PHP Web Host - Quality Web Hosting For All PHP Applications Sign up for PayPal and start accepting credit card payments instantly
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
leopoldm
New Member
New Member


Joined: Jan 22, 2004
Posts: 11

PostPosted: Fri May 28, 2004 6:56 am Reply with quote Back to top

Hello,

When extracting Sentinel, BitDefender Virus Scan shows following message : C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/abuse/abuse.js is infected with JS.Trojan.Spawn.A

What happens ?
Thanks for comments, advice, ...

Greetz,

Leopold
View user's profile Send private message Visit poster's website
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16987
Location: Kansas

PostPosted: Fri May 28, 2004 7:00 am Reply with quote Back to top

There's no virus. Don't know what's setting off the alert.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
leopoldm
New Member
New Member


Joined: Jan 22, 2004
Posts: 11

PostPosted: Fri May 28, 2004 7:21 am Reply with quote Back to top

This is the full report :
Quote:
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>LICENSE.txt OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>README.txt OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/abuse/.htaccess OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/abuse/abuse.js Infected JS.Trojan.Spawn.A
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/abuse/abuse.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/abuse/abuse.swf OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/abuse/GanjaUKevil.swf OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/admin/case/case.sentinel.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/admin/links/links.sentinel.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/admin/modules/sentinel.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/admin/modules/sentinel.php=>(JAVASCRIPT 1) OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/admin/modules/sentinel.php=>(JAVASCRIPT 2) OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/admin/modules/sentinel.php=>(JAVASCRIPT 3) OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/blocks/block-Sentinel.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/images/admin/sentinel.png OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/images/sentinel/Sentinel_Large.png OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/images/sentinel/Sentinel_Medium.png OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/images/sentinel/Sentinel_Small.png OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/includes/sentinel.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/language/sentinel/lang-english.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/nsnst.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\LICENSE.txt OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\README.txt OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\abuse\.htaccess OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\abuse\abuse.js Infected JS.Trojan.Spawn.A
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\abuse\abuse.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\abuse\abuse.swf OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\abuse\GanjaUKevil.swf OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\abuse\index.html OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\admin\case\case.sentinel.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\admin\links\links.sentinel.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\admin\modules\sentinel.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\admin\modules\sentinel.php=>(JAVASCRIPT 1) OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\admin\modules\sentinel.php=>(JAVASCRIPT 2) OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\admin\modules\sentinel.php=>(JAVASCRIPT 3) OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\blocks\block-Sentinel.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\images\admin\sentinel.png OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\images\sentinel\index.html OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\images\sentinel\Sentinel_Large.png OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\images\sentinel\Sentinel_Medium.png OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\images\sentinel\Sentinel_Small.png OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\includes\sentinel.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\language\sentinel\lang-english.php OK
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\nsnst.php OK

Summary:

C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\NSN_Sentinel_100.tar=>html/abuse/abuse.js Infected JS.Trojan.Spawn.A
C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar\html\abuse\abuse.js Infected JS.Trojan.Spawn.A

Statistics

Scan path : C:\Documents and Settings\Leopold\Desktop\CPG_Nuke\NSN_Sentinel_100.tar
Folders : 14
Files : 49
Archives : 1
Packed files : 2
Identified viruses : 1
Infected files : 2
Warnings : 0
Suspect files : 0
Disinfected files : 0
Deleted files : 0
Copied files : 0
Moved files : 0
Renamed files : 0
I/O errors : 0
Scan time : 00:00:01
Scan speed (files/sec) : 49

Virus definitions : 78001
Scan plugins : 12
Archive plugins : 34
Unpack plugins : 3
Mail plugins : 6
System plugins : 1

Scan options

Detection
[X] Scan boot sectors
[X] Scan archives
[X] Scan packed files
[X] Scan email

File mask
[ ] Programs
[X] All files
[ ] User defined extensions:
[ ] Exclude extensions: ;

Action

Infected objects
[ ] Ignore
[ ] Disinfect
[ ] Delete
[ ] Copy to quarantine
[ ] Move to quarantine
[ ] Rename
[X] Prompt user

Second action
[X] Ignore
[ ] Delete
[ ] Copy to quarantine
[ ] Move to quarantine
[ ] Rename
[ ] Prompt user

Scan options
[X] Enable warnings
[X] Enable heuristics
[X] Show all files in log
[X] Report file: vscan.log
[ ] Append to existing report
View user's profile Send private message Visit poster's website
GanjaUK
Life Cycles Becoming CPU Cycles


Joined: Feb 14, 2004
Posts: 633
Location: England

PostPosted: Fri May 28, 2004 7:25 am Reply with quote Back to top

The reason for this:
Quote:

When a user visits the page, the script will prevent the user from closing the Window via traditional methods, by rapidly moving the Window across the screen, and trapping the ALT, F4, CTRL, and DEL keys. When either of these keys are pressed, a message box is displayed.

Some AV class this as a trojan for the above reason.

Only registered users can see links on this board!
Get registered or login to the forums!


So don't worry, no infections in here. I would class it as an annoyance for the attacker, not a trojan.
View user's profile Send private message Visit poster's website
leopoldm
New Member
New Member


Joined: Jan 22, 2004
Posts: 11

PostPosted: Fri May 28, 2004 7:30 am Reply with quote Back to top

Ok, thanks !

Btw, does someone knows if Sentinel can be used with CPG Nuke 8.2 ? Question
View user's profile Send private message Visit poster's website
BobMarion
Former Admin in Good Standing


Joined: Oct 30, 2002
Posts: 1043
Location: RedNeck Land (known as Kentucky)

PostPosted: Fri May 28, 2004 8:44 am Reply with quote Back to top

Wasn't tested with it but it's possible if the db scheme is the same.
View user's profile Send private message Send e-mail Visit poster's website
stephen2417
Worker
Worker


Joined: Jan 18, 2004
Posts: 244
Location: Bristolville, OH

PostPosted: Mon May 31, 2004 4:08 pm Reply with quote Back to top

leopoldm wrote:
Ok, thanks !

Btw, does someone knows if Sentinel can be used with CPG Nuke 8.2 ? Question
Only registered users can see links on this board!
Get registered or login to the forums!
View user's profile Send private message Visit poster's website
sgtbookie
Hangin' Around


Joined: May 08, 2004
Posts: 29
Location: Atlanta, GA

PostPosted: Wed Jun 23, 2004 7:57 pm Reply with quote Back to top

So what do we do if our Virus protection has already quarantined these files?
View user's profile Send private message Visit poster's website
GanjaUK
Life Cycles Becoming CPU Cycles


Joined: Feb 14, 2004
Posts: 633
Location: England

PostPosted: Wed Jun 23, 2004 7:59 pm Reply with quote Back to top

Download Sentinel 1.2.0 and your AV should not quarantine anything. The code was re done so not to set off false alarms on AV scanners.
View user's profile Send private message Visit poster's website
sgtbookie
Hangin' Around


Joined: May 08, 2004
Posts: 29
Location: Atlanta, GA

PostPosted: Wed Jun 23, 2004 8:05 pm Reply with quote Back to top

Cool, thanks. FOr a second there I though someone had found a hole in my armor. Thanks for the fast reply!
View user's profile Send private message Visit poster's website
sgtbookie
Hangin' Around


Joined: May 08, 2004
Posts: 29
Location: Atlanta, GA

PostPosted: Wed Jun 23, 2004 8:07 pm Reply with quote Back to top

Whoops, spoke too soon. It is still false positiving the abuse.php file.

Scan type: Realtime Protection Scan
Event: Virus Found!
Virus name: Trojan.Offiz
File: Z:\Inetpub\TwelveVoltMan\html\abuse\abuse.php
Location: Quarantine
Computer: SPONGEBOB
User: sgtbookie
Action taken: Clean failed : Quarantine succeeded : Access denied
Date found: Wed Jun 23 22:07:05 2004
View user's profile Send private message Visit poster's website
sgtbookie
Hangin' Around


Joined: May 08, 2004
Posts: 29
Location: Atlanta, GA

PostPosted: Wed Jun 23, 2004 8:10 pm Reply with quote Back to top

Ok, I added exclusion to SAV for the time being and replaced the files. What does the abuse.php do for Sentinel? Do I need to make any changes to the .htaccess file since it is set for allow all?
View user's profile Send private message Visit poster's website
GanjaUK
Life Cycles Becoming CPU Cycles


Joined: Feb 14, 2004
Posts: 633
Location: England

PostPosted: Wed Jun 23, 2004 10:09 pm Reply with quote Back to top

abuse.php is where the pop up style windows would be generated from if you choose to turn that feature on in Sentinel administration area.

Make sure you have a line break at the end of your .htaccess so Sentinel has a fresh line to write its 1st ip there without merging with the line above.
View user's profile Send private message Visit poster's website
djmaze
Subject Matter Expert


Joined: May 15, 2004
Posts: 689
Location: http://tinyurl.com/5z8dmv

PostPosted: Wed Jun 30, 2004 7:59 am Reply with quote Back to top

GanjaUK wrote:
Make sure you have a line break at the end of your .htaccess so Sentinel has a fresh line to write its 1st ip there without merging with the line above.

How is it ever possible a PHP can write to a file which doesn't belong to him Question

And to prove i'm wright here's a script that well print out your .htaccess
Code:
<?php
if (file_exists(".htaccess")) {
$file = fopen(".htaccess", "a+");
fwrite($file, 'just a line of text');
fclose($file);
echo '<html><body><pre>'.
implode("", file(".htaccess")).'
</pre></body></html>';
}
?>

Just upload the php to your root as check.php or something.
View user's profile Send private message Visit poster's website
BobMarion
Former Admin in Good Standing


Joined: Oct 30, 2002
Posts: 1043
Location: RedNeck Land (known as Kentucky)

PostPosted: Wed Jun 30, 2004 9:01 am Reply with quote Back to top

Quote:
How is it ever possible a PHP can write to a file which doesn't belong to him


Just make sure it's CHMODed to 666 and the script can read and write to the .htaccess file without problems.
View user's profile Send private message Send e-mail Visit poster's website
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16987
Location: Kansas

PostPosted: Wed Jun 30, 2004 10:38 am Reply with quote Back to top

It's the web server which has [or has not] authority, not PHP. Regardless, as Bob says, once you change mod the file, or any files for that matter, you allow/disallow access. And I don't understand how your script proves you're right. Right about what? What are you trying to prove?
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
squiresmk
Regular
Regular


Joined: May 31, 2004
Posts: 95
Location: NY

PostPosted: Wed Jun 30, 2004 10:30 pm Reply with quote Back to top

PHP is considered the 'owner' Wink
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16987
Location: Kansas

PostPosted: Thu Jul 01, 2004 4:42 am Reply with quote Back to top

Not if it's running as an Apache module.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum