Forums: Securityscan.us - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Securityscan.us anyone heard of this ?

#1 User is offline   Ali 

  • Private
  • Icon
  • Group: Members
  • Posts: 9
  • Joined: 14-June 05

Post icon  Posted 11 July 2005 - 05:17 PM

I recieved a mail today from Hyperntecs Corporation about an online securitycheck for browsers.
I went to their site http://www.securityscan.us and performed the check.
After the scan I get this message :

Two critical security holes have been discovered in your browser!


Dear user, two extremely critical security vulnerabilities have been discovered in your Internet browser, therefore we recommend that you run this new patch immediately so we can preform the scan.

With a link to a patch.

I've tried with Firefox and with IE 6.0 ( both give the same message.

can this be trusted ?
0

#2 User is offline   Matt 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 26
  • Joined: 22-June 05

Posted 11 July 2005 - 05:33 PM

I highly doubt it.

here is why :

1. wether you do a "virus detection" or "security scan", you get to download the exact same file.

2. Why the file is making a call to kernel32.dll LoadLibraryA GetProcAddress ??

I wouldnt trust this site !

One thing though, McAfee didn't say anything...

Maybe somebody can enlighten us on the nature of this file ?! I wonder what it does exactly.
0

#3 User is offline   Ali 

  • Private
  • Icon
  • Group: Members
  • Posts: 9
  • Joined: 14-June 05

Posted 11 July 2005 - 06:01 PM

I did a scan with kapersky: a Trojan.backdoor.Win32.Rbot.gen

So everybody be warned.
0

#4 Guest_Necrocide_*

  • Group: Guests

Posted 11 July 2005 - 06:53 PM

Yeah, don't trust the site. A quick view at the source code of the "process bar" shows;

Quote

<meta http-equiv="refresh" content="10;URL=results.php??langid=ie&venid=sym&plfid=23&pkj=LVXYRHYTINMHDKDCWLL&scanstate=2">
Which means at it only load 10 secs, and then transfer to the site, so if you type

Quote

w3w.securityscan.us/results.php??langid=ie&venid=sym&plfid=23&pkj=LVXYRHYTINMHDKDCWLL&scanstate=2


You will get the message. More funny all the "langid=ie" and other fancy things in the uri is only for to make it seem "proffesional" - its not. You get the same message when you goto;

Quote

w3w.securityscan.us/results.php
And for the so-called "Security Scan" the fake result file is here;

Quote

w3w.securityscan.us/results.php?scanstate=1


It's okay made to fool normal users, sad.
0

#5 User is offline   iceman517 

  • Private
  • Icon
  • Group: Members
  • Posts: 16
  • Joined: 04-January 04

Posted 12 July 2005 - 08:29 AM

is it a trojan wen download the patch and start
istallt a file C:\WINDOWS\system32\ovhaztyne.exe

what will send to internernet
0

#6 User is offline   lovepump 

  • Private
  • Icon
  • Group: Members
  • Posts: 19
  • Joined: 15-February 04

Posted 12 July 2005 - 11:48 AM

Looks like its already down. Good.

Funny, it didn't take long to get caught either:

Quote

Domain Registration Date:                    Tue Jul 12 18:24:45 GMT 2005


Bob
0

#7 User is offline   myth 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 408
  • Joined: 09-January 04

Posted 12 July 2005 - 12:02 PM

lol

seems safe to download for now :P

Quote

Necrocide —› dns: resolved (irc.xposed.org) to (127.0.0.1)

lovepump Name:  irc.xposed.org
lovepump Address: 127.0.0.1

myth PING irc.xposed.org (127.0.0.1) 56(84) bytes of data.

_SerhaT_ Pingen naar irc.xposed.org [127.0.0.1]met 32 byte gegevens:

[tibbar] Pinging irc.xposed.org [127.0.0.1] with 32 bytes of data:


Will post back if he changes the server to a working one.
0

#8 User is offline   aelphaeis_mangarae 

  • Members
  • Icon
  • Group: Members
  • Posts: 936
  • Joined: 22-January 04

Posted 19 July 2005 - 01:51 PM

Quote

lovepump Name:  irc.xposed.org


lovepump???

Is that meant to be an alias or something? I know of someone with that alias....


EDIT: myth = lovepump?
:: Black Hat Forums ::
http://blackhat-forums.com
0

#9 User is offline   myth 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 408
  • Joined: 09-January 04

Posted 19 July 2005 - 02:32 PM

myth != lovepump

but i think he wants to be me :P j/k

run off to irc, we're both in there if you want to speak with him...
0

#10 User is offline   lovepump 

  • Private
  • Icon
  • Group: Members
  • Posts: 19
  • Joined: 15-February 04

Posted 19 July 2005 - 04:32 PM

I'm the only person I know that uses the nick lovepump.

Bob
0

#11 User is offline   sarab200x 

  • Private
  • Icon
  • Group: Members
  • Posts: 3
  • Joined: 07-August 05

Posted 07 August 2005 - 05:56 AM

this site and the other site have back doors as a gift for u... :D ...if u want security use norton & zone alarms & black ice....this is the only way you keep secure your information in net...
0

#12 User is offline   satknis 

  • Corporal
  • Icon
  • Group: Members
  • Posts: 162
  • Joined: 18-March 04

Posted 07 August 2005 - 02:19 PM

where do you find that thread? :P

norton, zone alarm & black ice are no good protections!
use others, search here in the forum for a better solution. :)
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting