eztv.wf | eztvstatus.org
Search title:  
TV Packs only
 
💬

EZTV - Trojan?

Join the conversation
🏠 Forum » General » EZTV - Trojan?
Page 1 of 2 Next › Last »
Posted at 16/06/2007, 01:11
#41143
every time i open the eztv page nod32 comes up with this:

img522.imageshack.us/img522/5153/trojankj3.png

must be hiding in one of your banner ads
Posted at 16/06/2007, 01:19
#41146
1) we don't have ads.
2) we don't have ads.
3) the only iframe we use is when you reply to a thread, the iframe is to show
the previous posts.

so based off that the only solution i can come up with is that nod32 is shit and
doesn't know what it is talking about.
Posted at 16/06/2007, 01:40
#41148
nova, it did happen, then disappeared after we started talking about it on the
irc channel, so someone in there was probably responsible. ive already given
info to bog about it.

the embedded code used the clsid as mentioned in this security bulletin:
messenger.yahoo.com/security_update.php?id=060707
Posted at 16/06/2007, 02:12
#41151
based off that url seems like only yahoo! people are affected by it. i didn't
know yahoo! still existed to be honest.

but it is still an iframe issue, and the only place that uses that is on our
reply to thread page.
Posted at 16/06/2007, 02:24
#41152
nova, see my msgs to you on irc
Posted at 16/06/2007, 02:30
#41155
✎ Quote by novaking
1) we don't have ads.
2) we don't have ads.
3) the only iframe we use is when you reply to a thread, the iframe is to show
the previous posts.

so based off that the only solution i can come up with is that nod32 is shit and
doesn't know what it is talking about.


sorry, i just assumed adblock was hiding them


well - as long as you guys know about it 🙂


edit - if you want a copy of that file, let me know - sitting in quarantine.
Posted at 16/06/2007, 08:43
#41187
just thought i'd register cause tvfan's post made me laugh. i use norton and i
also got a warning pop up. something about a html file. downloader trojan or
something. i've been checking the forums ever since to see if anyone else got
the same thing. and well just now i noticed this post. so it wasnt a photoshop.
just wanna add, your attitude nova isnt very good. not saying you did it on
purpose but you would think you would want to get to the bottom of something
serious like this.

edit - it only ever came up twice btw after i refreshed the page the 2nd time.
wish i had got a screenshot. but i thought norton would of quarantined it but
instead it just deleted it.

btw - i've been a lurker here for a while and its nice to see tvfan being his
nice and usual arrogant self
Posted at 16/06/2007, 08:49
#41189
ok looked in the logs

eztvefnet[1].htm & index[3].htm files.

this was the culprit
h**p://securityresponse.symantec.com/security_response/writeup.jsp?docid=2002-
101518-4323-99
Posted at 16/06/2007, 08:54
#41190
iframe.bof is an exploit for a buffer overrun vulnerability that occurs in
internet explorer v6.0 running on windows xp/2000 computers. it allows to
remotely execute arbitrary code in the vulnerable computer, with the same
privileges as the current user.

iframe.bof is an exploit for a buffer overrun vulnerability that occurs in
internet explorer v6.0 running on windows xp/2000 computers, and allows to
remotely execute arbitrary code in the vulnerable computer, with the same
privileges as the current user.

this vulnerability is rated as extremely critical, according to panda software,
and it is caused due to the way in which internet explorer handles the
attributes src and name in the html tags frame, iframe and embed.

the exploit is included in a malicious web page or in an e-mail message in html
format, which contain executable code. this executable code is automatically
run when a buffer overflow occurs while processing a specially crafted iframe,
frame or embed tag. if exploited successfully, iframe.bof allows to run
arbitrary code, which could be of any nature.

as mentioned above, this exploit is hosted in web pages or included in e-mail
messages in html format. in order to exploit the vulnerability, a malicious
user would have to entice the user into accessing one of those web pages or
opening the e-mail message. some variants of the worm mydoom use this exploit
in order to affect computers.

-----------------------------

*looks at photoshop file* aren't you running ie7?

Posted at 16/06/2007, 09:03
#41191
well im running ie7...........
Posted at 16/06/2007, 09:13
#41194
✎ Quote by one_tjc
every time i open the eztv page nod32 comes up with this:

img522.imageshack.us/img522/5153/trojankj3.png

must be hiding in one of your banner ads



screenshot shows tabs "loading" before eztv, what makes you so sure one of them
are not responsible?

Posted at 16/06/2007, 09:20
#41196
ive been using this site since the very beginning and in that time i've used 3
different anti-virus/spyware programs. never have i had any problem with
trojans, pop-ups or anything remotely like that.

btw brett007, nice going. bad mouthing novaking and tvfan in the same post.
i smell barbecue.
Posted at 18/06/2007, 07:09
#41454
i use nod32, i have no problems at all.
Posted at 18/06/2007, 08:33
#41460
the site was only exposed for a brief period of time.
Posted at 18/06/2007, 10:07
#41465
use etrust, isa & gfi. haven't had any problems from this site, although i am
relatively new to this site. checked my isa sql logs, which logs everything
24/7 and no issues from this site whatsoever since my first access or during
any access thereafter. as torrent sites goes this has to be one of if not
equally the cleanest one i have visited. this is in terms of any and all noisy
data, i.e. any 'unwanted' or 'unnecessary' data of any kind. kudos to the
coders. nice site, well done!
Page 1 of 2 Next › Last »
ssl  EZTV RSS EZTV Status | EZTV API | upload Upload | DMCA: [email protected]