Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


Tel69

Tel69
261 posts

Ultimate Geek

Trusted
Lifetime subscriber

#44003 23-Oct-2009 18:42
Send private message

Hi all,

I have an interesting one. I got a malware link via a spam e-mail.
It was VERY amateur it say the least. (In the form in ftp://user:pass@11.1.1.1/randomnumber.htm

So I used my FTP client to get the file and sure enough on total antivirus a 20% hit rate for a malware downloader.
Looking at the html it's encrypted. (Haven't figured how yet)
Soooo, I downloaded the whole site.
Then I renamed the randomnumber.htm to r.htm on the site so no-one could get to the malware link.
On investigating the sites other pages, loads of encrypted pages, loaded of porn banners.

I'm wondering if I should just delete the whole site via FTP.
This is not an ethical debate on wether or not I'm perceived as hacking following a link sent to me by malware (Which just happened to contain the username and password DUH!), but more an ethical debate on if I should kill the whole site to stop the idiots who would click on links like that for the site.

Cheers,
Tel
EDIT : fixed some typos and clarified.

Create new topic
Tel69

Tel69
261 posts

Ultimate Geek

Trusted
Lifetime subscriber

  #266438 23-Oct-2009 18:55
Send private message

Oh, the site is in turkey, so they are not up yet, BUT each time I connect when I disconnect I change my IP.
You gotta be safe especially downloading a malware installers complete site. :)



zocster
1983 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #266447 23-Oct-2009 19:25
Send private message

Dodgy, have a read at this and this.




 

Andy Ghozali
Geekzone Member

Logo
E: andy@ghozali.ru
M: +64 21 395 458
A: Andy's Business Services, 231 High St, Christchurch 8011, NZ
www.andy.mobifacebook icon linkedin icon instagram icon 

Tel69

Tel69
261 posts

Ultimate Geek

Trusted
Lifetime subscriber

  #266458 23-Oct-2009 20:05
Send private message

Interesting.
The ftp server running this is FileZilla Server, but strangely enough their site has been majorly done over with heaps of malware http code and porn site banners and a "mass_send.php" in a whole load of directories.

I'd say your right, it was a legit site but has been compromised, probably by your first link.
The IP address itself seems to be a user of "Radore Telekomunikasyon" in Turkey.

Your thoughts on should I go to the effort to force the admin of this FTP server to look at their security?
(Read delete everything off the site as it's almost all malware and porn links now)



zocster
1983 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #266463 23-Oct-2009 20:39
Send private message

hmm i guess if you're kind enough to spend time, sure why not let them know. from the articles i read, I think not saving ftp password on your local machine is a good start lol.




 

Andy Ghozali
Geekzone Member

Logo
E: andy@ghozali.ru
M: +64 21 395 458
A: Andy's Business Services, 231 High St, Christchurch 8011, NZ
www.andy.mobifacebook icon linkedin icon instagram icon 

Tel69

Tel69
261 posts

Ultimate Geek

Trusted
Lifetime subscriber

  #266475 23-Oct-2009 21:28
Send private message

Yes it definately is Andy, lol.
I think this should serve as a warning for the person who runs the ftp site. (saved as warning.txt on the FTP site)

"Your security is comprimised.
Change ALL your FTP, online (Internet banking and the such passwords) and your local user passwords on the machine.
Then use SFTP as opposed to open FTP from now on."

Hopefully that should give them an idea they have been compromised.

Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.