• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

Oi Admin

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    Oi Admin

    Just go a Symantec warning when I loaded CUK...

    Code:
    [SID: 25679] Web Attack: Malicious Toolkit Website 17 detected.
    Traffic has been blocked from this application: C:\Program Files (x86)\Internet Explorer\iexplore.exe
    IP address was 62.76.41.19 - couldn't perform a backtrace

    #2
    No warnings here - but I run AdBlocker so maybe an advert on the site?

    Comment


      #3
      Code:
      19.41.76.62.in-addr.arpa. 43200	IN	PTR	62-76-41-19.clodo.ru.
      clodo.ru is a Russian web hosting company. Running their home page through Google Translate clearly illustrates why text should be text, not pixels in images

      Comment


        #4
        Originally posted by NickFitz View Post
        Code:
        19.41.76.62.in-addr.arpa. 43200	IN	PTR	62-76-41-19.clodo.ru.
        clodo.ru is a Russian web hosting company. Running their home page through Google Translate clearly illustrates why text should be text, not pixels in images
        Ummm, could you translate what the code you quoted means and the following comment into slightly easier to understand english for those not so techy. I am interested but your post just went:

        ---- > woooosh
        <chef's head>
        The proud owner of 125 Xeno Geek Points

        Comment


          #5
          Originally posted by chef View Post
          Ummm, could you translate what the code you quoted means and the following comment into slightly easier to understand english for those not so techy. I am interested but your post just went:

          ---- > woooosh
          <chef's head>
          It's a reverse DNS lookup, carried out with the Unix dig command:

          Code:
          dig -x 62.76.41.19
          Given an IPv4 address like ww.xx.yy.zz, one can find out what (if any) domain name is associated with it by looking at the in-addr.arpa domain with the address prefixed in reverse order thus: zz.yy.xx.ww.in-addr.arpa, and this will return a PTR record with the name which, if looked up, would have returned that IP address. In this case, it's a machine at a Russian hosting company. Some of the text on their home page isn't text, it's an image file which happens to include a bunch of pixels that look, to us, like Cyrillic text; but Google can't read that, so although the rest of the page gets translated, that not-actually-text-just-a-picture-of-text remains untranslated.

          The full response from dig (with details relating to my own network slightly modified) is:

          Code:
          dig -x 62.76.41.19
          
          ; <<>> DiG 9.7.3-P3 <<>> -x 62.76.41.19
          ;; global options: +cmd
          ;; Got answer:
          ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 41151
          ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
          
          ;; QUESTION SECTION:
          ;19.41.76.62.in-addr.arpa.	IN	PTR
          
          ;; ANSWER SECTION:
          19.41.76.62.in-addr.arpa. 40704	IN	PTR	62-76-41-19.clodo.ru.
          
          ;; Query time: 3 msec
          ;; SERVER: 192.168.666.1#53(192.168.666.1)
          ;; WHEN: Fri Apr 27 07:46:09 2012
          ;; MSG SIZE  rcvd: 76
          For example, here's another one:

          Code:
          dig -x 46.43.34.11
          
          ; <<>> DiG 9.7.3-P3 <<>> -x 46.43.34.11
          ;; global options: +cmd
          ;; Got answer:
          ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 64022
          ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
          
          ;; QUESTION SECTION:
          ;11.34.43.46.in-addr.arpa.	IN	PTR
          
          ;; ANSWER SECTION:
          11.34.43.46.in-addr.arpa. 86400	IN	PTR	forums.contractoruk.com.
          
          ;; Query time: 46 msec
          ;; SERVER: 192.168.666.1#53(192.168.666.1)
          ;; WHEN: Fri Apr 27 07:49:52 2012
          ;; MSG SIZE  rcvd: 79
          (also slightly modified).

          Comment


            #6
            Originally posted by chef View Post
            Ummm, could you translate what the code you quoted means and the following comment into slightly easier to understand english for those not so techy. I am interested but your post just went:

            ---- > woooosh
            <chef's head>
            Their main selling points ("BUY HERE - WE'RE CHEAP AND WE INJECT MALWARE INTO YOUR WEBSITE!! probably), are in an image and therefore can't be translated so viewers won't know why they should give said hosting company their hard earned dosh... - conversion rates are carp...
            "I can put any old tat in my sig, put quotes around it and attribute to someone of whom I've heard, to make it sound true."
            - Voltaire/Benjamin Franklin/Anne Frank...

            Comment


              #7
              Originally posted by NickFitz View Post
              Techie stuff with the correct answer...

              (also slightly modified).
              Or maybe not...
              "I can put any old tat in my sig, put quotes around it and attribute to someone of whom I've heard, to make it sound true."
              - Voltaire/Benjamin Franklin/Anne Frank...

              Comment


                #8
                Same here Malwarebytes puts up a big red warning when CUK loads.

                This is getting silly now, several times now we've had virus/trojan warnings, the place is riddled with undesirable tulipe.

                I'm outa here!

                Comment


                  #9
                  Originally posted by DimPrawn View Post
                  Same here Malwarebytes puts up a big red warning when CUK loads.

                  This is getting silly now, several times now we've had virus/trojan warnings, the place is riddled with undesirable tulipe.

                  I'm outa here!
                  Oi, Admin! It worked, you can turn it off now

                  Comment


                    #10
                    Originally posted by DimPrawn View Post
                    the place is riddled with undesirable tulipe.
                    That is no way to talk about sas.

                    Comment

                    Working...
                    X