Adblock breaks this site

A file link container. STOP THE VIRUSES!

Discussion in 'Denied Suggestions' started by thr0wback, Jan 2, 2011.

Thread Status:
Not open for further replies.
  1. thr0wback

    thr0wback Apprentice
    Banned

    Joined:
    Dec 14, 2007
    Posts:
    979
    Referrals:
    0
    Sythe Gold:
    0
    A file link container. STOP THE VIRUSES!

    Ok, after blocking a few keylog/accsteal-attempts I had the idea to make an "File link container".

    What is this?
    A file link container would be a sort of box (like qoute) opened and closed with [FILE]www.google.com/virus.exe[/FILE]

    This "box" has the color orange and status "Unchecked" by default.
    Then, the box can either go green "Verified" (no virus) or red "Malicious" (virus)



    Ofcourse, people can just post links without the [FILE] tags, people positing links to files should always use the [FILE] tags or a mod locks it.
    Simple as that.

    How and who will verify?

    What will happen:
    1. Multi-scan (VirusTotal/jotti/virscan/novirusthanks)
    -> if virus detected, RED
    2. Analyzing (Checking internet behavior, what files it uses, what registry codes it reads, if it creates anything (like an exe))
    -> if malicious behavior is found, RED
    3. If its a VB.NET application (most viruses are as vb.net as its easy to learn, and kids love being bad ass) we reflect it using reflecter or deobfuscate if obfuscated.
    4. If its not VB.NET we try to decompile & deobfuscate.
    If not working -> Disassembly (I have minor experience with this, but I'm learning).


    Everyone who knows what they are talking about can help, I volunteer to verify and make reports. (eg. http://sythe.org/showthread.php?p=7675079#post7675079)

    Thanks for reading!


    thr0wback

    PS: "file link container" sounds cheap, anyone has a better idea?
     
  2. Corey

    Corey Grand Master
    Crabby Retired Global Moderator

    Joined:
    Oct 5, 2009
    Posts:
    4,518
    Referrals:
    3
    Sythe Gold:
    3
    UWotM8? <3 n4n0 Oktoberfest 2013 Village Drunk Shitting Rainbow Potamus Sythe Awards 2012 Winner Wait, do you not have an Archer rank? MushyMuncher
    A file link container. STOP THE VIRUSES!

    No support, its kind of obvious when the file is infected (auth generators, paypal money dupes, etc), so it would be easier to just delete the links.
     
  3. thr0wback

    thr0wback Apprentice
    Banned

    Joined:
    Dec 14, 2007
    Posts:
    979
    Referrals:
    0
    Sythe Gold:
    0
    A file link container. STOP THE VIRUSES!

    There not just auth. Generators anymore.

    Last time it was a guy posting his modified version of rsbot. It actually worked but sended ur pw to a site. I deleted more then 10 logs
     
  4. jizzownya

    jizzownya Forum Addict
    Banned

    Joined:
    Dec 5, 2008
    Posts:
    426
    Referrals:
    2
    Sythe Gold:
    0
    A file link container. STOP THE VIRUSES!

    I agree with this.

    If you can't differentiate between a harmful link, and a safe one, you shouldn't be clicking on any in the first place.

    I for one, inspect every link that comes from someone who I don't trust.
     
  5. Angelmax

    Angelmax Grand Master
    $25 USD Donor Retired Sectional Moderator

    Joined:
    Jul 10, 2009
    Posts:
    2,193
    Referrals:
    0
    Sythe Gold:
    0
    A file link container. STOP THE VIRUSES!

    There's a verified program section in Runescape Cheating for just this.
     
  6. thr0wback

    thr0wback Apprentice
    Banned

    Joined:
    Dec 14, 2007
    Posts:
    979
    Referrals:
    0
    Sythe Gold:
    0
    A file link container. STOP THE VIRUSES!

    Yes, and it Says its not updated.
    Meh, idc if people get keylogged. It happend to me a while back and I don't want other kids to lose there acc
     
  7. Wolfdog

    Wolfdog Untired, we stand. Exhausted, we fall.
    Retired Sectional Moderator

    Joined:
    May 11, 2009
    Posts:
    2,611
    Referrals:
    2
    Sythe Gold:
    87
    Discord Unique ID:
    431330502142722048
    Discord Username:
    wolfdog
    Nitro Booster Hoover Extreme Homosex Homosex Potamus
    A file link container. STOP THE VIRUSES!

    Support, mainly because iv made it a goal of mine to find all the infected RS private servers out there, and you'd be amazed at how many there are, including a LARGE amount that still function perfectly + have a decent base.
     
  8. GovindAlt

    GovindAlt Member
    Do Not Trade

    Joined:
    Jan 5, 2011
    Posts:
    31
    Referrals:
    0
    Sythe Gold:
    0
    A file link container. STOP THE VIRUSES!

    A server side virus scanner? Not going to happen, sorry. Sandbox emulation would be more than the server could take with the attacks, and non-sandboxed sample testing is dangerous (and also would be unbearably slow).

    Close this, one of my minions.
     
  9. Carcinomati

    Carcinomati Apprentice
    Banned

    Joined:
    Jan 4, 2011
    Posts:
    772
    Referrals:
    0
    Sythe Gold:
    0
    A file link container. STOP THE VIRUSES!

    Really isn't necessary, if you suspect a malicious file you can just scan it with an online scanner using the file's URL.
     
  10. Magic Arrow

    Magic Arrow Protector of the homosex, defender of the AIDS
    $5 USD Donor Mudkips Retired Sectional Moderator

    Joined:
    Feb 3, 2007
    Posts:
    4,129
    Referrals:
    673
    Sythe Gold:
    49
    Extreme Homosex Sythe Awards 2013 Winner
    A file link container. STOP THE VIRUSES!

    This.
     
< Alternative Methods of Proof. | RSBOT / iBot coding section >
Thread Status:
Not open for further replies.


 
 
Adblock breaks this site