PDA

View Full Version : attacks from this site?


argus tuft
October 22nd, 2006, 08:09 PM
hi all, not sure where exactly to post this, but my AV just detected an attempt to extract personal information from my pc, not the first time its happaned to me at wilders either... I hope im suffering from a paranoid AV program, any-one else had anything like this happen here??http://www.wilderssecurity.com/images/smilies/confused.gif
???

LowWaterMark
October 22nd, 2006, 08:22 PM
What warning/alert did it give, for what link or file or whatever, and what AV was it?

dw2108
October 22nd, 2006, 09:42 PM
No paranoid behavior. Hackers have been trying to crack this site to prevent people at Wilders from assisting people who visit this site in need help with viruses, worms trojans as well as security or other advice.

Dave

metallicakid15
October 22nd, 2006, 10:58 PM
my av dosent seem to be working :(

argus tuft
October 23rd, 2006, 02:10 AM
LowWaterMark, sorry about the delay in getting back... my AV is trend micro 2006, and the alert said something like "trend micro internet security has prevented your private information from being transmitted to www.wilderssecurity.com/etc/etc/etc (address of page i was viewing) if you wish to send this information press add exception" the information being targeted was my credit card no. (if only they knew)

C.S.J
October 23rd, 2006, 07:49 AM
-{ Quote: "LowWaterMark, sorry about the delay in getting back... my AV is trend micro 2006, and the alert said something like "trend micro internet security has prevented your private information from being transmitted to www.wilderssecurity.com/etc/etc/etc (address of page i was viewing) if you wish to send this information press add exception" the information being targeted was my credit card no. (if only they knew)" }-

easily answered,

you have added information such as your name / email into your protect private information, when you submit ie., your name to wilders as maybe its your username, trend blocks this information, as it should do.

but this is definatly the problem whats going on, your antivirus is not broken or acting funny, its actually performing what you told it to do. *lol*

1. never put your credit card into these private data parts of suites, a number of suites do this... but i see no point really.
2. if your going to use your name or email, make sure you add it to excepetions of email as whenever its inputted in a email, it will prevent the email being sent.
3. add exceptions to websites you want to return to, or turn off the feature completly. (if the site looks and feels clean that is)


i was quite sure after your first post without any other details, that this was your problem, but didnt decide to reply till more details were posted, but now im 100% sure.

configure your settings on this matter, and let us know how you get on.

LowWaterMark
October 23rd, 2006, 07:54 AM
-{ Quote: "LowWaterMark, sorry about the delay in getting back... my AV is trend micro 2006, and the alert said something like "trend micro internet security has prevented your private information from being transmitted to www.wilderssecurity.com/etc/etc/etc (address of page i was viewing) if you wish to send this information press add exception" the information being targeted was my credit card no. (if only they knew)" }-Ah, I had wondered if it was something like that. I think you'll find my post in the following thread, (plus the link to the dslreports thread within it), explains a lot about how those kind of "private data" monitors work...

http://www.wilderssecurity.com/showthread.php?t=107512

In short, the data that forms dynamically generated webpages at sites like this will contain lots of numbers, and if you enable such a monitoring tool to alert you on something like your credit card (or pin or social security numbers), then you can see false positives like this.

Since there are no pages on this site that ask for credit card numbers, you are getting a false alert on that.

aigle
October 23rd, 2006, 02:31 PM
-{ Quote: "easily answered,

you have added information such as your name / email into your protect private information, when you submit ie., your name to wilders as maybe its your username, trend blocks this information, as it should do. " }-

If ur explanation is correct, he should not be able to login while running TM but I don,t see such a complain by him.

C.S.J
October 23rd, 2006, 03:10 PM
it was an invalid referance to the privata data option in trend micro 2007.

just an example, to help him locate his problem and fix it.

aigle
October 23rd, 2006, 03:55 PM
So it was from TM firewall or some other componenet?