![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 | |
Confirmed User
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
|
Estdomains Is Behind The Trojan!
So I am here to bust out the people behind this... From a post on adx by DanS where he pointed out that surfers were being redirected to a codec download on assisass.com I found the domain that the codec was being downloaded from...
The domain also has other exploits so I am not going to post the url but I will post the IP... 216.255.179.125 Some investigation of this ip revealed that it resolves to an ISP called InterCage... From an earlier post you will find that the people that discovered the trojan at the University of Minnesota discovered that the varient that they wrre analyzing was being hosted by InHosters and they determined that InHosters was being run by a crime ring from the Ukraine. http://lists.sans.org/pipermail/unis...er/026937.html After digging a little deeper into Intercage I discovered that they have been blacklisted and accused of many crimes... including hijacking proxies and whole netblocks... http://spamhuntress.com/wiki/Dyakon http://blogs.zdnet.com/Spyware/?p=752 I did a whois on the domain serving the trojan and discovered that it was registered via ESTDOMAINS... there have been many posts on adx about the onslought of cheaters that have appeared over the last few months that were registered via ESTDOMAINS... the odd thing about most of these cheaters is that the traffic doesn't necessarily look like cheater traffic... it doesn't always have alot of proxy and it generates clicks... I think it's already been posted that this trojan generates fake traffic. And then I hit the motherload... InHosters, Estdomains and Intercage are all the same company... http://blogs.zdnet.com/Spyware/?p=763 Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2003
Posts: 22,651
|
Ma.....get muh shotgun...
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Industry Role:
Join Date: Aug 2001
Location: Nomad
Posts: 5,196
|
Estdomains is behind alot of crap, no need to even post it. They are probably one of the biggest spammers on the net
__________________
. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Confirmed User
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Posts: 59,204
|
The Ukraine...what a surprise. Its really time they get their own internet over there thats cut off from the rest of the world.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
So Fucking Banned
Join Date: Mar 2007
Posts: 301
|
Good fucking job man!!!!!
Now like what do we do? I say lets start that coillation against this shit! It is like the war on terror,same shit different towel head! Until all the sponsors get there act together we as webmasters will always run this risk! Problem is will the sponsors play ball? |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
why can't you give a url to the codec download? I have my own reservations about estdomains, but an accusation needs the solid proof, or else you're leaving yourself open for banning....
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 | |
So Fucking Banned
Join Date: Mar 2007
Posts: 301
|
Quote:
Problem is cheater scum not Race/Religion/or region ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 | |
Confirmed User
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
|
Quote:
http://alexa.com/data/details/traffi...m%2Fgoanal.php that won't take you directly to the download but will show you what the url is. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Confirmed User
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 | |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
Quote:
![]() --edit never mind the source shows the links
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
just be careful nation-x - great investigative posting, but the motherload post, even following the links is still circumstantial....
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 | |
Confirmed User
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
|
Quote:
Let's consider the enormity of this for a moment... not only is this rampant ripping off of affiliates (and more then likely programs as well)... it's a HUGE security problem... Those professors estimated that lots and lots of people were infected... it could even be millions since there are no antivirus programs that currently detect the trojan... and judging by the amount of traffic that this one install location gets I would be willing to estimate that it's POSSIBLE that more then a million machines may be infected. Dude... that is a National Security Risk! |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Confirmed User
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
|
btw... I should mention that the codec installer doesn't show up for firefox
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Confirmed User
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
|
and really... ultimately... your posts tell me that you didn't read the mailing list post from Brian Eckman... he plainly says that the thing is controlled by InHost... Inhost = Estdomains...
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
Don't get me wrong - it IS serious shit, and a lot of major players couldn't give a toss. There are some out there that are actively trying to combat this problem.
I infected a puter with the trojan, and tested it out, and in my tests the first click had a refcode changed, which stuck. If the link had no refocde in it, it appeared unchanged, but when it got the the processor, a new refcode got added. The refcode appeared to change randomly though, which was weird. HOWEVER - there is a current easy workaround for this trojan, and with a bit more implementation, will protect for a few more revisions. I'm not posting what the solution is on a public board, but it is a payside server-side implementation that will protect all affiliates. Funny though how some big guys don't seem to care about it ![]()
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 | ||
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
Quote:
Quote:
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
So Fucking Banned
Join Date: Feb 2007
Location: Australia
Posts: 571
|
Nice work man
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 | |
Confirmed User
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 | |
in a van by the river
Industry Role:
Join Date: May 2003
Posts: 76,806
|
Quote:
I think if this is true and enuff of us bitch we can at least get epass and paypal to pull the plug on them.
__________________
In November, you can vote for America's next president or its first dictator. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 | |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
Quote:
![]()
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
Confirmed User
Join Date: Nov 2005
Posts: 2,167
|
Don't have time to read it all (read only your initial post), but because they are registered through estdomains, estdomains is behind it? Is that what you're saying?
__________________
agentGFY *at* gmail.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 |
So Fucking Banned
Join Date: Mar 2007
Posts: 301
|
PLEASE SEE THREAD:ANTI SPYWARE COALITION!!!!!!!
Why can't we form a group, say the " anti spyware coalition ". Why can't affiliates donate $50 a month to this and sponsors donate $500 a month. If just 100 affiliates anti up and just 10 sponsors that is $10,000 a month. apoint a board, hire a couple full time well qualified anti spyware people to start working on this. 10K a month should hire a couple really qualified people. the more people who join the group the lower we can reduce the fees. $50 x 100 is the same as 1000 x $5 so fees could be lowered as more people join and/or more people could be hired to work on it. If you make even $1,000 a month what is $50 to help fight this. Sponsors, if you make millions a month what is $500 ? |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 | |
Totally Borked
Industry Role:
Join Date: Feb 2005
Posts: 6,284
|
Quote:
It's not rocket science.... yet it requires a bit of backend work, which most don't want to do, until that is enough affiliates start talking up....
__________________
![]() For coding work - hit me up on andy // borkedcoder // com (consider figuring out the email as test #1) All models are wrong, but some are useful. George E.P. Box. p202 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 |
So Fucking Banned
Join Date: Mar 2007
Posts: 301
|
Anti Spyware Coalition.
PLEASE SEE THREAD AND SIGN THE FUCK UP!!!!!!!!!!!!! ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 |
Confirmed User
Industry Role:
Join Date: Dec 2005
Posts: 410
|
Fuck those homos... I hope someone stops them up.
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 |
So Fucking Banned
Join Date: Dec 2006
Posts: 440
|
where is Ukraine?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#28 | |
Too lazy to set a custom title
Industry Role:
Join Date: May 2004
Location: West Coast, Canada.
Posts: 10,217
|
Quote:
http://www.gofuckyourself.com/showthread.php?t=573522 |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 |
Confirmed User
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
|
it funny how this shit has turned out to be all interconnected
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#30 |
Confirmed User
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
|
I am amazed at the lack of response I am seeing to these threads...
|
![]() |
![]() ![]() ![]() ![]() ![]() |