WoWInterface

WoWInterface (https://www.wowinterface.com/forums/index.php)
-   Chit-Chat (https://www.wowinterface.com/forums/forumdisplay.php?f=2)
-   -   VIRUS!! ui.worldofwar.net again (https://www.wowinterface.com/forums/showthread.php?t=18813)

syrupk 10-21-08 02:24 PM

VIRUS!! ui.worldofwar.net again
 
http://www.virustotal.com/analisis/7...f0fbff035f9e8a

there is the viruses and keyloggers from a stolen version of metz remix, and a wowace upddater file at ui.worldofwar.net.

Can anyone help us take care of this. No one at the site is doing anything about it and we are getting harassed on the wowUI forums. I made posts on their sites interface forum and nothing :(

Tekkub 10-21-08 03:22 PM

****, and here I am with no popcorn.

Petrah 10-21-08 04:11 PM

Rushster = Cowan :mad:

syrupk 10-21-08 04:27 PM

http://www.worldofwar.net/forums/sho...d.php?t=418214

Please help me fight back guys they are calling me a liar now? :*(

Bikther 10-21-08 04:44 PM

I thought it was established a while ago that ui.worldofwar.net wasn't a site to be trusted. I think it was just as 2.0 came out that a large number of complaints of virus' started popping up about that site.

syrupk 10-21-08 04:46 PM

Quote:

Originally Posted by Bikther (Post 106048)
I thought it was established a while ago that ui.worldofwar.net wasn't a site to be trusted. I think it was just as 2.0 came out that a large number of complaints of virus' started popping up about that site.

Lots of people still use that site, though not me. One of the virused files over there is a UI I uploaded to here that got stolen and put over there. I'm making it my business because it has to do with me.

Not to mention, not everyone knows not to go there.

Elloria 10-21-08 04:47 PM

Quote:

Originally Posted by Bikther (Post 106048)
I thought it was established a while ago that ui.worldofwar.net wasn't a site to be trusted. I think it was just as 2.0 came out that a large number of complaints of virus' started popping up about that site.

Imo we should write blizzard and complain. A site like this should stay operating. The virus scanners they use apparently don't catch some things.

Petrah 10-21-08 04:47 PM

Quote:

Originally Posted by syrupk (Post 106037)
http://www.worldofwar.net/forums/sho...d.php?t=418214

Please help me fight back guys they are calling me a liar now? :*(

Create a video while downloading the files from their site, opening them, and uploading the infected files to VirusTotal. Then upload to YouTube, and tell em to kiss your ass.

syrupk 10-21-08 04:49 PM

I really really hope this makes their entire site go down the tubes. We will never now how many files are infected with this thing over there.

Cairenn 10-21-08 04:56 PM

Warning others about this is good. However, do please remember the rules of THIS site. No flaming.

syrupk 10-21-08 04:56 PM

Quote:

Originally Posted by Cairenn (Post 106057)
Warning others about this is good. However, do please remember the rules of THIS site. No flaming.

Sorry Cairenn, i'm really really really really mad :(

Xinhuan 10-21-08 04:58 PM

What's more ridiculous is the

Quote:

Virus/spyware scanned on upload
banner at the top of every addon they host!

Edit: Whoa first post! (Even though I joined this site over 20 months ago!)

Cairenn 10-21-08 04:58 PM

I know and I understand. Keep it civil regardless dear. :)

*hugs syrupk*

Tekkub 10-21-08 05:00 PM

**** "civil"... I don't have any popcorn!

Cairenn 10-21-08 05:01 PM

*hands tekkub some bacon*

syrupk 10-21-08 05:02 PM

Your guys' support means very very much to me. I don't know why it upsets me so much because the guy fortunately didn't make an account with my name or anything. The UI community is very important to me and I hate seeing people get treated this way.

Tristanian 10-21-08 05:22 PM

I was personally willing to give them the benefit of the doubt until today, but this is a fraking travesty really.

*Hides in corner, staying silent, to avoid flaming*

syrupk 10-21-08 05:26 PM

Theres responses now, lets see what they do for damage control.

Xinhuan 10-21-08 05:29 PM

Quote:

Originally Posted by syrupk (Post 106037)
http://www.worldofwar.net/forums/sho...d.php?t=418214

Please help me fight back guys they are calling me a liar now? :*(

Appears your thread got deleted. :mad:

Tekkub 10-21-08 05:30 PM

Quote:

Originally Posted by Xinhuan (Post 106070)
Appears your thread got deleted. :mad:

That's their standard damage control there.

syrupk 10-21-08 05:31 PM

They moved it to the other ongoing thread.

Seerah 10-21-08 06:26 PM

ah. here it is: http://www.worldofwar.net/forums/sho...d.php?t=418210

with a reply from Rushter: "It wasnt an exe, it was a zip :)"

wulfy27 10-21-08 06:43 PM

Quote:

Originally Posted by Tekkub (Post 106071)
That's their standard damage control there.

:rolleyes:

Maybe their doing "their" best. It's not warm and cozy everywhere you know.

Cralor 10-21-08 07:11 PM

Quote:

Originally Posted by Seerah (Post 106078)
ah. here it is: http://www.worldofwar.net/forums/sho...d.php?t=418210

with a reply from Rushter: "It wasnt an exe, it was a zip :)"

...... :mad:

Cairenn 10-21-08 07:15 PM

Easy, guys ....

Tekkub 10-21-08 07:16 PM

where Is My ****ing Popcorn?

*edit* also the de-caps-ing that this forum does sucks.

Cairenn 10-21-08 07:19 PM

Oh bite me, tek. :p

Tekkub 10-21-08 07:20 PM

You know I only like MALE meat :P

Cairenn 10-21-08 07:21 PM

*grins* ;)

Yhor 10-21-08 07:34 PM

Reading through the 'blue' responses really makes me appreciate the 'Red and Orange' responses we get here :)

Thanks for letting this f'oob into the community here at WoWI :D

Cairenn 10-21-08 07:35 PM

Awww, thanks Yhor. :o

Xinhuan 10-22-08 06:13 AM

Warning: New "Curse Updater" on wowui

http://wowui.worldofwar.net/?p=mod&m=6663

Virus alert!

Zyonin 10-22-08 06:34 AM

Seeing all that crap on ui (again) makes me glad I left that place after the Ace mirroring fiasco. I was one of the more prominent members there and was even a candidate for a moderator. It seems they still don't learn. Note this is not trying to bash ui, its just my thoughts.

That "Curse Client" upload there just screams "Trojan!" to me. I doubt that ui would allow a "competitor" to upload nor do I think Curse would upload their software to a third party site.

Dridzt 10-22-08 07:48 AM

Quote:

Scanning Report

22 October 2008 16:28:25 - 16:28:28

Computer name: ----
Scanning type: Scan target
Target: Addons\30000\CurseUpdaterzip-1224675514.zip
Result: 1 malware found

Trojan-Spy.Win32.Ardamax.n (virus)
That's from F-Secure Client Security.

There's one thing that needs saying though.

Always in the past when one site found itself in the crosshairs,
it indicated an increase in activity by those that try to upload malware
on ALL addon hosting sites.

It seems it's not an isolated incident.. there's multiple malware uploads
at wowui even after all the ruckus has started and their staff is supposedly "alerted".

The weakest link is the first to break (wowui constantly in the recent period)
but it should sound the alarm for other addon sites as well to enhance their vigilance.

Xinhuan 10-22-08 07:53 AM

Quote:

Originally Posted by Lykofos (Post 106183)
Seeing all that crap on ui (again) makes me glad I left that place after the Ace mirroring fiasco. I was one of the more prominent members there and was even a candidate for a moderator. It seems they still don't learn. Note this is not trying to bash ui, its just my thoughts.

I left the wowui site 3 years ago. I was their Mage class webmaster/moderator, and also had FTP access to their worldofwar main page website.

While I still have 2 addons uploaded at wowui since 3 years ago, I have not uploaded any new ones since then, I only keep them updated so as to have less support issues of un-updated addons.

They just keep repeating their mistakes again and again.

syrupk 10-22-08 08:04 AM

I guess I don't really understand why they are allowing uploads if they have done nothing to fix the problem.

Evolution85 10-22-08 09:22 AM

Stuff like this is the reason the ONLY add on and mod site I trust is this one!

