A file link container. STOP THE VIRUSES!

Discussion in 'Denied Suggestions' started by thr0wback, Jan 2, 2011.

Thread Status:
Not open for further replies.
A file link container. STOP THE VIRUSES!
  1. Unread #1 - Jan 2, 2011 at 12:56 PM
  2. thr0wback
    Joined:
    Dec 14, 2007
    Posts:
    979
    Referrals:
    0
    Sythe Gold:
    0

    thr0wback Apprentice
    Banned

    A file link container. STOP THE VIRUSES!

    Ok, after blocking a few keylog/accsteal-attempts I had the idea to make an "File link container".

    What is this?
    A file link container would be a sort of box (like qoute) opened and closed with [FILE]www.google.com/virus.exe[/FILE]

    This "box" has the color orange and status "Unchecked" by default.
    Then, the box can either go green "Verified" (no virus) or red "Malicious" (virus)



    Ofcourse, people can just post links without the [FILE] tags, people positing links to files should always use the [FILE] tags or a mod locks it.
    Simple as that.

    How and who will verify?

    What will happen:
    1. Multi-scan (VirusTotal/jotti/virscan/novirusthanks)
    -> if virus detected, RED
    2. Analyzing (Checking internet behavior, what files it uses, what registry codes it reads, if it creates anything (like an exe))
    -> if malicious behavior is found, RED
    3. If its a VB.NET application (most viruses are as vb.net as its easy to learn, and kids love being bad ass) we reflect it using reflecter or deobfuscate if obfuscated.
    4. If its not VB.NET we try to decompile & deobfuscate.
    If not working -> Disassembly (I have minor experience with this, but I'm learning).


    Everyone who knows what they are talking about can help, I volunteer to verify and make reports. (eg. http://sythe.org/showthread.php?p=7675079#post7675079)

    Thanks for reading!


    thr0wback

    PS: "file link container" sounds cheap, anyone has a better idea?
     
  3. Unread #2 - Jan 2, 2011 at 1:08 PM
  4. Corey
    Joined:
    Oct 5, 2009
    Posts:
    4,518
    Referrals:
    3
    Sythe Gold:
    3
    UWotM8? <3 n4n0 Oktoberfest 2013 Village Drunk Shitting Rainbow Potamus Sythe Awards 2012 Winner Wait, do you not have an Archer rank? MushyMuncher

    Corey Grand Master
    Crabby Retired Global Moderator

    A file link container. STOP THE VIRUSES!

    No support, its kind of obvious when the file is infected (auth generators, paypal money dupes, etc), so it would be easier to just delete the links.
     
  5. Unread #3 - Jan 2, 2011 at 1:17 PM
  6. thr0wback
    Joined:
    Dec 14, 2007
    Posts:
    979
    Referrals:
    0
    Sythe Gold:
    0

    thr0wback Apprentice
    Banned

    A file link container. STOP THE VIRUSES!

    There not just auth. Generators anymore.

    Last time it was a guy posting his modified version of rsbot. It actually worked but sended ur pw to a site. I deleted more then 10 logs
     
  7. Unread #4 - Jan 2, 2011 at 1:25 PM
  8. jizzownya
    Joined:
    Dec 5, 2008
    Posts:
    426
    Referrals:
    2
    Sythe Gold:
    0

    jizzownya Forum Addict
    Banned

    A file link container. STOP THE VIRUSES!

    I agree with this.

    If you can't differentiate between a harmful link, and a safe one, you shouldn't be clicking on any in the first place.

    I for one, inspect every link that comes from someone who I don't trust.
     
  9. Unread #5 - Jan 2, 2011 at 1:29 PM
  10. Angelmax
    Joined:
    Jul 10, 2009
    Posts:
    2,193
    Referrals:
    0
    Sythe Gold:
    0

    Angelmax Grand Master
    $25 USD Donor Retired Sectional Moderator

    A file link container. STOP THE VIRUSES!

    There's a verified program section in Runescape Cheating for just this.
     
  11. Unread #6 - Jan 2, 2011 at 1:34 PM
  12. thr0wback
    Joined:
    Dec 14, 2007
    Posts:
    979
    Referrals:
    0
    Sythe Gold:
    0

    thr0wback Apprentice
    Banned

    A file link container. STOP THE VIRUSES!

    Yes, and it Says its not updated.
    Meh, idc if people get keylogged. It happend to me a while back and I don't want other kids to lose there acc
     
  13. Unread #7 - Jan 3, 2011 at 8:37 AM
  14. Wolfdog
    Joined:
    May 11, 2009
    Posts:
    2,611
    Referrals:
    2
    Sythe Gold:
    87
    Discord Unique ID:
    431330502142722048
    Discord Username:
    wolfdog
    Nitro Booster Hoover Extreme Homosex Homosex Potamus

    Wolfdog Untired, we stand. Exhausted, we fall.
    Retired Sectional Moderator

    A file link container. STOP THE VIRUSES!

    Support, mainly because iv made it a goal of mine to find all the infected RS private servers out there, and you'd be amazed at how many there are, including a LARGE amount that still function perfectly + have a decent base.
     
  15. Unread #8 - Jan 5, 2011 at 11:45 AM
  16. GovindAlt
    Joined:
    Jan 5, 2011
    Posts:
    31
    Referrals:
    0
    Sythe Gold:
    0

    GovindAlt Member
    Do Not Trade

    A file link container. STOP THE VIRUSES!

    A server side virus scanner? Not going to happen, sorry. Sandbox emulation would be more than the server could take with the attacks, and non-sandboxed sample testing is dangerous (and also would be unbearably slow).

    Close this, one of my minions.
     
  17. Unread #9 - Jan 5, 2011 at 12:41 PM
  18. Carcinomati
    Joined:
    Jan 4, 2011
    Posts:
    772
    Referrals:
    0
    Sythe Gold:
    0

    Carcinomati Apprentice
    Banned

    A file link container. STOP THE VIRUSES!

    Really isn't necessary, if you suspect a malicious file you can just scan it with an online scanner using the file's URL.
     
  19. Unread #10 - Jan 6, 2011 at 9:56 PM
  20. Magic Arrow
    Joined:
    Feb 3, 2007
    Posts:
    4,129
    Referrals:
    673
    Sythe Gold:
    49
    Extreme Homosex Sythe Awards 2013 Winner

    Magic Arrow Protector of the homosex, defender of the AIDS
    $5 USD Donor Mudkips Retired Sectional Moderator

    A file link container. STOP THE VIRUSES!

    This.
     
< Alternative Methods of Proof. | RSBOT / iBot coding section >

Users viewing this thread
1 guest
Thread Status:
Not open for further replies.


 
 
Adblock breaks this site