Silk Road forums

Discussion => Off topic => Topic started by: InfiniteSource on May 19, 2013, 11:35 am

Title: a popular member on the forums may have just tried to Trojan me. Anyone confirm?
Post by: InfiniteSource on May 19, 2013, 11:35 am
Title says it all. Please let me know if I can PM you the exact link he sent to me, to you. I don't want to just post a download link. Too many idiots will end up downloading it.

I believe it may be a rat disguised as a jpg file. Everything about the .zip is very very strange.
Title: Re: a popular member on the forums may have just tried to Trojan me. Anyone confirm?
Post by: Jack N Hoff on May 19, 2013, 11:58 am
Shoot it to me!
Title: Re: a popular member on the forums may have just tried to Trojan me. Anyone confirm?
Post by: InfiniteSource on May 19, 2013, 01:10 pm
Sent! thanks jack n hoff
Title: Re: a popular member on the forums may have just tried to Trojan me. Anyone confirm?
Post by: SelfSovereignty on May 19, 2013, 01:14 pm
Well now I'm awfully curious; send me the link, would one of you?
Title: Re: a popular member on the forums may have just tried to Trojan me. Anyone confirm?
Post by: InfiniteSource on May 19, 2013, 01:30 pm
Well now I'm awfully curious; send me the link, would one of you?

Sent.
Title: Re: a popular member on the forums may have just tried to Trojan me. Anyone confirm?
Post by: northsouth on May 19, 2013, 01:52 pm
A RAT in a .jpg file? That sounds unlikely. For it to work, there has to be a vulnerability in whatever software you use to display the image. If you're really unlucky, it will target the thumbnail-creation feature in Windows, because it is executed as you unpack the image. Or maybe it's a vulnerability in the way Windows handles zip files, and you got infected the second you completed the download, and Windows tried to figure out what was inside the zip! But honestly, if such a brilliant zero-day exploit exists, it would be a shame to waste it on you  ::)
Title: Re: a popular member on the forums may have just tried to Trojan me. Anyone confirm?
Post by: InfiniteSource on May 19, 2013, 01:54 pm
A RAT in a .jpg file? That sounds unlikely. For it to work, there has to be a vulnerability in whatever software you use to display the image. If you're really unlucky, it will target the thumbnail-creation feature in Windows, because it is executed as you unpack the image. Or maybe it's a vulnerability in the way Windows handles zip files, and you got infected the second you completed the download, and Windows tried to figure out what was inside the zip! But honestly, if such a brilliant zero-day exploit exists, it would be a shame to waste it on you  ::)

You better refresh you history. jpg.>.rar

exe displays as image, user un-rars, clicks image, accidenly runs exe.

I'm on tails right now, so I fucked around with it. Its really a strange set of files.
Title: Re: a popular member on the forums may have just tried to Trojan me. Anyone confirm?
Post by: northsouth on May 19, 2013, 02:46 pm
You better refresh you history. jpg.>.rar

exe displays as image, user un-rars, clicks image, accidenly runs exe.


You said it was a zip file, not rar (not that it really matters)... But no, that's not how it works. If the file-extension is .jpg, it will be treated as a jpg-image, even if it's really an .exe file. And besides, binary exe files wont execute in tails. It's a linux distro.
Title: Re: a popular member on the forums may have just tried to Trojan me. Anyone confirm?
Post by: SelfSovereignty on May 19, 2013, 02:55 pm
So uh... unless Tails fucks with the kernel, Linux isn't gonna give a fuck what the file extension is.  It doesn't even look at it.  Whatever funky launcher Tails uses might, but if it does, it breaks with Linux tradition.

File's fine as far as I can tell man.  Pretty nice looking picture too.  I actually know exactly who sent you this now, since I recognize the work (but of course I can't say)  :P
Title: Re: a popular member on the forums may have just tried to Trojan me. Anyone confirm?
Post by: paxpax on May 19, 2013, 02:59 pm
Comp science major, send it over.
Title: Re: a popular member on the forums may have just tried to Trojan me. Anyone confirm?
Post by: SelfSovereignty on May 19, 2013, 03:06 pm
... well now isn't that odd.  Windows thinks there's four files in it.  Unzipped it shows 3.  With Vim, a programming editor, it shows... 4.  Except, one of them is a blank line.  I've never seen that.  Frankly I don't know wtf is up with that, but I don't see any virus or anything.  Just looks like a fucked up Zip header -- I don't really know to be honest.
Title: Re: a popular member on the forums may have just tried to Trojan me. Anyone confirm?
Post by: InfiniteSource on May 19, 2013, 03:26 pm
... well now isn't that odd.  Windows thinks there's four files in it.  Unzipped it shows 3.  With Vim, a programming editor, it shows... 4.  Except, one of them is a blank line.  I've never seen that.  Frankly I don't know wtf is up with that, but I don't see any virus or anything.  Just looks like a fucked up Zip header -- I don't really know to be honest.

Thanks bud. I'm going to lock the thread and send it to pax. Any updates I will just post. It ain't easy knowing jack shit about programming.