PDA

View Full Version : GeorgeS Site Infected


Hateborne
01-12-2013, 11:06 AM
I kept getting warnings about the site being infected. Every time I tried to wget the index.html, my company antivirus kept INSTANTLY deleting the file. I finally loaded up a VM Ubuntu, did a wget -m on the site, and found a nasty bit of code inserted into the bottom of the index.html file. It is resolving to a russian site. Which actual infection set they are using, I cannot say for sure.

GeorgeS if you are reading this (or if some one knows how to get in touch with him), your webserver has been tamperered with and the index.html has been modified. I had a few other files threw up warnings of possible infections with ESET's NOD32. Sometime this weekend I will swipe all the files from your site, scan them, and dump the clean ones on my site (www.hateborne.com). I will create a folder named "georgeS" under the eqemu branch on my site for them.

Thanks in advance for checking into this.

-Hate

c0ncrete
01-12-2013, 11:22 AM
it's been that way for some time, which is why he is hosted here now:

http://www.georgestools.chrsschb.com/

Hateborne
01-14-2013, 02:02 PM
Ah ok, thank you for the heads up. Can the other one be destroyed or brought down? (Or maybe have the provider simply forward the address to the new one?)

Or is there more of a story here? (a.k.a 'leave it be')


-Hate