MSFN Forum: Invision Power Board has an exploit? - MSFN Forum

Jump to content



Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Invision Power Board has an exploit? A virus! Rate Topic: -----

#1 User is offline   RJARRRPCGP 

  • MSFN Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 1,154
  • Joined: 13-April 05

Posted 18 November 2006 - 02:13 AM

Someone over at ocforums.com reported getting a virus after logging on to an
Invision Power Board-based message board.

http://www.ocforums....ad.php?t=486916

This post has been edited by RJARRRPCGP: 18 November 2006 - 12:07 PM



#2 User is offline   Martin L 

  • 我叫马丁
  • Group: Patrons
  • Posts: 1,684
  • Joined: 09-July 03

Posted 18 November 2006 - 07:09 AM

please dont make me laugh here...

Quote

Powered by Invision Power Board(U) v1.3 Final © 2003 IPS, Inc.


you really think we still have such an old build running here on msfn...? IPB is nearly finished developing version 2.2 and we are running 2.1.x here on msfn...

And another thing is... that site is using a lot of hacks... and those hacks might have exploits...

So the statement that all the IPB boards are "providing" a virus to its users only applies to that site.

#3 User is offline   RJARRRPCGP 

  • MSFN Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 1,154
  • Joined: 13-April 05

Posted 18 November 2006 - 12:07 PM

View PostMartin L, on Nov 18 2006, 07:09 AM, said:

please dont make me laugh here...

Quote

Powered by Invision Power Board(U) v1.3 Final © 2003 IPS, Inc.


you really think we still have such an old build running here on msfn...? IPB is nearly finished developing version 2.2 and we are running 2.1.x here on msfn...

And another thing is... that site is using a lot of hacks... and those hacks might have exploits...

So the statement that all the IPB boards are "providing" a virus to its users only applies to that site.



No. I believe that a virus writer found an exploit in IPB and managed to inject virus code into the server.
But it appears to only effect Java. (not JavaScript)

Also, I didn't see anything saying if this was an old virus or not. Sounded like a new virus.

The poster over at ocforums.com said that the Java tray icon appears and that it started downloading some data then closed.

I posted this thread, because I have been worried about a virus spree. Because there's a newly discovered exploit that's likely being acted on by a new virus, probably the Workstation service in Windows 2000 SP4 and Windows XP 2002 SP2. (Windows XP 2002 actually is what regular Windows XP non-server is )

I have proof. Look on the box of plain ol Windows XP, it will say 2002. (not the copyright year!)

Apparently 2003 was supposed to be an updated Windows XP, but decided to make a server version only!

This post has been edited by RJARRRPCGP: 18 November 2006 - 12:16 PM


#4 User is offline   Aegis 

  • MSFN Expert
  • PipPipPipPipPipPip
  • Group: Banned
  • Posts: 1,298
  • Joined: 12-March 05

Posted 18 November 2006 - 12:39 PM

Quote

Apparently 2003 was supposed to be an updated Windows XP, but decided to make a server version only!

http://www.x86-secre...u/p46xx/x64.png

This post has been edited by Aegis: 18 November 2006 - 12:40 PM


#5 User is offline   RJARRRPCGP 

  • MSFN Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 1,154
  • Joined: 13-April 05

Posted 18 November 2006 - 07:31 PM

View PostAegis, on Nov 18 2006, 12:39 PM, said:

Quote

Apparently 2003 was supposed to be an updated Windows XP, but decided to make a server version only!

http://www.x86-secre...u/p46xx/x64.png


I forgot to say with the exception of Windows XP 64-bit Edition. I wished that Microsoft made a 32-bit version of it.

#6 User is offline   WBHoenig 

  • Member
  • PipPip
  • Group: Members
  • Posts: 186
  • Joined: 20-March 05

Posted 18 November 2006 - 07:38 PM

View PostMartin L, on Nov 18 2006, 08:09 AM, said:

please dont make me laugh here...

Quote

Powered by Invision Power Board(U) v1.3 Final © 2003 IPS, Inc.


you really think we still have such an old build running here on msfn...? IPB is nearly finished developing version 2.2 and we are running 2.1.x here on msfn...

And another thing is... that site is using a lot of hacks... and those hacks might have exploits...

So the statement that all the IPB boards are "providing" a virus to its users only applies to that site.


I hate when they do that... using 1.3 is really taking your life into your own hands, especially on a big board.

This post has been edited by WBHoenig: 18 November 2006 - 07:38 PM


#7 User is offline   LLXX 

  • MSFN Junkie
  • PipPipPipPipPipPipPipPipPip
  • Group: Banned
  • Posts: 3,399
  • Joined: 04-December 05

Posted 19 November 2006 - 07:07 AM

View PostMartin L, on Nov 18 2006, 08:09 AM, said:

please dont make me laugh here...

Quote

Powered by Invision Power Board(U) v1.3 Final © 2003 IPS, Inc.


you really think we still have such an old build running here on msfn...? IPB is nearly finished developing version 2.2 and we are running 2.1.x here on msfn...

And another thing is... that site is using a lot of hacks... and those hacks might have exploits...

So the statement that all the IPB boards are "providing" a virus to its users only applies to that site.
Your server on the other hand isn't that updated...

Server: Apache/1.3.37 (Unix) PHP/5.1.4 mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 FrontPage/5.0.2.2635.SR1.2 mod_ssl/2.8.28 OpenSSL/0.9.7a
X-Powered-By: PHP/5.1.4

#8 User is offline   #rootworm 

  • Member
  • PipPip
  • Group: Members
  • Posts: 206
  • Joined: 16-July 06

Posted 19 November 2006 - 08:00 AM

x

This post has been edited by #rootworm: 19 April 2007 - 12:08 AM


#9 User is offline   Nuno Brito 

  • .script developer
  • PipPip
  • Group: Members
  • Posts: 259
  • Joined: 11-May 06

Posted 21 November 2006 - 02:32 PM

Don't forget that IPB 2.1.7 also has an integrated antivirus tool:
http://forums.invisi...howtopic=223110

:)

#10 User is offline   gamehead200 

  • SEARCH!!! SEARCH!!!
  • Group: Super Moderator
  • Posts: 7,019
  • Joined: 02-September 02
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 21 November 2006 - 05:11 PM

View PostLLXX, on Nov 19 2006, 09:07 AM, said:

Your server on the other hand isn't that updated...

Server: Apache/1.3.37 (Unix) PHP/5.1.4 mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 FrontPage/5.0.2.2635.SR1.2 mod_ssl/2.8.28 OpenSSL/0.9.7a
X-Powered-By: PHP/5.1.4

Apache is the latest 1.x.x.x version on the server. Yes, PHP should be updated. Maybe xper could take a look at that...

Also, may I point out the current version number for Apache: 1.3.3.7 :w00t:

#11 User is offline   Tarun 

  • Area 5 Investigator
  • Group: Super Moderator
  • Posts: 2,991
  • Joined: 27-January 04
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 21 November 2006 - 05:17 PM

I like how the first link doesn't even point to anything but a dead thread. The fact that it's a vBulletin forum also makes me believe the original link was changed.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users



All trademarks mentioned on this page are the property of their respective owners
Copyright © 2001 - 2011 msfn.org
Privacy Policy