Previous Thread
Next Thread
Print Thread
Hop To
#40925 06/15/2004 12:00 PM
Joined: Jun 2006
Posts: 73
C
journeyman
journeyman
C Offline
Joined: Jun 2006
Posts: 73
I have an unregistered user on one of my boards that's getting a Norton Anti-Virus warning when clicking into one of the forums. He said it's been happening for about 3 days, and his virus definitions are up to date. Norton claims the virus is VBS.Inor, and it tries to repair 6 files.

I don't allow attachments on my board, and I'm serving from Unix. Anyone have any ideas on how to troubleshoot this? <img src="https://www.ubbcentral.com/boards/images/graemlins/confused.gif" alt="" />

My Board

Joined: Dec 2003
Posts: 613
Likes: 6
Former Developer
Former Developer
Joined: Dec 2003
Posts: 613
Likes: 6
OKay, I'm using Norton 2004 on this machine... and while I do not get the alert while browsing your board, I *DID* get the alert later:

I viewed source and found an odd object tag at the top, pointing to http://www.archeryoutdoors.com/forums/images/icons/img.php

(If you are using IE and have no virus protection, I highly suggest not clicking on that link.)

When I tried to save the file to examine it, Norton popped up and prevented me from doing so.

I used an alternate client to fetch the script, and it does indeed look like a malicious VBScript.

How did the object tag get there?


Charles Capps
Former UBB.classic Maintainer
Joined: Dec 2003
Posts: 613
Likes: 6
Former Developer
Former Developer
Joined: Dec 2003
Posts: 613
Likes: 6
It looks like the object tag is inside the Header Insert, so removing it from there will fix things up.

Now, as to how it got in there.. I would highly suggest interrogating all of your admins. They make "smart" virus code nowadays, but I simply don't see how it could simply insert itself in a random text field on a random webpage of its own accord. It would HAVE to have been intentionally put there.

Also, check and change your FTP login information... the virus infected script is on your server, so it would have to have been uploaded somehow. There's a high chance that at one point, your server was broken into from some method. There's also a high chance that at least one of your accounts on the board has been broken into.

Last edited by Charles Capps; 06/15/2004 1:57 PM.

Charles Capps
Former UBB.classic Maintainer
Joined: Jun 2006
Posts: 73
C
journeyman
journeyman
C Offline
Joined: Jun 2006
Posts: 73
I WILL be doing a little interrogating! I used the Unix editor pico to view the contents of the linked file, and here's what I saw:
Code
&lt;?
header("content-type: application/hta");
$szFile="data.hta";
$hFile=fopen($szFile, "r");
$szHTML=fread($hFile,filesize($szFile));
fclose($hFile);
echo($szHTML);
?&gt;
I have no idea what this does or why it's there. Do moderators have access to the header-insert admin?

Joined: Dec 2003
Posts: 613
Likes: 6
Former Developer
Former Developer
Joined: Dec 2003
Posts: 613
Likes: 6
No, nor can they upload files (not that UBB.threads should let admins upload images that aren't images) without FTP access.

The virus in question would be in the data.hta file that should also be located in that directory... the PHP script just serves it up with the right content type as to ensure IE's infected...


Charles Capps
Former UBB.classic Maintainer

Link Copied to Clipboard
ShoutChat
Comment Guidelines: Do post respectful and insightful comments. Don't flame, hate, spam.
Recent Topics
PHP 8 bug in membermanage.tmpl
by phoenix011235 - 09/08/2026 7:47 PM
Are any of these legitmate?
by Baldeagle - 09/06/2026 1:37 PM
8.0.1 Patch Changelog Discussion
by isaac - 11/26/2025 1:34 PM
Upgraded to ver8 - now can't login
by phoenix011235 - 10/24/2024 8:50 AM
Who's Online Now
0 members (), 563 guests, and 80 robots.
Key: Admin, Global Mod, Mod
Random Gallery Image
Latest Gallery Images
Ride safe!
Ride safe!
by Morgan, December 7
Los Angeles
Los Angeles
by isaac, August 6
3D Creations
3D Creations
by JAISP, December 30
Artistic structures
Artistic structures
by isaac, August 29
Powered by UBB.threads™ PHP Forum Software 8.1.0
(Snapshot build 20260527)