nakenprat
Forum Gratis WebcamChat Bildealbum Grupper Nettbutikk

SexyNatalie.com
SexyNatalie
Besøk sexynatalie

Filmer fra Sexy Natalie
sexy natalie
Klikk for å se mer


sexy natalie
Klikk for å se mer


sexy natalie
Klikk for å se mer


Sexleketøy for begge
Fleshlight Vibro
Fleshlight Vibro
Massasjestav
Massasjestav Extra
Norske piker
Norske piker film
The Ripper
The Ripper

Gå tilbake   Nakenprat med pornofilmer, sexleketøy, sexbilder , erotisk chat , norsk porno og erotikk > Generellt > Generell prat

Heads up For Brukere som kjører Flashget.

Sjekk disse nettstedene for gratis porno
01. Nakna svenska tjejer 05. Gamle damer 09. Hjemme Sex 13. Billiga brudar 17. Monskerkuk
02. Deilige jenter 06. Hjemme knull 10. Snuska 14. Eroslisten 18. Erotikk
03. Fyllesex 07. Frekke piker 11. Villig vagina 15. Gratis erotik 19. Fulle jenter
04. Voksne damer 08. Gratis gallerier 12. Fittknull 16. Norsk porno 20. Damelisten

Svar
 
Trådverktøy
  #1  
Gammel 30-03-08, 20:06
Lilith sin avatar
Sucubus
 
Medlem siden: Jul 2005
Sted: My Crypt
Innlegg: 4.631
Utførte Takk: 0
Takket 81 ganger i 43 poster
Lilith will become famous soon enough
Standard Heads up For Brukere som kjører Flashget.

TrojanGet infects users around the world
March 14, 2008

A few days ago we started getting messages from users saying that their antivirus software had started detecting Trojans in the Flashget directory

Image
http://i31.ti*ny*pic.com/2v1l0qs.jpg

Analysis showed that the problem was affecting Flashget users all over the world. Files called inapp4.exe, inapp5.exe, and inapp6.exe (which are detected by Kaspersky Anti-Virus as Trojan-Dropper.Win32.Agent.exo, Dropper.Win32.Agent.ezxo, and Trojan-Dowloader.Win32.Agent.kht) appeared on the victim machines.

The strangest thing was the fact that no other Trojans were detected that could have been used for the files shown above to get onto the system. Some affected users had fully patched operating systems and browsers. So how did the malicious programs penetrate their computers?

The first thing that was noticed was the location of the Trojans – the FlashGet directory. Taking a closer look, it became clear that in addition to the Trojans, the date the FGUpdate3.ini file had been created/modified was very recent (the difference from the original file is highlighted in blue):


[Add]
fgres1.ini=1.0.0.1035
FlashGet_LOGO.gif=1.0.0.1020
inapp4.exe=1.0.0.1031
[AddEx]
[fgres1.ini]
url=h__p://dl.flashget.com/flashget/fgres1.cab
flag=16
path=%product%
[FlashGet_LOGO.gif]
url=h__p://dl.flashget.com/flashget/FlashGet_LOGO.cab
flag=16
path=%product%

[inapp4.exe]
url=h__p://dl.flashget.com/flashget/appA.cab
flag=2
path=%product%

Image
http://i27.ti*ny*pic.com/i20x37.png

Strangely enough, the link to inapp4.exe (a Trojan file) leads to the FlashGet site, which is where the Trojan was downloaded from as appA.cab.

The FlashGet site didn't have any information about the incident, but the users’ forum was full of messages on the topic, even though the developers hadn’t said anything about it.

According to information we managed to find on the web, the first infection was detected on 29 February. The last case we know of occurred on 9 March. For 10 days a perfectly legitimate program acted as a Trojan-Downloader, installing and launching Trojans from the developer’s site onto users’ computers!

The Trojans have now been removed from the site, and FGUpdate3.ini (which also downloads to the user's machine via the Internet) is in its original condition.

So how was FlashGet turned into a Trojan-Downloader? There's one obvious answer – the developer’s site was hacked and someone managed to substitute the standard configuration file and link it to a Trojan located on the site. Why the hacker didn't use a different site isn't clear. Maybe this was deliberate stealthing, as a link to FlashGet in the configuration file isn't likely to arouse suspicion). We decided to check whether it would be possible to use this technique to download any file from any site. The answer? Yes, it is.

All you need to do is add a link (which can point to any file you want) to the FGUpdate3.ini file and it will be automatically downloaded to your computer every time you launch FlashGet. Even if you don’t press “Refresh”, FlashGet uses the information from the .ini file. This “vulnerability” is present in all versions of FlashGet 1.9.xx.

So, in spite of the fact that the site is no longer “hacked”, users are still vulnerable. Any Trojan program could modify the local .ini FlashGet file, causing it to function like a Trojan-Downloader. And it's worth noting here that FlashGet is usually treated as a trusted application, consequently, network activity caused by the application or requests to sites won't be flagged as suspicious, and users won't be alerted.


There has, as yet, been no official reaction from the Chinese developers of FlashGet. The reason for the incident remains unclear and there is no guarantee that it will not happen again. Users should feel free to draw their own conclusions… and take whatever measures they feel to be appropriate.

(Fjern * i bilde link, de andre linkene er ikke noe å bry seg med! sens*r..grr)
Svar med sitat
  #2  
Gammel 30-03-08, 20:56
Done&Gone sin avatar
From Asia With Love
 
Medlem siden: Sep 2006
Sted: Vagina City
Innlegg: 1.071
Utførte Takk: 67
Takket 707 ganger i 195 poster
Done&Gone is a splendid one to beholdDone&Gone is a splendid one to beholdDone&Gone is a splendid one to beholdDone&Gone is a splendid one to beholdDone&Gone is a splendid one to beholdDone&Gone is a splendid one to beholdDone&Gone is a splendid one to behold
Standard

Vet ikke om det var dette jeg hørte på tv`en her om dagen... Det var i hvertfall noe om ett stort utbrudd. Fikk ikke hørt alt for den jævla hunden bjeffer alltid når jeg skal se på noe interresant^^... Takk for infoen Lilith
Svar med sitat
Svar

vibro

tips.kripos.no
Ser du noe ulovlig? Tips politiet samt admin
Trådverktøy

Regler for innlegg
Du kan ikke starte nye tråder
Du kan ikke svare på innlegg / tråder
Du kan ikke laste opp vedlegg
Du kan ikke redigere innleggene dine

BB kode er
Smilier er
[IMG] kode er
HTML kode er Av
Trackbacks are Av
Pingbacks are Av
Refbacks are Av


Alle tider vises som GMT +1. Klokka er nå 10:04.


vBulletin 3.7.4 © 2000-2012 Jelsoft Enterprises Ltd.

Flere linker til porno : Pornofilm - Pornografi - Nordic Members - Gratis erotik - Naken bilder - Eros - Fitte
Lesbe - Kuk - Erotikk - Jenter - Norske par - Porno - Sexleketøy - Erotikk leker - Glidemiddel

Beskytt barna dine mot uønsket innhold - Klikk her