Ravens PHP Scripts: Forums
 

 

View next topic
View previous topic
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> NukeSentinel(tm)
Author Message
leopoldm
New Member
New Member



Joined: Jan 22, 2004
Posts: 11

PostPosted: Fri May 28, 2004 6:56 am Reply with quote

Hello,

When extracting Sentinel, BitDefender Virus Scan shows following message : C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/abuse/abuse.js is infected with JS.Trojan.Spawn.A

What happens ?
Thanks for comments, advice, ...

Greetz,

Leopold
 
View user's profile Send private message Visit poster's website
Raven
Site Admin/Owner



Joined: Aug 27, 2002
Posts: 17088

PostPosted: Fri May 28, 2004 7:00 am Reply with quote

There's no virus. Don't know what's setting off the alert.
 
View user's profile Send private message
leopoldm







PostPosted: Fri May 28, 2004 7:21 am Reply with quote

This is the full report :
Quote:
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>LICENSE.txt OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>README.txt OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/abuse/.htaccess OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/abuse/abuse.js Infected JS.Trojan.Spawn.A
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/abuse/abuse.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/abuse/abuse.swf OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/abuse/GanjaUKevil.swf OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/admin/case/case.sentinel.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/admin/links/links.sentinel.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/admin/modules/sentinel.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/admin/modules/sentinel.php=>(JAVASCRIPT 1) OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/admin/modules/sentinel.php=>(JAVASCRIPT 2) OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/admin/modules/sentinel.php=>(JAVASCRIPT 3) OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/blocks/block-Sentinel.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/images/admin/sentinel.png OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/images/sentinel/Sentinel_Large.png OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/images/sentinel/Sentinel_Medium.png OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/images/sentinel/Sentinel_Small.png OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/includes/sentinel.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/language/sentinel/lang-english.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/nsnst.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\LICENSE.txt OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\README.txt OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\abuse\.htaccess OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\abuse\abuse.js Infected JS.Trojan.Spawn.A
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\abuse\abuse.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\abuse\abuse.swf OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\abuse\GanjaUKevil.swf OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\abuse\index.html OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\admin\case\case.sentinel.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\admin\links\links.sentinel.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\admin\modules\sentinel.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\admin\modules\sentinel.php=>(JAVASCRIPT 1) OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\admin\modules\sentinel.php=>(JAVASCRIPT 2) OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\admin\modules\sentinel.php=>(JAVASCRIPT 3) OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\blocks\block-Sentinel.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\images\admin\sentinel.png OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\images\sentinel\index.html OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\images\sentinel\Sentinel_Large.png OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\images\sentinel\Sentinel_Medium.png OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\images\sentinel\Sentinel_Small.png OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\includes\sentinel.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\language\sentinel\lang-english.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\nsnst.php OK

Summary:

C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/abuse/abuse.js Infected JS.Trojan.Spawn.A
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\abuse\abuse.js Infected JS.Trojan.Spawn.A

Statistics

Scan path : C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar
Folders : 14
Files : 49
Archives : 1
Packed files : 2
Identified viruses : 1
Infected files : 2
Warnings : 0
Suspect files : 0
Disinfected files : 0
Deleted files : 0
Copied files : 0
Moved files : 0
Renamed files : 0
I/O errors : 0
Scan time : 00:00:01
Scan speed (files/sec) : 49

Virus definitions : 78001
Scan plugins : 12
Archive plugins : 34
Unpack plugins : 3
Mail plugins : 6
System plugins : 1

Scan options

Detection
[X] Scan boot sectors
[X] Scan archives
[X] Scan packed files
[X] Scan email

File mask
[ ] Programs
[X] All files
[ ] User defined extensions:
[ ] Exclude extensions: ;

Action

Infected objects
[ ] Ignore
[ ] Disinfect
[ ] Delete
[ ] Copy to quarantine
[ ] Move to quarantine
[ ] Rename
[X] Prompt user

Second action
[X] Ignore
[ ] Delete
[ ] Copy to quarantine
[ ] Move to quarantine
[ ] Rename
[ ] Prompt user

Scan options
[X] Enable warnings
[X] Enable heuristics
[X] Show all files in log
[X] Report file: vscan.log
[ ] Append to existing report
 
GanjaUK
Life Cycles Becoming CPU Cycles



Joined: Feb 14, 2004
Posts: 633
Location: England

PostPosted: Fri May 28, 2004 7:25 am Reply with quote

The reason for this:
Quote:

When a user visits the page, the script will prevent the user from closing the Window via traditional methods, by rapidly moving the Window across the screen, and trapping the ALT, F4, CTRL, and DEL keys. When either of these keys are pressed, a message box is displayed.

Some AV class this as a trojan for the above reason.

McAfee source

So don't worry, no infections in here. I would class it as an annoyance for the attacker, not a trojan.

_________________
Image
Need a quality custom theme designed? PM me!
 
View user's profile Send private message Visit poster's website
leopoldm







PostPosted: Fri May 28, 2004 7:30 am Reply with quote

Ok, thanks !

Btw, does someone knows if Sentinel can be used with CPG Nuke 8.2 ? Question
 
BobMarion
Former Admin in Good Standing



Joined: Oct 30, 2002
Posts: 1037
Location: RedNeck Land (known as Kentucky)

PostPosted: Fri May 28, 2004 8:44 am Reply with quote

Wasn't tested with it but it's possible if the db scheme is the same.

_________________
Bob Marion
Codito Ergo Sum
http://www.nukescripts.net 
View user's profile Send private message Send e-mail Visit poster's website
stephen2417
Worker
Worker



Joined: Jan 18, 2004
Posts: 244
Location: Bristolville, OH

PostPosted: Mon May 31, 2004 4:08 pm Reply with quote

leopoldm wrote:
Ok, thanks !

Btw, does someone knows if Sentinel can be used with CPG Nuke 8.2 ? Question
[ Only registered users can see links on this board! Get registered or login! ]
 
View user's profile Send private message Visit poster's website
sgtbookie
Hangin' Around



Joined: May 08, 2004
Posts: 29
Location: Atlanta, GA

PostPosted: Wed Jun 23, 2004 7:57 pm Reply with quote

So what do we do if our Virus protection has already quarantined these files?

_________________
Sgt.Bookie
TwelvevoltmanDOTcom 
View user's profile Send private message Visit poster's website
GanjaUK







PostPosted: Wed Jun 23, 2004 7:59 pm Reply with quote

Download Sentinel 1.2.0 and your AV should not quarantine anything. The code was re done so not to set off false alarms on AV scanners.
 
sgtbookie







PostPosted: Wed Jun 23, 2004 8:05 pm Reply with quote

Cool, thanks. FOr a second there I though someone had found a hole in my armor. Thanks for the fast reply!
 
sgtbookie







PostPosted: Wed Jun 23, 2004 8:07 pm Reply with quote

Whoops, spoke too soon. It is still false positiving the abuse.php file.

Scan type: Realtime Protection Scan
Event: Virus Found!
Virus name: Trojan.Offiz
File: Z:\Inetpub\TwelveVoltMan\html\abuse\abuse.php
Location: Quarantine
Computer: SPONGEBOB
User: sgtbookie
Action taken: Clean failed : Quarantine succeeded : Access denied
Date found: Wed Jun 23 22:07:05 2004
 
sgtbookie







PostPosted: Wed Jun 23, 2004 8:10 pm Reply with quote

Ok, I added exclusion to SAV for the time being and replaced the files. What does the abuse.php do for Sentinel? Do I need to make any changes to the .htaccess file since it is set for allow all?
 
GanjaUK







PostPosted: Wed Jun 23, 2004 10:09 pm Reply with quote

abuse.php is where the pop up style windows would be generated from if you choose to turn that feature on in Sentinel administration area.

Make sure you have a line break at the end of your .htaccess so Sentinel has a fresh line to write its 1st ip there without merging with the line above.
 
djmaze
Subject Matter Expert



Joined: May 15, 2004
Posts: 727
Location: http://tinyurl.com/5z8dmv

PostPosted: Wed Jun 30, 2004 7:59 am Reply with quote

GanjaUK wrote:
Make sure you have a line break at the end of your .htaccess so Sentinel has a fresh line to write its 1st ip there without merging with the line above.

How is it ever possible a PHP can write to a file which doesn't belong to him Question

And to prove i'm wright here's a script that well print out your .htaccess
Code:
<?php

if (file_exists(".htaccess")) {
$file = fopen(".htaccess", "a+");
fwrite($file, 'just a line of text');
fclose($file);
echo '<html><body><pre>'.
implode("", file(".htaccess")).'
</pre></body></html>';
}
?>

Just upload the php to your root as check.php or something.
 
View user's profile Send private message Visit poster's website
BobMarion







PostPosted: Wed Jun 30, 2004 9:01 am Reply with quote

Quote:
How is it ever possible a PHP can write to a file which doesn't belong to him


Just make sure it's CHMODed to 666 and the script can read and write to the .htaccess file without problems.
 
Raven







PostPosted: Wed Jun 30, 2004 10:38 am Reply with quote

It's the web server which has [or has not] authority, not PHP. Regardless, as Bob says, once you change mod the file, or any files for that matter, you allow/disallow access. And I don't understand how your script proves you're right. Right about what? What are you trying to prove?
 
squiresmk
Regular
Regular



Joined: May 31, 2004
Posts: 95
Location: NY

PostPosted: Wed Jun 30, 2004 10:30 pm Reply with quote

PHP is considered the 'owner' Wink

_________________
Captain of the Internet Debate Team. 
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
Raven







PostPosted: Thu Jul 01, 2004 4:42 am Reply with quote

Not if it's running as an Apache module.
 
Display posts from previous:       
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> NukeSentinel(tm)

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001-2007 phpBB Group
All times are GMT - 6 Hours
 
Forums ©