Login
  • Home
  • Articles
  • Reviews
  • Videos
  • Blogs
  • Forums
  • Tools
  • Bonuses
  #1 (permalink)  
Old 03-09-2009, 08:36 PM
zayphod's Avatar
Senior Member
 
Join Date: Aug 2008
Location: Fremantle, Australia
Posts: 468
Exclamation Norton False Positive

Hi Trikkur,

I visited the pokertrikz website (the home page first, and then the blog page) this morning at home and got a blocked attack message pop up from Norton Internet Security (NIS).

This suprised me since the last thing I expect is the website trying to access my machine. I of course trust you and believe you to run an honest site, but I do need an explanation for the attempted intrusion.

The details from NIS are given below concerning this matter.

Details: Attempted Intrusion "HTTP MSIE7 Uninitialized Memory Code Exec" against your machine was detected and blocked.
Intruder: www.pokertrikz.com(http(80)).
Risk Level: High.
Protocol: TCP.
Attacked IP: localhost.
Attacked Port: 1281.

The link to the symantec website and their description of this is given below. The only thing of difference I note from their explanation is that I use firefox and not IE. However, it is concerning when they make the following statement concerning this intrusion type,

Possible False Positives: There are no known false positives associated with this signature.

HTTP MSIE7 Uninitialized Memory Code Exec: Attack Signature - Symantec Corp.

A fairly quick response to this would be appreciated please.

Cheers
Zayphod
Reply With Quote
  #2 (permalink)  
Old 03-09-2009, 08:45 PM
Administrator
 
Join Date: Jan 2008
Location: Akron, Ohio
Posts: 1,538
Default

Hi,

There have not been any other reports of this and we've tested on IE7 as well. Has anyone else seen anything like this? If so please respond and send Joe or Me a PM with any information you can give us. What page did it occur on? What browser do you use? What AntiVirus? Anything you remember.

Thanks
Reply With Quote
  #3 (permalink)  
Old 03-09-2009, 08:47 PM
Senior Member
 
Join Date: Aug 2008
Location: Notts, UK.
Posts: 1,201
Send a message via Skype™ to ThatDeviant
Default

Nothing here.
Reply With Quote
  #4 (permalink)  
Old 03-09-2009, 08:51 PM
zayphod's Avatar
Senior Member
 
Join Date: Aug 2008
Location: Fremantle, Australia
Posts: 468
Default

I use
1: Mozilla firefox
2: Norton Internet Security (is up to date)
3: First went to Free Poker Training | Online Poker Strategy
4: Went to blog page from the link in the homepage
5: Intrusion message

Cheers
Andrew
Reply With Quote
  #5 (permalink)  
Old 03-09-2009, 08:55 PM
zayphod's Avatar
Senior Member
 
Join Date: Aug 2008
Location: Fremantle, Australia
Posts: 468
Default

good GOD i just let my real name out of the bag
Reply With Quote
  #6 (permalink)  
Old 03-09-2009, 08:55 PM
Joe's Avatar
Joe Joe is offline
Administrator
 
Join Date: Sep 2008
Posts: 42
Default

Quote:
Originally Posted by zayphod View Post
I use
1: Mozilla firefox
2: Norton Internet Security (is up to date)
3: First went to Free Poker Training | Online Poker Strategy
4: Went to blog page from the link in the homepage
5: Intrusion message

Cheers
Andrew
Did you actually go inside a blog when it happened, or did you just go to the blog list page? Can you reproduce the problem? Do you have any more logs or details from NIS you can PM me?
Reply With Quote
  #7 (permalink)  
Old 03-09-2009, 09:07 PM
zayphod's Avatar
Senior Member
 
Join Date: Aug 2008
Location: Fremantle, Australia
Posts: 468
Default

Joe or Trikkur i don't mind if this post is deleted and we carry on via PM. So as not to freak people unnecessarily. I should have gone down the PM route in the first place. Sorry about that.

To the general populace: DONT PANIC!

I will, as Joe suggests, try and recreate this later when I get home (I am currently at work). Is it possible for a third party to make such an intrusion (if it is in fact a real intrusion attempt) and have it appear as if it is coming from a website I am visiting?

Cheers
Reply With Quote
  #8 (permalink)  
Old 03-09-2009, 09:29 PM
Joe's Avatar
Joe Joe is offline
Administrator
 
Join Date: Sep 2008
Posts: 42
Default

Hi Andrew,

I think it's good to keep this thread open in the name of transparency!

The blog list page is something I coded myself and therefore I know there is nothing dodgy within it. I've done some quick googling on the exploit:-

National Vulnerability Database (NVD)National Vulnerability Database (CVE-2009-0075)

I don't know how technical you are, but to paraphrase the details in the above link: it seems that there was a bug in the way IE7 handled errors in deleted webpage elements and it was possible to make a webpage that could create/delete objects to force this to happen.

Given that this vulnerability only existed in unpatched versions of IE7, and you weren't even running IE7 I am 99.999% confident that your machine is uncompromised and that this message is NIS throwing a false positive.

Furthermore, this exploit does not work via an inbound dodgy connection back to your PC - it works by the webpage's Javascript exploiting IE's memory leaks and therefore allowing the webserver to run code on the user's machine. If there was a connection back to your PC, it would be very unlikely to be from port 80 (this is the standard WWW port). The port 1281 is actually the port on your machine that connected TO the webserver on port 80 - even though that error message makes it look like port 80 connected back to your machine.

The only explanation I can think of is something caused an error in the process of deleting an object (maybe the homepage hadn't completely finished loading when you clicked on the List Blogs link) and NIS thought it was an attempt to exploit this bug in IE. What I don't understand is why I haven't seen it, as I run NIS and Firefox 3.07 and must have clicked around thousands of times since I started working on the site.

Anyway I hope this relieves you somewhat

Cheers

Joe
Reply With Quote
  #9 (permalink)  
Old 03-09-2009, 09:34 PM
zayphod's Avatar
Senior Member
 
Join Date: Aug 2008
Location: Fremantle, Australia
Posts: 468
Default

Hi Joe,

no dramas mate. It all sounds good. i will try and recreate it at home and see if I can get it to happen again. If it does I will give you the full details. Might be time for NIS to add a false positive to their list

There is a good possibility that I did indeed try and log in before all was loaded.

I have faith in the pokertrikz team and thank you and trikkur for your prompt responses.

Cheers
Zayphod (forget this Andrew cat...I dont know who he is)

Last edited by zayphod; 03-09-2009 at 09:37 PM. Reason: someone called andrew keeps putting his name on my posts
Reply With Quote
  #10 (permalink)  
Old 03-09-2009, 10:40 PM
zayphod's Avatar
Senior Member
 
Join Date: Aug 2008
Location: Fremantle, Australia
Posts: 468
Default

Hi Trikkur or Joe,

can you edit the title of this thread so it doesn't appear as "in your face" as it is now. i think Joe handled this really well and for the sake of transparency it should stay up as Joe said but the title can be downgraded a bit

Cheers
Zayphod
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -4. The time now is 06:01 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.0 RC2 ©2009, Crawlability, Inc.
Template-Modifications by TMS

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42