LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-28-2011, 05:19 AM   #1
qrange
Senior Member
 
Registered: Jul 2006
Location: Belgrade, Yugoslavia
Distribution: Debian stable/testing, amd64
Posts: 1,061

Rep: Reputation: 47
forum hacked, noscript disabled


I browsed forum 'cadtutor.net' which have been hacked to "serve" malware.

noscript was disabled for that site, should I worry about catching a virus on Debian?
 
Old 02-28-2011, 08:35 AM   #2
stress_junkie
Senior Member
 
Registered: Dec 2005
Location: Massachusetts, USA
Distribution: Ubuntu 10.04 and CentOS 5.5
Posts: 3,873

Rep: Reputation: 335Reputation: 335Reputation: 335Reputation: 335
How do you know that the site was hacked? If you know that then you may be able to find what malware was involved. That would tell you if you may have a problem.
 
Old 02-28-2011, 08:37 AM   #3
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
Can you be more specific regarding the exploitation of the site? I have used cadtutor in the past and found it to be a good resource. I am sorry to hear that they are having potential trouble.

If you were running Debian Linux, your chances of being infected with operable mal-ware are small. This assumes, of course, that it was targeting Windows mal-ware which 99.99% of it is. If you were running as a regular user, not as root, the chances of you being permanently infected are exceedingly small. Clear out your browsers cache, cookies, etc, and reboot and things should be clear. You can always run an anti-virus scan to see if you have anything left over. The bigger risk is that you may pass an infection on to a Windows system and this would help in that regard as a precaution.

Last edited by Noway2; 02-28-2011 at 08:37 AM. Reason: Added Windows mal-ware comment
 
Old 02-28-2011, 06:09 PM   #4
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by qrange View Post
I browsed forum 'cadtutor.net' which have been hacked to "serve" malware.

noscript was disabled for that site, should I worry about catching a virus on Debian?
An actual virus (in the technical sense) on GNU/Linux is quite unlikely. However, there may have been some other type of malware. On what date exactly did you visit the site with NoScript disabled? What browser (and version number) where you using? Were the rest of the installed packages up-to-date? Did you use your primary account on your computer or a dedicated/disposable account? Have you found any information that would indicate the type of malware that was being issued on the site? Answers to these questions would help us gauge your risk level from exposure. Of course, there's no replacement for the use of automated scanning tools and/or keen observation/analysis.

Quote:
Originally Posted by stress_junkie View Post
How do you know that the site was hacked?
My guess is it's because of this discussion.

Last edited by win32sux; 02-28-2011 at 06:13 PM.
 
Old 03-01-2011, 01:03 AM   #5
qrange
Senior Member
 
Registered: Jul 2006
Location: Belgrade, Yugoslavia
Distribution: Debian stable/testing, amd64
Posts: 1,061

Original Poster
Rep: Reputation: 47
thanks for replies.
I had posted a question on cadtutor on 25 febrary and browsed it around that time, using latest Debian testing.
Google set me in 'panic mode' with its report. However now it doesn't report site is hacked.
It seems that they had problems in january too.

I'm gonna delete bunch of sites from my noscript now, to be safe.
Except for linuxquestions.org.
If this forum ever gets a virus, it will be probably end of the world, anyway.
 
Old 03-18-2011, 06:43 AM   #6
qrange
Senior Member
 
Registered: Jul 2006
Location: Belgrade, Yugoslavia
Distribution: Debian stable/testing, amd64
Posts: 1,061

Original Poster
Rep: Reputation: 47
now the cadtutor site redirects to some "Emily Myers" pottery. WTF?
do you all have this problem?
 
Old 03-18-2011, 08:00 AM   #7
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
No, cad tutor comes up just fine for me (tried at 9am EDT) and even browsed around a few tutorials. Do you have some example URLs and / or IP addresses? What happens if you do an nslookup from your PC of these URLs? Also try against another DNS like Google (8.8.8.8). You are going to cadtutor.NET correct?
 
