If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.
+ Reply to Thread
Results 1 to 12 of 12

Thread: Website hackings

  1. #1

    Website hackings

    Vana'diel Atlas has been hacked. Sounds like some password stealing stuff so watch out.

  2. #2
    The Original PLD
    Reputation Reputation
    Vandoura's Avatar Users Server Users Starting Nation
    Join Date
    Jun 2005
    Location
    Windurst Water
    Posts
    2,743
    Users Job Users Job Users Job
    Can someone able to verify it?
    Spoiler:

    http://i39.photobucket.com/albums/e1.../vandycopy.png
    Qcdn-Original birthplace for Grammar Nazi

  3. #3
    Legionnaire
    Reputation
    johnno25's Avatar Users Server Users Starting Nation
    Join Date
    Oct 2007
    Location
    Canada
    Posts
    143
    Gamer IDs

    Gamertag: LeadVandamage
    Users Job Users Job Users Job
    FFXI atlas has had a trojan attached to it for about 6 weeks now iirc, whenever I tried to look up NM information on it my AV program would block it. I assumed it was common knowledge since it's been on there so long.


    And yes, I can confirm it's down, I can't even have the main page up without getting a virus warning.

    Find some other site for maps if you can (Wiki has some)
    Last edited by johnno25; June 25th, 2009 at 08:16 AM.
    Darthjohnboy
    PLD 75 WAR 75 BLM 75 THF 75 NIN 37 SAM 37 WHM 27 DRK 21 RDM 75 SMN 29 COR 27
    Bastok: Rank 10
    CoP: 8-3
    ZM: 14
    TOAU: Done
    WoTG: 10

  4. #4
    Cuetlachtli ヾ(´・ω・`)
    Reputation Reputation Reputation
    Zerayla's Avatar Users Server Users Starting Nation
    Join Date
    Sep 2005
    Location
    Canada
    Posts
    1,526
    Users Job Users Job Users Job
    Any suggestions for what a person should do if they visited FFXI Atlas in the last week? I haven't logged in or anything, but I have used the site to help get through some promy runs i've done.

    I currently use Avast Home Edition (free version) and I did run it earlier this week as well, but didn't have anything come up as far as viruses go.
    (c) Me.
    ★The Strength of the Wolf is in the Pack. The Strength of the Pack is in the Wolf★
    PLD
    76|RDM 80|WHM 80|WAR 75|
    SAM 75|BLM 76|MNK 75|DRG 80|COR 77|SMN 75
    SpiritOfTheWolf Linkshell (social) ~ My FFXIBlog ~ MyDeviantart




  5. #5
    Dances like a pimp
    Reputation Reputation Reputation Reputation Reputation Reputation
    JP's Avatar Users Server Users Starting Nation
    Join Date
    Sep 2007
    Location
    Pen Island
    Posts
    2,380
    Gamer IDs

    PSN ID: Justinp14
    Users Job Users Job Users Job
    Yeah I expected my PC to block the site if there was a trojan on it. I just did a scan and nada. And I went to Atlas sometime this week.

  6. #6
    The Original PLD
    Reputation Reputation
    Vandoura's Avatar Users Server Users Starting Nation
    Join Date
    Jun 2005
    Location
    Windurst Water
    Posts
    2,743
    Users Job Users Job Users Job
    Quote Originally Posted by Zerayla View Post
    Any suggestions for what a person should do if they visited FFXI Atlas in the last week? I haven't logged in or anything, but I have used the site to help get through some promy runs i've done.

    I currently use Avast Home Edition (free version) and I did run it earlier this week as well, but didn't have anything come up as far as viruses go.