Cladhaire 10-22-08 09:58 AM

Quote:

Originally Posted by Evolution85 (Post 106218)
Stuff like this is the reason the ONLY add on and mod site I trust is this one!

To be fair any site can have issues, including this one. The important thing is educating the users and making sure they have the knowledge and information necessary in order to make informed decisions.

No system is bulletproof. Computers fail, humans get lazy, it happens. How you react to the issue is almost as important as the fact that the issue happened in the first place. I'm glad to see WoWUI is finally getting around to removing the files in question.

tinyu 10-22-08 10:18 AM

Quote:

Originally Posted by Cladhaire (Post 106224)
To be fair any site can have issues, including this one. The important thing is educating the users and making sure they have the knowledge and information necessary in order to make informed decisions.

No system is bulletproof. Computers fail, humans get lazy, it happens. How you react to the issue is almost as important as the fact that the issue happened in the first place. I'm glad to see WoWUI is finally getting around to removing the files in question.

thank you for saying that.

Taffu 10-22-08 10:32 AM

Cladhaire is absolutely correct.

But, I think the thing that bugs most users is that the devs on ui.worldofwar.net seem more intent during the initial hours of a security breach return-slinging mud at the users on their forums and firing back with "It's ok/Don't worry" rather than immediately (regardless of immediate "testing/scanning" of their servers) putting notices & possibly shutting down the ability to download the suspected AddOns.

I personally was breached from an AddOn from worldofwar.net back in the day (Benecast) that resulted in the loss of everything my wife & I's accounts had. I think users/players simply expect a little better of a turnaround & attitude from the site devs in regards to the situation. Sure, someone might seem out of hand with spamming the forums and whatnot regarding the issue, but among the camaraderie with the AddOn/UI Community, we're simply looking out for one another by informing folks through the most immediate way we know how. The users cannot post the news or shut down the AddOns in question...so they resort to Comments/Forums/Etc. to get the news out. Each time this has happened, I think the community as a whole has been more judgemental not that it happened in the first place, but in how the situation was handled.

Just my 2 cents on the subject... ;)

Evolution85 10-22-08 11:34 AM

Quote:

Originally Posted by Cladhaire (Post 106224)
To be fair any site can have issues, including this one. The important thing is educating the users and making sure they have the knowledge and information necessary in order to make informed decisions.

No system is bulletproof. Computers fail, humans get lazy, it happens. How you react to the issue is almost as important as the fact that the issue happened in the first place. I'm glad to see WoWUI is finally getting around to removing the files in question.

True....

But some sites work harder then others. Having been a victim of the allakhazam debacle several years ago and having my account compromised from it I am EXTREMELY wary of most sites. I have seen what happens here when a attempt is made to pass an infection to users.

Wow Interface should be the example that all should follow. At least thats my opinion and I stand by it...

Tsurani 10-22-08 05:15 PM

Just to compile the important posts into one:



That's right three viruses in two days. :eek:

Looks like the same people this time pretending to be the Curse Updater. Please don't be fooled into downloading this one either.

F-Secure Client Security says:

Code:

22 October 2008 16:28:25 - 16:28:28
Computer name: ----
Scanning type: Scan target
Target: Addons\30000\CurseUpdaterzip-1224675514.zip
Result: 1 malware found

Trojan-Spy.Win32.Ardamax.n (virus)

The relevant forum thread here is http://forums.wowace.com/showthread.php?t=14710



Just to clarify:

NO ONE from Curse had anything to do with this, I've reported it to have it taken down.


More Intel:

File is/was a fake. The readme.txt in the archive is a verbatim copy of the wikipedia entry on Kafka and the only other file is a file called MetzRemix.exe which is virus/trojan infected. This has nothing to do with the curse client nor does it have anything to do with the real MetzRemix which is an actual UI compilation, and everything to do with someone trying to trick people into installing a trojan by using a fake association.

The offending poster Quarenteen (http://wowui.worldofwar.net/?p=profile&u=411659) faked being WoWAce and Curse. WoWUI has claimed to have banned that user now. I hope they share IP with wowinterface and curse to avoid that the same folks try other ways to trick people again (without at least switching IP addresses).


All times are GMT -6. The time now is 05:40 PM.

vBulletin © 2024, Jelsoft Enterprises Ltd
© 2004 - 2022 MMOUI