Jump to content


Photo

Malicious Software warnings on Agony site


  • Please log in to reply
15 replies to this topic

#1 Aluchem

Aluchem

Posted 25 June 2013 - 02:44 AM

I'm getting repeated warnings from my Virus software (Avast) about the Agony site, better check that out :)


Posted Image

Back 5 minutes, already causing trouble
- Dybbuch

#2 Aluchem

Aluchem

Posted 25 June 2013 - 03:03 AM

Looks like it is most likely Avast, as I'm getting positives from other sites that don't typically host malware


Posted Image

Back 5 minutes, already causing trouble
- Dybbuch

#3 Silivay

Silivay

Posted 25 June 2013 - 04:39 AM

I use Avast and haven't received any warnings. Are there certain pages?


“Moros' are like dinosaur, you have to hold really still.” ― Deran Francks
BASIC-20101226 * WOLFPACKS-20101228 * FLYBYS-20110212 * COVOPS-20110219 * ADVANCED-20111216

#4 Aluchem

Aluchem

Posted 25 June 2013 - 06:03 AM

No it's just on any page view or refresh, seems to be tied to google api scriptaculous.


Posted Image

Back 5 minutes, already causing trouble
- Dybbuch

#5 Silivay

Silivay

Posted 26 June 2013 - 04:55 AM

I am using the free version of Avast. Perhaps the paid version detects something else. I have used Firefox v21 and v22, maybe a browser difference? I have the noscript addon running, but I have allowed googleapis.com.


“Moros' are like dinosaur, you have to hold really still.” ― Deran Francks
BASIC-20101226 * WOLFPACKS-20101228 * FLYBYS-20110212 * COVOPS-20110219 * ADVANCED-20111216

#6 Aluchem

Aluchem

Posted 27 June 2013 - 02:53 AM

I'm also using the free version of Avast. Post update and there are no warnings, so most likely false positives.


Posted Image

Back 5 minutes, already causing trouble
- Dybbuch

#7 Oweim

Oweim
  • PipPip

Posted 31 July 2013 - 09:03 PM

I'm running McAfee and have gotten the warning (just two days ago)


_______________________________________________________________________________________________
BASIC-20120310

#8 Greygal

Greygal

Posted 01 August 2013 - 03:54 AM

This was sent to me by one of the people receiving virus warnings:

 

W9lpWIh.jpg?1


What you do for yourself dies with you, what you do for others is immortal.

BASIC | WOLFPACKS | ADVANCED | HSSR | EYES OF THE KILLER | STEALTH BOMBRS | FLYBYS | SKIRMISHING | INTERMEDIATE

The only chance you get is the one you take.

Redemption Road - Free Public Roams and Other Events!

Public Chat: Redemption Road - Mailing List: Redemption Roams

Roc’s Rule #286:  A real friend never lets you do anything stupid … alone.

m3gAb3q.png

 


#9 Othran

Othran

Posted 01 August 2013 - 06:58 AM

No offence but unless you have a specific reason for requiring Java (95% of people don't) then you should remove it. If you require Java on a server (its common) then FFS use one of the cut-down versions Oracle now provide for that very purpose - they have cut large chunks of library functions from these versions hence reducing the attack profile.

 

Since Oracle got their hands on Java it has become the most exploited piece of software on PCs. It isn't a risk these days, its a bloody liability.

 

Deinstall it is the only sensible advice, for Oracle have proven they cannot be relied upon to fix "in the wild" exploits promptly.


Today's word is :

MORAL, adj. Conforming to a local and mutable standard of right. Having the quality of general expediency.

#10 Silivay

Silivay

Posted 02 August 2013 - 02:28 AM

The alert might indicate that some content (such as an iframe) was added to the agony-unleashed.com web server that tries to pull a java exploit package from another site. Apache 2 (or Linux) appears to have an unidentified exploit at the present - though I don't know that Agony is running either of those.

 

You might try something like this to look for added modules.

http://blog.sucuri.n...he-modules.html

 

Agree, at least disable Java plugin in the browser. NoScript is really nice as well; although, it will drive you nuts for the first month while you get the white list completed.


