Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

But doctor...I am Pagliacci

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
It's bad, its only use is to be a red flag when you see people install it or hear people talk about it.

Also they got hacked http://blog.talosintelligence.com/2017/09/avast-distributes-malware.html

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

lol

Potato Salad
Oct 23, 2014

nobody cares


"Hi there's a payload on our installer that we didn't know about"

I actually want to see if cylance picks this up, pinging a consultant

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Potato Salad posted:

"Hi there's a payload on our installer that we didn't know about"

I actually want to see if cylance picks this up, pinging a consultant
Aren't they on virustotal now?

CLAM DOWN
Feb 13, 2007




https://nakedsecurity.sophos.com/2017/09/17/vevo-hacked-3-12-tb-of-data-leaked/

quote:

Vevo hacked, 3.12 TB of data leaked

...

A Vevo spokesperson said to Gizmodo on Friday:

(We) can confirm that Vevo experienced a data breach as a result of a phishing scam via LinkedIn. We have addressed the issue and are investigating the extent of exposure.

...



aaahaahahaahhaahahahahaha

Potato Salad
Oct 23, 2014

nobody cares


Heh, almost everyone on virustotal misses it.

The Fool
Oct 16, 2003


Potato Salad posted:

Heh, almost everyone on virustotal misses it.

Who didn't?

Potato Salad
Oct 23, 2014

nobody cares


The Fool posted:

Who didn't?

ClamAV; I am not familiar with it

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Unreal. I love this.

The Fool
Oct 16, 2003


Potato Salad posted:

ClamAV; I am not familiar with it

I've never used it, but it's gimmick is that it is open source and community managed.

AFAIK, it's signature based.

Potato Salad
Oct 23, 2014

nobody cares


De-escalation training, day 1:

Don't tell someone to gently caress off from the outset.

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


anthonypants posted:

It's bad, its only use is to be a red flag when you see people install it or hear people talk about it.

Also they got hacked http://blog.talosintelligence.com/2017/09/avast-distributes-malware.html

These kinds of attacks suck because they encourage people not to keep their software updated, exposing them to more vulnerabilities.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

probably not the best policy for extortion attempts

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Potato Salad posted:

ClamAV; I am not familiar with it

Yeah, they probably just ripped the hashes out of the blog post and threw them up there. I'm working with Symantec to get their sigs updated to check for it, though Cisco picked up on it in the first place because it was tripping their heuristics engine and the other vendors will probably want to look at theirs and figure out why theirs didn't catch wind of it.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
:thurman:

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

That guy is super smart.

orange sky
May 7, 2007

I wonder if Defender ATP picked it up, I'm not too familiar with the solution but it sounds like something it'd detect

fyallm
Feb 27, 2007



College Slice
Anyone going to be at Derbycon this weekend?

Three-Phase
Aug 5, 2006

by zen death robot

Man Stabbed posted:

What are you gonna do? Stab me?

DACK FAYDEN
Feb 25, 2013

Bear Witness

anthonypants posted:

It's bad, its only use is to be a red flag when you see people install it or hear people talk about it.
poo poo, I probably still have it installed on my home machine out of laziness. What's a better replacement for the default "remove programs" Windows uninstaller? I only ever open it when I need to uninstall ten things at once.

edit: actually, also, why does Windows only let you uninstall one program at a time, what data collision is it trying to prevent?

DACK FAYDEN fucked around with this message at 22:05 on Sep 18, 2017

Diva Cupcake
Aug 15, 2005

Is Revo Uninstaller still a thing? Probably that.

Wiggly Wayne DDS
Sep 11, 2010



yeah i'm sure the malware made sure to hook into the uninstaller as well, nevermind the other secondary payloads that haven't been found

Three-Phase
Aug 5, 2006

by zen death robot
5.33 are the versions that had the malware, right? I believe they released 5.32 like in June or July then 5.33 in August.

DACK FAYDEN
Feb 25, 2013

Bear Witness

Three-Phase posted:

5.33 are the versions that had the malware, right? I believe they released 5.32 like in June or July then 5.33 in August.
Yeah, clicking through there the link says it was 5.33 only and the current 5.33 download link is fine. August 15-September 15 if dates make it easier for you to remember.

(the free version doesn't autoupdate so I am totally fine but I'm still gonna get rid of it because where there's one breach...)

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

DACK FAYDEN posted:

edit: actually, also, why does Windows only let you uninstall one program at a time, what data collision is it trying to prevent?
Could be registry stuff, probably doesn't want things overwriting files in C:\Config.msi\

Three-Phase
Aug 5, 2006

by zen death robot
General ITSEC question - how do criminals afford "junk domains" or whatever you'd call them to host malware/spyware or do command and control and so forth? A single .com domain can be like $10 or more a year, how do they register dozens or hundreds of "kj9fslidjflskdjgflkjdfg dot zyx" or whatever domains?