Old 03-18-2011, 08:12 AM   #8
qrange
Senior Member
 
Registered: Jul 2006
Location: Belgrade, Yugoslavia
Distribution: Debian stable/testing, amd64
Posts: 1,061

Original Poster
Rep: Reputation: 47
Angry

yes, I am trying forum on cadtutor.net and get 'not found' page.
if I try www.cadtutor.net directly, it shows a page that looks like this: http://www.emilymyers.com/
url bar shows cadtutor.net.

can you send me email of moderator there, I want to complain.
grr

Last edited by qrange; 03-18-2011 at 08:14 AM.
 
Old 03-18-2011, 10:13 AM   #9
tredegar
LQ 5k Club
 
Registered: May 2003
Location: London, UK
Distribution: Fedora38
Posts: 6,147

Rep: Reputation: 435Reputation: 435Reputation: 435Reputation: 435Reputation: 435
The cadtutor link you give in post #8 works fine for me.
So it is not their fault.

Are you suffering from a variant of the upside-down ternet ?

Otherwise, perhaps your DNS is broken, or you have put something strange in your firewall rules.
 
Old 03-18-2011, 11:01 AM   #10
qrange
Senior Member
 
Registered: Jul 2006
Location: Belgrade, Yugoslavia
Distribution: Debian stable/testing, amd64
Posts: 1,061

Original Poster
Rep: Reputation: 47
I'm at home now and it works normally. no its not 'upsidedown thingy'. I suspect that those *incompetent fools* (sorry, cannot think of better words) at cadtutor decided to play a little game with everyone using proxy.
At work we are FORCED to use corporate proxy+NAT.

many others probably have to use proxies, this is very unprofessional from such big website like cadtutor.

:<
 
Old 03-18-2011, 11:44 AM   #11
qrange
Senior Member
 
Registered: Jul 2006
Location: Belgrade, Yugoslavia
Distribution: Debian stable/testing, amd64
Posts: 1,061

Original Poster
Rep: Reputation: 47
now it doesn't work here either..

edit: they are having DNS problems. guess I need to wait it gets resolved.

Last edited by qrange; 03-18-2011 at 03:10 PM.
 
Old 03-18-2011, 03:47 PM   #12
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
Definitely a DNS problem. Performing an nslookup on cadtutor.net is returning 109.228.20.69 AND 77.72.206.14 in alternating fashion. Both of them reverse lookup to an intermediate service provider, so it would taking additional digging to figure out who is in the error. Since it is alternatively giving right / wrong information, it looks like there are multiple DNS servers, one or more of which has incorrect zone information.
 
Old 03-18-2011, 05:35 PM   #13
tredegar
LQ 5k Club
 
Registered: May 2003
Location: London, UK
Distribution: Fedora38
Posts: 6,147

Rep: Reputation: 435Reputation: 435Reputation: 435Reputation: 435Reputation: 435
Quote:
Originally Posted by Noway2 View Post
Definitely a DNS problem. Performing an nslookup on cadtutor.net is returning 109.228.20.69 AND 77.72.206.14 in alternating fashion. Both of them reverse lookup to an intermediate service provider, so it would taking additional digging to figure out who is in the error. Since it is alternatively giving right / wrong information, it looks like there are multiple DNS servers, one or more of which has incorrect zone information.
OK.
Thanks for the further information.

@qrange

If your DNS (maybe yours, maybe your ISP's) is broken you should not use "internet banking" or similar until you have this issue fully resolved.

I have asked that this thread be moved to "Linux-Security" where better informed members will be able to help you.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
do you use NoScript? newbiesforever General 31 04-02-2010 04:47 PM
My web server has been hacked. SU password has been disabled rcrosoer Linux - Security 11 06-27-2008 02:18 PM
Compuiters hacked via online forum? astromech Linux - Security 19 01-07-2008 11:22 AM
Fedora Core Forum site down or hacked? maximalred General 2 01-15-2005 09:07 AM
SuSE Forum Hacked Adler General 26 10-17-2004 02:21 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:36 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration