World of Warcraft

1 . 2
Blizzard Entertainment
View All Posts by This User ignore-inactive
Slouken
Blizzard Poster
  • 0. Caution: Virus Warning!   12/02/2007 05:48:11 PM PST
quote reply
Please be aware that key loggers have been added to AddOn packages on several different AddOn sites.

In general we recommend not downloading any AddOn packages that have executables or batch files that run installers or data collectors, as they may have been tampered with.

Cairenn has posted an excellent description of the problem and how to resolve it if you've already installed an infected package:
http://forums.worldofwarcraft.com/thread.html?topicId=3168484081&sid=1

In addition, WoWI has taken the step of quarantining any package that has an executable installer. This was a bold move to ensure the safety of the community and is greatly appreciated.

[ Post edited by Slouken ]

70
View All Posts by This User Toggle Ignore / Unignore This User
  • 1. Re: Caution: Virus Warning!   12/02/2007 05:55:15 PM PST
quote reply
Blocking executables is a great step for protecting users, as long as it's enforced alongside the nightly virus scans as well as at the point of upload, to prevent infections such as this one, where a file server was compromised directly. (I have no reason to suspect that's not the plan)

Thanks WoWI ;)

Nymbia is a cheater.
12
View All Posts by This User Toggle Ignore / Unignore This User
  • Llane
  • 2. Re: Caution: Virus Warning!   12/02/2007 06:00:58 PM PST
quote reply
Sweet deal!

Thank you!

Revu - 70 priest, Llane.
Gleb - 70 hunter, Llane.
Izahamburger - ?? drood, Llane.
70
View All Posts by This User Toggle Ignore / Unignore This User
  • Thorium Brotherhood
  • 3. Re: Caution: Virus Warning!   12/02/2007 06:27:46 PM PST
quote reply
Executables can be fine, if you can get your hands on the complete source code of the mod and installer, and can locally re-create the install environment - eg, tools such as MinGW and NSIS. Several open source projects build Win32 installers using this method on non-Win32 machines. The advantages of doing this are.. well, fairly obvious if you understand the procedure. However, I thoroughly do not recommend this approach for, at a guess, 99.9999% of WoW players.

NEVER trust an installer package that you can't get the source code for and can't build for yourself.*

Hugz 'n stuff,

Me.

*Well, 'cept for WoW's installer, 'coz Slouken wouldn't be that nasty to us! :)

I have pen and ink cause I am good little girl.
70
View All Posts by This User Toggle Ignore / Unignore This User
  • 4. Re: Caution: Virus Warning!   12/02/2007 07:16:26 PM PST
quote reply
Uploading .exe files is also disabled for Curse at the moment. We haven't had a problem with the trojans going around, but want to take extra precautions to make sure that it doesn't happen.

[ Post edited by Guillotine ]


Guillotine-
Member of Curse Staff (www.Curse.com)
Member of Cosmos Team (www.cosmosui.org)
70
View All Posts by This User Toggle Ignore / Unignore This User
  • Kilrogg
  • 5. Re: Caution: Virus Warning!   12/02/2007 07:26:07 PM PST
quote reply
Indeed. As Guillotine said, we're going to be taking extra precautions at Curse as well due to this news. It's unfortunate to hear of this happening to yet another of the respected AddOn websites.

http://my.curse.com/kody
70
View All Posts by This User Toggle Ignore / Unignore This User
  • 6. Re: Caution: Virus Warning!   12/02/2007 07:31:41 PM PST
quote reply
Always use protection, kids.
14
View All Posts by This User Toggle Ignore / Unignore This User
  • 7. Re: Caution: Virus Warning!   12/02/2007 07:45:08 PM PST
quote reply
For the record, it wasn't our upload system that was compromised it was our secondary file server. Someone hacked in and edited the files directly. :(

Cairenn
Administratrix - WoWInterface
Credendo Vides
UI Dev, Hosting & Support
http://www.WoWInterface.com
2
View All Posts by This User Toggle Ignore / Unignore This User
  • 8. Re: Caution: Virus Warning!   12/02/2007 07:46:25 PM PST
quote reply

Q u o t e:
Always use protection, kids.


This is one situation where virus scanners WON'T pick it up.

I know of exactly ONE anti-virus program which is currently detecting it. Norton, Mcafee, AVG, and pretty much every other AV product ou there - aren't picking it up as I'm writing this.

EDIT: Scratch that, we're up to two. AntiVir and ClamAV.

[ Post edited by Sbo ]


EPIC MACRO: /run SetDungeonDifficulty(3);
80
View All Posts by This User Toggle Ignore / Unignore This User
  • Medivh
  • 9. Re: Caution: Virus Warning!   12/02/2007 07:49:57 PM PST
quote reply
Curse my blasted net connection and the freenode Tor block. Always looking for more toys to dissect, if only I wasn't a half-hour behind the conversation...

I take it all of the major AV providers have been handed a zip?

Live or die trying.

Q u o t e:
Mage - This fight is for the ones who say "SHAMAN NEED BUFFS" HAHAHA!! because mage is EZ SELECT MODE.
2
View All Posts by This User Toggle Ignore / Unignore This User
  • 10. Re: Caution: Virus Warning!   12/02/2007 07:50:42 PM PST
quote reply

Q u o t e:
Curse my blasted net connection and the freenode Tor block. Always looking for more toys to dissect, if only I wasn't a half-hour behind the conversation...

I take it all of the major AV providers have been handed a zip?


Get me e-mail addresses and links, and sure ;)

hacks@blizzard.com has been, though.

EPIC MACRO: /run SetDungeonDifficulty(3);
57
View All Posts by This User Toggle Ignore / Unignore This User
  • Boulderfist
  • 11. Re: Caution: Virus Warning!   12/03/2007 07:21:09 AM PST
quote reply
Just wanted to let everyone know also that wowui.incgamers no longer accepts executables as of last week. It is just too risky and really not that necessary to have them at all except in a few cases.

[ Post edited by Rushyman ]


http://www.WoWDigger.com
Gear Outfit Planner - Talent Builder - Profiler - WoW DB
70
View All Posts by This User Toggle Ignore / Unignore This User
  • 12. Re: Caution: Virus Warning!   12/03/2007 12:30:31 PM PST
quote reply
Bump, because this needs to be on the front page.
5
View All Posts by This User Toggle Ignore / Unignore This User
  • Ravenholdt
  • 13. Re: Caution: Virus Warning!   12/03/2007 01:40:30 PM PST
quote reply
Slouken, this is important for people to read. Now and in the future.

Sticky this thread.
55
View All Posts by This User Toggle Ignore / Unignore This User
  • Gilneas
  • 14. Re: Caution: Virus Warning!   12/03/2007 01:42:36 PM PST
quote reply
also please read my thread at WOWI it will help you and everyone else out of this problem and the problems to come.

http://www.wowinterface.com/forums/showthread.php?t=13296

*edit*
yes i know it is off site but the blizz boards don't like me, don't support vB code, and it is 6 posts long.



Q u o t e:


This is one situation where virus scanners WON'T pick it up.

I know of exactly ONE anti-virus program which is currently detecting it. Norton, Mcafee, AVG, and pretty much every other AV product ou there - aren't picking it up as I'm writing this.

EDIT: Scratch that, we're up to two. AntiVir and ClamAV.


Another one that detects it:
ESET Nod32 Online Scanner (Win 98/ME/NT 4.0/2000/XP/Vista) http://www.eset.com/onlinescan/index.php

[ Post edited by Lenno ]


Ace Updater no more surfing for Ace mods
http://wowace.com/wiki/WowAceUpdater
2
View All Posts by This User Toggle Ignore / Unignore This User
  • 16. Re: Caution: Virus Warning!   12/03/2007 03:55:47 PM PST
quote reply
The virus in question has three parts.

I can tell you that one of the parts is only being picked up by a total of five anti-virus products, while another is picked up by three, and the last part, two.

NOD32 is picking up none of them, according to virustotal.com.

EPIC MACRO: /run SetDungeonDifficulty(3);
5
View All Posts by This User Toggle Ignore / Unignore This User
  • Shattered Halls
  • 17. Re: Caution: Virus Warning!   12/03/2007 05:51:27 PM PST
quote reply
Ty for putting this warning out. Perhaps Blizzard could set up their own site to host popular add-ons? This may help ensure safety?
55
View All Posts by This User Toggle Ignore / Unignore This User
  • Gilneas
  • 18. Re: Caution: Virus Warning!   12/04/2007 03:52:53 PM PST
quote reply
OMG this is on page 4?!? this needs to be stickied

Ace Updater no more surfing for Ace mods
http://wowace.com/wiki/WowAceUpdater
70
View All Posts by This User Toggle Ignore / Unignore This User
  • 19. Re: Caution: Virus Warning!   12/05/2007 04:02:48 PM PST
quote reply
/bump
1 . 2
Forum Nav : Jump To This Forum
Blizzard Entertainment