless it is from a highly trusted source e.g. definately not a wow-addon website.