Item Search
     
BG-Wiki Search
+ Reply to Thread
Page 1 of 15 1 2 3 11 ... LastLast
Results 1 to 20 of 286

Thread: Don't be stupid.     submit to reddit submit to twitter

  1. #1
    Relic Horn
    Join Date
    Oct 2005
    Posts
    3,144
    BG Level
    7
    FFXI Server
    Unicorn
    WoW Realm
    Shattered Hand

    Don't be stupid.

    http://img160.imageshack.us/img160/9154/whatnow3uz.jpg

    Now for the story of how I managed to get this pic...

    Who remembers seeing those generally vague posts about Parsers/Bots with links to exes named POS_Logger.exe and DamageProc.exe? Viruses of course, cue the picture of "This guy seems legit" that priran posted. Anyway using a trick that aurik (don't tell anyone what it was, I plan on doing this again if he makes another post) showed me I managed to get the contents of the exe in a somewhat readable format. I located the IP of the server that the trojan horse phoned home to and ran a quick portscan to see what services were running on it. Found: Port 21 (FTP). So I go back and dig through the exe and find 2 lines in there:

    Admin
    gGPaK45w

    I did what any normal geek would do and logged in to his FTP and started poking around. Tons of porn, some Final Fantasy Roms, some Music but whats this...a folder called accounts? Jackpot. I tried to copy as much as I could, but by 1pm Central today he found out I was leeching his server hard (over 1000 folders in that directory, and FTP doesn't like transfering tons of small files so it went sloooow) and I got shut out. I started with the old ones in april (stupid me), and moved up to the newer ones. I made it up to June 14th. All in all I'd guess about 8-12 different computers were compromised, I'm not sure how many were compromised from yesterday's posting as I didn't make it up the logs that far =(. These 1000+ folders were all filled with keylogs, detailed records of every keystroke done on the compromised machine. Thats a ton of shit to look through.

    Anyway some of you may know Totien. I'm sure he's wisened up by now and is using a password a little more secure than "budlight" lol. Accodring to what I see here his machine was compromised on April 18th of this year.

    I've got a lot more interesting tidbits I found out about in here, but I'm not going to compromise ANY accounts if I find any passwords, rather I will do everything I can to contact that person and have them prevent anything happening to their character.

    So far I've found:
    Morie - Bahamut server
    Totien - Not sure what server but its too late =(
    Etern - Bahamut server (japanese)
    Avid - Bahamut? (japanese)
    Pyoi - Bahamut Server (japanese in zigma's Wyrm Shell lol) it is also possible Akuby was compromised as a result of this since it loos like Pyoi and Akuby are the same person from the information I have, or they share accounts/computers.

    Anyway, I'll update this as I find more. Theres is just way too much stuff to sort through. If you are on bahamut please contact these people and instruct them to do a full wipe of their computer.


    VIRUS SCANS DO NOT DETECT THIS TROJAN HORSE

  2. #2
    Smells like Onions
    Join Date
    Jan 2006
    Posts
    6
    BG Level
    0

    You are amazing good sir

  3. #3
    Cerberus
    Join Date
    Oct 2005
    Posts
    439
    BG Level
    4
    FFXI Server
    Diabolos

    Old. I heard about this last night...

    ...but probably since you were on TheIRC with us. Took you long enough to type this up.

  4. #4
    New Spam Forum
    Join Date
    Nov 2004
    Posts
    154
    BG Level
    3

    Holy mother, good detective work.

  5. #5

    wow....

  6. #6
    Vobent
    Guest

    A winnar is you.

  7. #7

    Wow... You are teh winRAR

  8. #8
    Relic Shield
    Join Date
    Sep 2004
    Posts
    1,726
    BG Level
    6
    FFXI Server
    Bahamut

    I was wondering what was up with this epidemic of people /telling me links to trojans. Valintino's account got compromised too I think..

  9. #9

    Good job.

    Where were these .exe's at that you were talking about? You said they were posted on here?

  10. #10
    Banned.

    Join Date
    Dec 2005
    Posts
    15,022
    BG Level
    9

    Old. I heard about this last night...
    Then how is it old?

    Anyway, awesome lawl ;o.

  11. #11
    Bagel
    Join Date
    May 2005
    Posts
    1,300
    BG Level
    6
    FFXI Server
    Sylph

    mr argus flee tool and POS




    anyways, good job thats some CSI shit lol

  12. #12

    Is there any way to tell or even be vaguely aware of the presence of this Trojan on your computer?

  13. #13

    Dezzimal, Could you post a Mirror of one of the Infected files so I can look at it?

  14. #14
    Relic Shield
    Join Date
    Nov 2004
    Posts
    1,553
    BG Level
    6
    FFXI Server
    Bahamut

    What do you mean by "it's too late"?

  15. #15
    Relic Horn
    Join Date
    Oct 2005
    Posts
    3,144
    BG Level
    7
    FFXI Server
    Unicorn
    WoW Realm
    Shattered Hand

    Quote Originally Posted by Mifaco
    I was wondering what was up with this epidemic of people /telling me links to trojans. Valintino's account got compromised too I think..
    Yes Valintino is in here. Have him change his xdeathasylum.com password too.

  16. #16
    Salvage Bans
    Join Date
    Nov 2005
    Posts
    953
    BG Level
    5
    FFXIV Character
    Oro Oro
    FFXIV Server
    Hyperion
    FFXI Server
    Titan

    Quote Originally Posted by Parshath
    Is there any way to tell or even be vaguely aware of the presence of this Trojan on your computer?
    lol i guess if you have pos/fleetool/mrargus that's probably a good indication.

  17. #17
    Been Here Longer Than you
    Join Date
    Jan 2005
    Posts
    29,562
    BG Level
    10

    Plz stop giving away my gil secrets.

  18. #18
    Old Merits
    Join Date
    May 2005
    Posts
    1,210
    BG Level
    6
    FFXI Server
    Asura

    Nice work, one of the reasons why I'm scared to actually download a parser. And LOL at all those pos/flee/argus pics.

  19. #19

    My mummy always said cheaters never prosper.

  20. #20
    Relic Horn
    Join Date
    Oct 2005
    Posts
    3,144
    BG Level
    7
    FFXI Server
    Unicorn
    WoW Realm
    Shattered Hand

    Quote Originally Posted by Ichthyos
    Quote Originally Posted by Parshath
    Is there any way to tell or even be vaguely aware of the presence of this Trojan on your computer?
    lol i guess if you have pos/fleetool/mrargus that's probably a good indication.
    The best way in my opinion would be an external firewall that can monitor what is getting sent where without the interference of being run on your computer where it it totally voulnerable to being compromised by the Virus/Trojan. Best defense by far though is the thread title. Don't download random .exes from people you don't know (and sometimes even people you do know).

+ Reply to Thread
Page 1 of 15 1 2 3 11 ... LastLast

Similar Threads

  1. If you're on Kujata don't be a dumbass: Pic inside.
    By *Shinzon* in forum FFXI: Everything
    Replies: 8
    Last Post: 2008-04-15, 22:42
  2. stupid speculation I shouldnt be making topics about
    By Overdrive_Bismark in forum FFXI: Everything
    Replies: 3
    Last Post: 2006-10-18, 13:21