“Moros' are like dinosaur, you have to hold really still.” ― Deran Francks
BASIC-20101226 * WOLFPACKS-20101228 * FLYBYS-20110212 * COVOPS-20110219 * ADVANCED-20111216

#11 Othran

Othran

Posted 02 August 2013 - 07:48 AM

NoScript & Adblock+ make browsing much nicer, but rather than just disabling Java plugins you may as well remove Java completely.

 

I haven't seen a single applet in the last 3 years and not even things like LibreOffice still require Java ("Open"Office still does but Oracle controls that, so you'd have to be delusional to use it).


Today's word is :

MORAL, adj. Conforming to a local and mutable standard of right. Having the quality of general expediency.

#12 Zael Serine

Zael Serine
  • PipPip

Posted 02 August 2013 - 09:12 AM

 

 ("Open"Office still does but Oracle controls that, so you'd have to be delusional to use it).

 
What are you getting at? Some people cannot afford Microsoft Office, so Open office is a good alternative.


#13 Dior Saursi

Dior Saursi

Posted 02 August 2013 - 10:23 AM

I'll remove java from my pc when minecraft no longer requires it.

#14 Othran

Othran

Posted 02 August 2013 - 10:31 AM

 

 

 ("Open"Office still does but Oracle controls that, so you'd have to be delusional to use it).

 
What are you getting at? Some people cannot afford Microsoft Office, so Open office is a good alternative.

 

 

OpenOffice has been a pile of junk since shortly after Oracle bought Sun. Just like Java is now junk. Oracle bought Sun in 2010 basically for the hardware/server side of things (although MySQL probably figured high up in the list); they didn't want Java other than to screw up competitors so its been largely abandoned until the last year - even then Oracle are only doing something about it because of bad publicity.

 

LibreOffice is the alternative to OpenOffice; written and maintained by the people who used to develop/maintain OpenOffice (for free) before Oracle told them to fuck off. Naturally, given their distrust of Oracle one of the first tasks for the new "fork" was to remove Java - they're pretty much there now, I've never noticed any loss of functionality but apparently Base still requires Java. Edit - linky for you, can't believe you're still using OpenOffice :) http://www.libreoffice.org/default/

 

@Dior - never played it so wasn't aware it was a java applet.


Today's word is :

MORAL, adj. Conforming to a local and mutable standard of right. Having the quality of general expediency.

#15 Loash

Loash

Posted 02 August 2013 - 11:44 AM

Deinstall it is the only sensible advice, for Oracle have proven they cannot be relied upon to fix "in the wild" exploits promptly.

 

Those of us in Denmark don't have a choice since the NemID system (http://en.wikipedia.org/wiki/NemID) (access to your bank, medical records, etc, etc) is Java based, can't say I like it, but I am stuck with it.


"Face the facts. Then act on them. It's the only mantra I know, the only doctrine I have to offer you, and it's harder than you'd think, because I swear humans seem hardwired to do anything but. Face the facts. Don't pray, don't wish, don't buy into centuries-old dogma and dead rhetoric. Don't give in to your conditioning or your visions or your fucked-up sense of... whatever. FACE THE FACTS. THEN act."
Quellcrist Falconer

#16 Othran

Othran

Posted 02 August 2013 - 12:01 PM

 

Deinstall it is the only sensible advice, for Oracle have proven they cannot be relied upon to fix "in the wild" exploits promptly.

 

Those of us in Denmark don't have a choice since the NemID system (http://en.wikipedia.org/wiki/NemID) (access to your bank, medical records, etc, etc) is Java based, can't say I like it, but I am stuck with it.

 

 

Best bet then is to use some form of "LiveCD" to boot from when you need to access those services. There's plenty of fast-booting Linux distros around or just roll your own.

 

It could be worse - for a while (ages ago) our bank used ActiveX. Now that really IS clueless :D


Today's word is :

MORAL, adj. Conforming to a local and mutable standard of right. Having the quality of general expediency.