Or are there just really, really shady registrars that are like "LOL OK here's a thousand domains whatever"?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Three-Phase posted:

General ITSEC question - how do criminals afford "junk domains" or whatever you'd call them to host malware/spyware or do command and control and so forth? A single .com domain can be like $10 or more a year, how do they register dozens or hundreds of "kj9fslidjflskdjgflkjdfg dot zyx" or whatever domains?

Or are there just really, really shady registrars that are like "LOL OK here's a thousand domains whatever"?
A lot of the gTLDs are far, far cheaper than .com domains. https://www.domcomp.com/tld/xyz

They make up for it by making renewals really expensive, but malware vendors or spammers don't have to worry about that.

anthonypants fucked around with this message at 02:43 on Sep 19, 2017

mewse
May 2, 2006

Three-Phase posted:

General ITSEC question - how do criminals afford "junk domains" or whatever you'd call them to host malware/spyware or do command and control and so forth? A single .com domain can be like $10 or more a year, how do they register dozens or hundreds of "kj9fslidjflskdjgflkjdfg dot zyx" or whatever domains?

Or are there just really, really shady registrars that are like "LOL OK here's a thousand domains whatever"?

I registered a .stream domain for 10 years for $2/year

Three-Phase
Aug 5, 2006

by zen death robot
I did have one other question and frankly I didn't see any other category on SH/SC for this kinda' thing (if there is a better thread for this PLEASE point it out to me!)

Do you guys have any suggestions on companies that will just hold a domain name(s) for someone without hosting? Just to hold the domain name and do privacy protection for the WHOIS stuff. I was looking at moving domains to NameCheap but I am not sure if you can just transfer them domains without hosting.

Volguus
Mar 3, 2009
I don't think any of the registrars force you to take hosting. Just buy the domain name (may or may not get free WHOIS privacy, depending on promos and stuff) and think about hosting and other stuff later.

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


Yeah I'm sitting on like 3 domains because I thought about maybe doing something with them some day. They're cheap.

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


Do registrars still allow domain preview? I know that was how malware used to pick up their domains.

Three-Phase
Aug 5, 2006

by zen death robot

duz posted:

Do registrars still allow domain preview? I know that was how malware used to pick up their domains.

Like a "try before you buy" or a refund on domains? Sounds like a really bad idea...

PS - thanks for the information and help you guys have been providing - I appreciate it.

mewse
May 2, 2006

FWIW my fav registrar is Gandi and they bundle whois protection into their prices. Hosting is completely optional.

yoloer420
May 19, 2006

duz posted:

Do registrars still allow domain preview? I know that was how malware used to pick up their domains.

The practice was called "domain tasting". ICANN eventually added a $0.20 fee for domains cancelled within the initial five day grace period, which reduced it somewhat as before that it cost nothing. In 2009 they limited it even further, to the point nobody really does it anymore. Now you just buy it for the year and see how it goes.

I run a small domain reseller and absolutely love scammers. They register domains, the domains get suspended, I keep their money :D

Edit: Scammers are bad. Scammers wasting their cash is good.

yoloer420 fucked around with this message at 06:45 on Sep 19, 2017

Furism
Feb 21, 2006

Live long and headbang

I'm traveling this week for work so I can't check at home, but I think I might have installed that version that got hacked (I use it for their "secure delete" of files feature). gently caress. Do we know exactly what it does/did?

Am I glad I 2FA everything...

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

The writeup from Avast claims that they neutered the C&C servers before any kind of payload could occur, though how they are actually confirming that claim is a bit of a mystery. It was arbitrary code installed as System so the worst case persistent rootkit is a possibility though considering the visibility they PROBABLY cleaned things up for the majority of users.

Wiggly Wayne DDS
Sep 11, 2010



BangersInMyKnickers posted:

The writeup from Avast claims that they neutered the C&C servers before any kind of payload could occur, though how they are actually confirming that claim is a bit of a mystery. It was arbitrary code installed as System so the worst case persistent rootkit is a possibility though considering the visibility they PROBABLY cleaned things up for the majority of users.
their claim is that of the infected clients that avast covered (~30% of so) they didn't detect a secondary payload. therefore the rest are fine and there's no evidence of a problem

not quite sure how they'd be able to make such a bold claim given the window of infection and degree of invasive analysis required to detect that weeks later, but that's their side of the matter

Wiggly Wayne DDS fucked around with this message at 15:56 on Sep 19, 2017

Adbot
ADBOT LOVES YOU

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?
So, before the hack, why was CCleaner bad? Just placebo software?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply