Welcome, Guest. Please login or register.
September 07, 2010, 08:24:48 AM
Home Help Search Login Register
News: The EPG is no longer being downloaded to the inverto, all recording will have to be scheduled manually or from the now/next banner. Please check this thread http://www.invertoforum.co.uk/forum/index.php?topic=2055.0

+  Inverto Forum
|-+  Other Inverto Products
| |-+  Inverto Product Discussion
| | |-+  Malware on Inverto's website
« previous next »
Pages: [1] Go Down Print
Author Topic: Malware on Inverto's website  (Read 796 times)
DTEG
Verty Addict
******
Offline Offline

Posts: 1004


View Profile Goznet Systems - web design and applications
« on: November 24, 2009, 06:44:37 PM »

Anyone else get a trojan horse warning (PHP:C99Shell-A) from the file http://www.inverto.tv/IMG/faq/dan.jpg when going to the Inverto home page? Or is Avast just being paranoid over a false positive?

Probably worth making sure your anti-virus is fully patched before trying, in case it is for real!
Logged
DTEG
Surrey, UK
Inverto IDL7000-PVR from boots.com, 80GB Maxtor QuickView, firmware 1.010
dmp
Administrator
Verty Addict
*****
Offline Offline

Posts: 1448


View Profile
« Reply #1 on: November 24, 2009, 09:03:08 PM »

Nothing on my laptop, but there again only a line of script came up with no picture.
Dave
Logged
DTEG
Verty Addict
******
Offline Offline

Posts: 1004


View Profile Goznet Systems - web design and applications
« Reply #2 on: November 26, 2009, 11:40:40 AM »

Shock horror, I emailed them and (although no personal response) they removed it. Someone's alive there?
Logged
DTEG
Surrey, UK
Inverto IDL7000-PVR from boots.com, 80GB Maxtor QuickView, firmware 1.010
browser01
Full Member
***
Offline Offline

Posts: 159


View Profile Email
« Reply #3 on: April 08, 2010, 10:59:30 AM »

Hi Guys  I recently got some evil junk mail on my hotmail account. It alleges as this forwarded text shows that it has come from admin@invertoforum.co.uk. I would just like to warn you and others that somebodys security has/might have been breached. I thought that my security was tight. However I have recently changed and now use Microsoft Security Essentials as my first line of defence and like all MS products I am not sure how reliable it is. I also run AVG, Spybot and SpywareBlaster in the background and usually get very little in the way of junk mail. Here is the header etc from this mail PLEASE everyone watch out for similar rubbish coming through and avoid following any links in this sort of unsolicited mail. Browser
> Subject: ararWvvSiueTetTx
> From: admin@invertoforum.co.uk
> Date: Mon, 5 Apr 2010 10:53:02 +0000
>
> tKb97V wnbggyroymws, nhgguigxpqan, [link=http://fgfpsclmepvv.com/]fgfpsclmepvv[/link], http://jrauhdyyqizw.com/

I have kept the original mail if one of you administrators would like a copy. B
« Last Edit: April 08, 2010, 11:03:32 AM by browser01 » Logged
dmp
Administrator
Verty Addict
*****
Offline Offline

Posts: 1448


View Profile
« Reply #4 on: April 08, 2010, 01:21:54 PM »

Hi Browser, sorry about that, not sure where it came from but if Sneeks sees this I'm sure he'd like to know. Thanks for the warning.
Dave
Logged
DTEG
Verty Addict
******
Offline Offline

Posts: 1004


View Profile Goznet Systems - web design and applications
« Reply #5 on: April 08, 2010, 05:06:58 PM »

All domains occasionally get used by spammers in the email addresses, which are invariably faked. Unless the actual SMTP headers trace back to an Inverto Forum server, there is nothing specifically to worry about in terms of system compromise. It's just annoying because although no-one human believes the email addresses any more, there are still some dumb spam filters that do, so the poor individual whose email address was arbitrarily chosen can get hundreds of rejection messages.
Logged
DTEG
Surrey, UK
Inverto IDL7000-PVR from boots.com, 80GB Maxtor QuickView, firmware 1.010
DTEG
Verty Addict
******
Offline Offline

Posts: 1004


View Profile Goznet Systems - web design and applications
« Reply #6 on: April 08, 2010, 05:41:08 PM »

On the other hand, with all the millions of domains out there, the chances of a spammer faking using Inverto Forum targeting one of us is somewhat lessened - though far from impossible given the volume of messages sent.
Logged
DTEG
Surrey, UK
Inverto IDL7000-PVR from boots.com, 80GB Maxtor QuickView, firmware 1.010
paulm
Newbie
*
Offline Offline

Posts: 27

View Profile
« Reply #7 on: April 09, 2010, 08:47:39 PM »

The reason they are using this address, of course, is because someone who has received mail from this address has been compromised. They'll grab an addressbook and use these addresses as ones which are pretty certain to get through filters etc (and might be recognisable). So if a community member has been got, then all his/her friends will be on the list and they'll get mail from others in the list and it continues ad infinitum (until someone manages to switch it off). The likelihood of invertoforum or whereever being compromised is pretty small especially if people's malware scanners are not picking anything up.

Logged
browser01
Full Member
***
Offline Offline

Posts: 159


View Profile Email
« Reply #8 on: April 23, 2010, 03:22:36 PM »

Just come to this site and found adverts at the top of the index page. 1 Says I can have a free macbook if I follow links etc 2 Is about an American banker who can make us all rich if we contact *****website. Anyone know how these have got onto the site? They seem to have gone now BUT it is a worrying development if no-one knows about it. Browser
Logged
browser01
Full Member
***
Offline Offline

Posts: 159


View Profile Email
« Reply #9 on: April 23, 2010, 04:35:17 PM »

Seems like it is my computer. These popups are occurring randomly on other websites too. I seem to have a couple of tracking cookies which could be the cause. I won't be able to rest until this behaviour is gone. Oh bother! (or words to that effect) B
Logged
dmp
Administrator
Verty Addict
*****
Offline Offline

Posts: 1448


View Profile
« Reply #10 on: April 23, 2010, 06:04:11 PM »

Hi Browser, I think it must be you, checking the top of my page and all is as it should be, I think a scan and clean up is in order for you.
Dave
Logged
Pages: [1] Go Up Print 
« previous next »
 


Login with username, password and session length

Powered by MySQL Powered by PHP Powered by SMF 2.0 RC3 | SMF © 2006–2010, Simple Machines LLC Valid XHTML 1.0! Valid CSS!