View Full Version : Only Tease Down?
Looks like all their sites are down?
Scotty.T
07-29-07, 12:01 AM
Yes, down for me too.
Not wanting to be alarmist... BUT...
I clicked on a link to their sites last night, (re the Big Brother Girl) and it attempted to install some quicktime exploit on my PC
Norton Blocked it...
However, perhaps... (Keyword here is Perhaps...) Perhaps theve been hacked ?
onlytease
07-29-07, 03:21 PM
all is ok, we had a problem with a load balancer but all now resolved.
ta
paul
all is ok, we had a problem with a load balancer but all now resolved.
ta
paul
You did have the Quicktime exploit thing going on though...
Im 100% certain of that. If your certain you are 'clean' then cool,
but if you would like me to retrace my steps, find the gallery and tell you the response that I get from norton, I will do so if its helpfull...
Just let me know mate :)
You did have the Quicktime exploit thing going on though...
Im 100% certain of that. If your certain you are 'clean' then cool,
but if you would like me to retrace my steps, find the gallery and tell you the response that I get from norton, I will do so if its helpfull...
Just let me know mate :)
Well I found the info pretty quickly so I thought Id post it anyway...
The suspect link WAS http://galleries.onlytease.com/216s/index.php?id=835430
But its not doing it now...
The exploit was logged by norton as
Details: Attempted Intrusion "HTTP Quicktime RTSP URI BO" against your machine was detected and blocked.
Intruder: 66.96.218.85(http(80)).
Risk Level: High.
Protocol: TCP.
Attacked IP: VAIO-PC.
Scotty.T
07-29-07, 04:37 PM
Well I found the info pretty quickly so I thought Id post it anyway...
The suspect link WAS http://galleries.onlytease.com/216s/index.php?id=835430
But its not doing it now...
The exploit was logged by norton as
Details: Attempted Intrusion "HTTP Quicktime RTSP URI BO" against your machine was detected and blocked.
Intruder: 66.96.218.85(http(80)).
Risk Level: High.
Protocol: TCP.
Attacked IP: VAIO-PC.
Where was that link clicked from? One of the threads on here or was it on another site?
Just curious, it's my link and wondered if it was picking up something on the site I have it on.
I was using it yesterday on and off, Norton and AVG never picked up anything for me.
Where was that link clicked from? One of the threads on here or was it on another site?
Just curious, it's my link and wondered if it was picking up something on the site I have it on.
I was using it yesterday on and off, Norton and AVG never picked up anything for me.
Ahhh... The mystery unravels :)
Yes mate, it WAS a link that you posted here in another thread:
http://www.beerandbollocks.com/forum/showpost.php?p=148883&postcount=2
I clicked on it shortly after you posted it... Within an hours or so anyway...
It was a rather insistent little exploit, because it appeared at the top, telling me to click here to install an active x, but then it also offered me the convenience of just pressing enter or the space bar, if I didn't feel like clicking...
Naturally I closed the window straight away. Norton almost wet its pants with excitement...
Naturally, I tried it again a couple of times, and it didn't do it... But I persisted long enough to have it happen again :)
Then I let it be... I just wanted to see if I was imagining it or not :)
onlytease
07-29-07, 10:44 PM
cheers for the info guys, i am away on hols checking this at the hotel, but have asked our network manager gaurav to look into this. if its ok tgitc he may contact you for more info if he thinks he needs it.
ta
paul
cheers for the info guys, i am away on hols checking this at the hotel, but have asked our network manager gaurav to look into this. if its ok tgitc he may contact you for more info if he thinks he needs it.
ta
paul
Hes welcome to contact me by all means, tgitc (@) thatguyinthecorner.com however pretty much all the info I have, is allready posted above :)
Have a good holiday :)
Paul,
I'm also getting that Trojan Downloader on the OnlyOpaques tour
Time Module Object Name Threat Action User Information
30/07/2007 19:09:59 IMON filehttp://66.96.218.85/download/167212/movie.qtl Exploit.Multi.Qtp.B trojan Connection terminated
vBulletin® v3.7.2, Copyright ©2000-2012, Jelsoft Enterprises Ltd.