It is currently Sat May 04, 2024 10:38 am

All times are UTC - 8 hours [ DST ]




Post new topic Reply to topic  [ 12 posts ] 
Author Message
Offline
 Post subject: Yutopian Hosting Malware
Post #1 Posted: Sun Dec 05, 2010 9:57 pm 
Dies with sente

Posts: 100
Liked others: 0
Was liked: 4
Rank: AGA 6 kyu
GD Posts: 316
KGS: andd
Hey recently my browser has directed me away from any site linked to yutopian enterprises because of malware being hosted on their site. Has anyone else seen this problem? I heard in the past that it was a small family company, so how would one go about letting them know their site might be compromised.

Top
 Profile  
 
Offline
 Post subject: Re: Yutopian Hosting Malware
Post #2 Posted: Mon Dec 06, 2010 6:01 am 
Lives in sente

Posts: 1037
Liked others: 0
Was liked: 181
Your browser won't let you get to the site even enough to see their contact address? (there are ways to do this safely or should be. Depends on what your browser can do in terms of its settings and whether you know how to set up a "user" on your computerr with minimal rights)

BTW -- how about telling us what browser and what settings? I'm not experiencing any serious problems with the site.

info@yutopian.com is the contact email address

Top
 Profile  
 
Offline
 Post subject: Re: Yutopian Hosting Malware
Post #3 Posted: Mon Dec 06, 2010 6:19 am 
Dies with sente

Posts: 100
Liked others: 0
Was liked: 4
Rank: AGA 6 kyu
GD Posts: 316
KGS: andd
http://www.google.com/safebrowsing/diagnostic?site=http://www.yutopian.com/go/&hl=en

Here is the google diagnostics of the page.
I use google chrome and, while I'm not security illiterate I generally stay away from site that my computer outright tells me to avoid for lack of a better understanding of the risks.

Top
 Profile  
 
Offline
 Post subject: Re: Yutopian Hosting Malware
Post #4 Posted: Mon Dec 06, 2010 10:01 am 
Judan

Posts: 6183
Liked others: 0
Was liked: 793
Ignoring the warning in firefox, I could have a look in the source code of the webpage. It starts

#!/usr/bin/perl

and goes on with code. Not what one would expect from a serious, ordinary webpage. So it could indeed be the case that malware has attacked poor Yutopian. But I have not attempted to understand the source code. Maybe it was intentional? Anyway I suggest going back to good old plain HTML without any scripts.

Top
 Profile  
 
Offline
 Post subject: Re: Yutopian Hosting Malware
Post #5 Posted: Mon Dec 06, 2010 10:32 am 
Lives in sente
User avatar

Posts: 1072
Location: Stratford-upon-Avon, England
Liked others: 33
Was liked: 72
Rank: 5K KGS
GD Posts: 1165
KGS: Dogen
RobertJasiek wrote:
Ignoring the warning in firefox, I could have a look in the source code of the webpage. It starts

#!/usr/bin/perl

and goes on with code. Not what one would expect from a serious, ordinary webpage. So it could indeed be the case that malware has attacked poor Yutopian. But I have not attempted to understand the source code. Maybe it was intentional? Anyway I suggest going back to good old plain HTML without any scripts.


CGI scripts are usually in Perl...

_________________
My blog about Macs and more: Kirkville

Top
 Profile  
 
Offline
 Post subject: Re: Yutopian allegedly hosting malware?
Post #6 Posted: Mon Dec 06, 2010 5:46 pm 
Lives with ko
User avatar

Posts: 130
Location: UK, Nr. London
Liked others: 163
Was liked: 67
Rank: 3k EGF 3k KGS
http://www.virustotal.com/url-scan/repo ... 1291678715

3 out of 6 webscan sites see it as giving the impression of having malware.

Firefox, G-Data, Google suggest its a malware site,
Opera, ParetoLogic, Phishtank suggest its a clean site.

I guess there is a least something about the way the site is coded that looks suspicious to the automated testing tools.

Top
 Profile  
 
Offline
 Post subject: Re: Yutopian Hosting Malware
Post #7 Posted: Tue Dec 07, 2010 12:03 am 
Lives with ko

Posts: 281
Location: France
Liked others: 69
Was liked: 25
Rank: yes
No need to go so far, take a look at the html source : an 1x1px iframe was added on the bottom of the page, that loads the probable malware from another page.

In other words, yutopian was hacked discretely.

Top
 Profile  
 
Offline
 Post subject: Re: Yutopian Hosting Malware
Post #8 Posted: Thu Dec 09, 2010 7:44 pm 
Gosei
User avatar

Posts: 1639
Location: Ponte Vedra
Liked others: 642
Was liked: 490
Universal go server handle: Bantari
RobertJasiek wrote:
Ignoring the warning in firefox, I could have a look in the source code of the webpage. It starts

#!/usr/bin/perl

and goes on with code. Not what one would expect from a serious, ordinary webpage. So it could indeed be the case that malware has attacked poor Yutopian. But I have not attempted to understand the source code. Maybe it was intentional? Anyway I suggest going back to good old plain HTML without any scripts.


Actually, going back slightly further, to paper mail and paper magazines, would be safer still.
Come to think of it, I never heard of cave drawings hosting malware neither.

Brb. Out to get a bucket of animal pigments. ;)

_________________
- Bantari
______________________________________________
WARNING: This post might contain Opinions!!

Top
 Profile  
 
Offline
 Post subject: Re: Yutopian Hosting Malware
Post #9 Posted: Thu Dec 09, 2010 9:50 pm 
Dies with sente

Posts: 105
Location: Ventura
Liked others: 42
Was liked: 49
Rank: KGS 4 kyu
Bantari wrote:
[Actually, going back slightly further, to paper mail and paper magazines, would be safer still.
Come to think of it, I never heard of cave drawings hosting malware neither.

Brb. Out to get a bucket of animal pigments. ;)


No need to go so far: http://www.fountainpennetwork.com/forum/

Top
 Profile  
 
Offline
 Post subject: Re: Yutopian Hosting Malware
Post #10 Posted: Fri Dec 10, 2010 2:47 am 
Lives in gote

Posts: 350
Location: London UK
Liked others: 19
Was liked: 19
Rank: EGF 12kyu
DGS: willemien
Norton safeweb gives the following info


Quote:
Embedded Link To Malicious Site (what's this?)

Threats found: 1
Here is a complete list: (for more information about a specific threat, click on the Threat Name below)
Threat Name: Embedded link to malicious site guwtron.com
Location: http://www.yutopian.com/

_________________
Promotor and Librarian of Sensei's Library

Top
 Profile  
 
Offline
 Post subject: Re: Yutopian Hosting Malware
Post #11 Posted: Fri Dec 10, 2010 4:32 am 
Oza

Posts: 2180
Location: ʍoquıɐɹ ǝɥʇ ɹǝʌo 'ǝɹǝɥʍǝɯos
Liked others: 237
Was liked: 662
Rank: AGA 5d
GD Posts: 4312
Online playing schedule: Every tenth February 29th from 20:00-20:01 (if time permits)
I have not bought from them for a long time and probably will not do so again, but in the past I have found them very easy to deal with. Perhaps someone should call them in person and direct them to this thread.

_________________
Still officially AGA 5d but I play so irregularly these days that I am probably only 3d or 4d over the board (but hopefully still 5d in terms of knowledge, theory and the ability to contribute).

Top
 Profile  
 
Offline
 Post subject: Re: Yutopian believe problem is fixed
Post #12 Posted: Fri Dec 10, 2010 11:20 am 
Lives with ko
User avatar

Posts: 130
Location: UK, Nr. London
Liked others: 163
Was liked: 67
Rank: 3k EGF 3k KGS
I have had a reply from katherine & sidney at yutopian saying they believe this problem has been resolved.

http://www.virustotal.com/url-scan/repo ... 1292001821

I see that all 6 testing sites give it a clean bill of health now, so its looking good.

Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 12 posts ] 

All times are UTC - 8 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group