Please wait...
HomeForumMembers LoungeGeneral TalkWarning Hacker add .
Topic Rating:

Jump to
ySense Customer Care CornerySense Knowledge CenterMembers LoungeYour StatsSuccess StoriesPayment ProofsMember IntroductionGeneral TalkForo en EspañolCharla GeneralSoporte General y PagosInternationalPortugueseItalianFrenchGermanHindiUrduFilipinoIndonesianArabicRomanianTurkishRussianBulgarianHungarianPolishEx-Yugoslavia
Warning Hacker add .

Locked

#21 by BouldRake » Tue Aug 23, 2016 12:46

Quote:don't store your passwords on your browser

The security conscious should read this:

Quote:In this paper we surveyed a wide variety of password
managers and found that they follow very different and
inconsistent autofill policies. We showed how an evil
coffee shop attacker can leverage these policies to steal
the user’s stored passwords without any user interaction.
We also demonstrated that password managers can pre-
vent these attacks by simply following two steps - never
autofilling under certain conditions like in the presence
of HTTPS certificate validation errors and requiring user
interaction through some form of trusted browser UI, that
untrusted JavaScript cannot affect, before autofilling any
passwords.

Password Managers: Attacks and Defenses | USENIX

In fact, storing passwords in the browser can be fine - or it can be disaster. Find a keychain that meets the recommendations in the paper.
BouldRake
Posts2,841
Member Since1 Aug 2010
Last Visit28 Nov 2023
Likes Given10
Likes Received2,968/1,514

#22 by sudsakonr » Wed Aug 24, 2016 03:00

thank you for the warning :)
sudsakonr
Posts4
Member Since9 Jan 2014
Last Visit31 Oct 2016
Likes Given0
Likes Received0

#23 by StarryMight » Wed Aug 24, 2016 16:17

I've encountered a couple of suspect ads like that recently...one called itself a CPA Conversion Test, and when I clicked on it, it led to a site for what appears to be a cheat for the mobile game "Clash of Clans" (which I don't play), which then asked me to download "ClixSense-AccountProblem.doc". I closed the message and reported the site. The other one I more recently encountered asked if I wanted to download "10$ ClixSense Bonus.wsf". I also closed that and reported the site.

This is exactly why I prefer to use Linux operating systems to do PTC, since the risk is much lower on them than Windows (which I do use for pretty much everything else ;)).
StarryMight
Posts128
Member Since29 Mar 2015
Last Visit20 Mar 2018
Likes Given13
Likes Received88/45

#24 by BouldRake » Wed Aug 24, 2016 16:22

StarryMight wrote: This is exactly why I prefer to use Linux operating systems to do PTC, since the risk is much lower on them than Windows (which I do use for pretty much everything else ;)).

Heh yeah - I couldn't figure out what it did (it's pretty well obfuscated), so I tried to run it (safely, in a sandbox), and couldn't get the damn thing to work.
BouldRake
Posts2,841
Member Since1 Aug 2010
Last Visit28 Nov 2023
Likes Given10
Likes Received2,968/1,514

#25 by revroach » Wed Aug 24, 2016 18:06

Name of my latest auto-dl: flashplayer22pp_xa_install.jar

The dl was blocked and stoped but thats a another one going around

It came up in the Grid btw
revroach
Posts188
Member Since24 Oct 2014
Last Visit6 Aug 2019
Likes Given147
Likes Received126/81

#26 by paper07 » Wed Aug 24, 2016 18:36

I got that too;
paper07
Posts30
Member Since25 Feb 2007
Last Visit29 Jan 2024
Likes Given57
Likes Received14/12

#27 by shelbri78 » Wed Aug 24, 2016 19:22

Never download anything you are not sure of and especially if you never requested it. That is basic computer smarts.
shelbri78
Posts22
Member Since4 Apr 2013
Last Visit3 Jul 2017
Likes Given3
Likes Received32/9

#28 by hyldig » Thu Aug 25, 2016 03:05

BR , it could be a dorment program waiting for another add with a trigger sequence that is missing to activate it . That way it might be able to mask itself from those who try to figure out what it is and hide from security detection and removal tools .
hyldig
Posts871
Member Since8 Sep 2013
Last Visit8 Jul 2017
Likes Given63
Likes Received444/306

#29 by x_0 » Thu Aug 25, 2016 03:34

I'm sure this kind of virus... :)


Virus Script / Batch
            This virus was originally known as the virus batch as was once contained in a batch file that is in DOS.Virus scripts are frequently obtained from the Internet because of the benefits of flexible and able to walk when we play on the internet, this type of virus usually stay in the HTML file (Hype text Markup Language) script created by using facilities such as Javascript, VBScript, 4 and combination of scripts that enable Active-X programs from Microsoft Internet Explorer.
x_0
Posts559
Member Since17 Feb 2016
Last Visit6 Aug 2017
Likes Given714
Likes Received410/239

#30 by BouldRake » Thu Aug 25, 2016 05:15

It's a windows script file, but it's broken up into functions of obfuscated (and rearranged) arrays. At the end, the obfuscated arrays are then concatenated into a string and called as a command. It's definitely either a virus or some kind of malicious exploit. Hyldig might be right about the missing piece, or it might just be something missing in the *nix environment - since it's quite specifically a Windows script.

But yeah, it's definitely dodgy.

Also, since there's now a .jar file in there, there are probably several different malicious files doing different things anyway. I only looked at the 10$ ClixSense Bonus.wsf file.
BouldRake
Posts2,841
Member Since1 Aug 2010
Last Visit28 Nov 2023
Likes Given10
Likes Received2,968/1,514

#31 by stsajen » Thu Aug 25, 2016 12:06

Today.... new file download: ClixSense 5$ Bonus.wsf

Becareful
stsajen
Posts3
Member Since28 Jul 2016
Last Visit9 Jun 2017
Likes Given0
Likes Received3/3

#32 by walkinganomaly » Thu Aug 25, 2016 12:36

stsajen wrote: Today.... new file download: ClixSense 5$ Bonus.wsf

Becareful

I got that one today as well, I hit "Report Problem" and "cancel" on the download. Makes me wonder about some people!
walkinganomaly
Posts952
Member Since14 Nov 2009
Last Visit10 Feb 2019
Likes Given7,106
Likes Received652/379

#33 by x_0 » Thu Aug 25, 2016 14:48

This script to test your antivirus try ... :thumbup:


antivirus test

1. open notepad, then copy and paste the code below

X5O! P% @ AP [4 \ PZX54 (P ^) 7CC) 7} $ EICAR-STANDARD-ANTIVIRUS-TEST-FILE! $ H + H *



2. then save the file by "Save As". and a file name with .com exstension
      (* Filename and directory files / spot-free files) can drive the C, D, E etc.
       example: test.com


3. The notification will appear on our antivirus and if we are good antivirus will be immediately deleted / diblock.


4. Do not be afraid of this file we created earlier that contain EICAR of the code will not infect our computers for Text Standard Text Code above are used by the Anti-Virus Developers particular by EICAR (European Institute for Computer Anti-virus Research). so EICAR itself is the body that focus in the field of viruses and they create a standardization of the antivirus. These standards are used to see the reaction when the antivirus detects the file created by the EICAR ie text files that we created earlier with the notepad.





:clap: :clap: :thumbup:
x_0
Posts559
Member Since17 Feb 2016
Last Visit6 Aug 2017
Likes Given714
Likes Received410/239

#34 by claxyclicks584 » Thu Aug 25, 2016 15:19

BouldRake wrote: It's a windows script file, but it's broken up into functions of obfuscated (and rearranged) arrays. At the end, the obfuscated arrays are then concatenated into a string and called as a command. It's definitely either a virus or some kind of malicious exploit. Hyldig might be right about the missing piece, or it might just be something missing in the *nix environment - since it's quite specifically a Windows script.

But yeah, it's definitely dodgy.

Also, since there's now a .jar file in there, there are probably several different malicious files doing different things anyway. I only looked at the 10$ ClixSense Bonus.wsf file.

I decompiled the source (at least for the 10$ ClixSense Bonus.wsf file), it's just a downloader for some .exe that I can't get to work. It pretends to be a "calculator", and it's been scanned on Virustotal for months. No antivirus detects it as a virus though.

Still don't open the file though. It might be on a timer, or the .exe might be detecting that it was being opened on a VM and didn't do anything.
claxyclicks584
Posts580
Member Since11 Sep 2012
Last Visit28 Apr 2020
Likes Given66
Likes Received631/271

#35 by revroach » Thu Aug 25, 2016 17:18

shelbri78 wrote: Never download anything you are not sure of and especially if you never requested it. That is basic computer smarts.


Mine came from pages that auto-downloaded the files. I've got my system to block that sort of thing but it does not always work with these.
revroach
Posts188
Member Since24 Oct 2014
Last Visit6 Aug 2019
Likes Given147
Likes Received126/81

#36 by suni373 » Fri Aug 26, 2016 01:51

Thanks for info.....
suni373
Posts309
Member Since30 Nov 2014
Last Visit2 Jun 2023
Likes Given132
Likes Received140/103

#37 by dawala » Fri Aug 26, 2016 03:52

Your click has been validated
You've just been credited $0.001


Viewing: http://affilatemoneymaking513.online/Close

This Ad wanted to download something bad.

I am online with sandboxie. This tool showed me that a download was to take place. I just closed the message from sandboxie and the Ad ran. I use the free version.

Happy clicking
dawala
Posts47
Member Since6 Dec 2012
Last Visit17 Nov 2017
Likes Given0
Likes Received8/7

#38 by dawala » Fri Aug 26, 2016 03:52

Your click has been validated
You've just been credited $0.001


Viewing: http:// affilatemoneymaking513.online/Close

This Ad wanted to download something bad.

I am online with sandboxie. This tool showed me that a download was to take place. I just closed the message from sandboxie and the Ad ran. I use the free version.

Happy clicking
dawala
Posts47
Member Since6 Dec 2012
Last Visit17 Nov 2017
Likes Given0
Likes Received8/7

#39 by True-Democracy » Fri Aug 26, 2016 04:04

Be careful it's back again, don't bather to report it because i already did. :thumbup:

True-Democracy
Posts1,310
Member Since27 Jun 2012
Last Visit3 Dec 2018
Likes Given3,053
Likes Received1,249/682

#40 by Charez » Fri Aug 26, 2016 04:43

yeah, i got more bonus in 2 days than with the grid within a year
so generous :)
Charez
Posts3,350
Member Since2 Nov 2010
Last Visit14 Jan 2021
Likes Given877
Likes Received2,277/1,201
Locked
Return to 'General Talk' Forum     Return to the forums index
All times displayed are PST - Server Time: Apr 20, 2024 01:56:33 PST