    Not all AV can detect all viruses. Some will find it, some will don't. If you ever use those virus scanner site (like virus.org that scan individual files for you using like 15 AV software) some file will detected as virus some will don't, some will falsely detected as virus. Only way to know you're protected is to know the software is able to detect 98-100% of the virus known. You can get those result from those website that independencely test AV software


    Remember, if you able to detect 75% of 10,000 (for example) known virus.. that mean 2,500 known virus wasn't detected (25% if them).
    Spoiler:

    http://i39.photobucket.com/albums/e1.../vandycopy.png
    Qcdn-Original birthplace for Grammar Nazi

  7. #7
    Tarutaru Extremist
    Reputation
    Pascal's Avatar Users Server Users Starting Nation
    Join Date
    Sep 2004
    Location
    West Virginia
    Posts
    1,492
    Users Job Users Job Users Job
    Quote Originally Posted by Vandoura View Post
    Can someone able to verify it?
    Google has flagged it.
    http://www.stopbadware.org/reports/c...fxi-atlas.com/

    RDM80/WHM57/BLM56/SCH40 - Bastok - Rank 7

  8. #8
    Vanadiel beastiary is down now too =/

  9. #9
    Legionnaire
    Reputation
    johnno25's Avatar Users Server Users Starting Nation
    Join Date
    Oct 2007
    Location
    Canada
    Posts
    143
    Gamer IDs

    Gamertag: LeadVandamage
    Users Job Users Job Users Job
    Avast is the program i use, and it is the one to tell me that FFXI atlas has trojans on it.

    Firefox is the web browser i use, and it has plugins and settings that block known bad sites. IE as far as i'm concerned does a spectacular job of not keeping up with anything and taking forever to introduce counter measures to anything.

    If your concerned about your PC, i recommend disconnecting from your internet, and run a complete virus scan. Once that is done, run a spyware scan and delete anything it finds.


    And stay the hell away from FFXI atlas
    Darthjohnboy
    PLD 75 WAR 75 BLM 75 THF 75 NIN 37 SAM 37 WHM 27 DRK 21 RDM 75 SMN 29 COR 27
    Bastok: Rank 10
    CoP: 8-3
    ZM: 14
    TOAU: Done
    WoTG: 10

  10. #10
    Tarutaru Extremist
    Reputation
    Pascal's Avatar Users Server Users Starting Nation
    Join Date
    Sep 2004
    Location
    West Virginia
    Posts
    1,492
    Users Job Users Job Users Job
    I can confirm it is there. The exploit is using JScript to launch a malformed PDF (fu.pdf) to cause a buffer overrun and attempts to do this several different ways. The call to the script (us.js) is in the latest entries on "Latest Major Updates". Assume the date is correct on the entry the site was infected on 6/23/2009. No way to know for sure.

    The script is loaded from 110.165.41.103. I would block this IP in your firewall if it is capable of it. The IP is assigned to Honk Kong and has been used to host malware before.

    Afraid I've not tested the PDF yet, so I do not know what happens if the exploits runs. If I have time at work tomarrow, I'll check it out.

    RDM80/WHM57/BLM56/SCH40 - Bastok - Rank 7

  11. #11
    Aegis High
    Reputation
    Users Server Users Starting Nation
    Join Date
    Jun 2005
    Location
    London
    Posts
    207
    Users Job Users Job Users Job
    Tis a shame. Are the owners able to do anything about it?
    Hacking a website, would it remove the ability to actually change your site again? Not quite sure how it works.

  12. #12
    Dances like a pimp
    Reputation Reputation Reputation Reputation Reputation Reputation
    JP's Avatar Users Server Users Starting Nation
    Join Date
    Sep 2007
    Location
    Pen Island
    Posts
    2,380
    Gamer IDs

    PSN ID: Justinp14
    Users Job Users Job Users Job
    They can but it seems they rarely update the site so it may be there for a while. It's kinda like somepage, it was never updated so it was always full of viruses.
    Now Playing - Dragon Quest IX (too lazy to make sig right now)
    vagina
    75 Chivalry 75 Jack of All Trades 75 Nuker 53 Shooter
    March 24, 2004 - January 24, 2010

+ Reply to Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts