Graal Forums

Graal Forums (https://forums.graalonline.com/forums/index.php)
-   Bomy Island Main Forum (https://forums.graalonline.com/forums/forumdisplay.php?f=80)
-   -   I got this in my e-mail. (https://forums.graalonline.com/forums/showthread.php?t=1479)

IceHawk 04-17-2001 01:22 PM

Quote:

Hello Graal2001 and GraalClassic players this message
is very important as myself and Stefan Knorr have
found a very dangerous secureity hole in most Graal2001
clients, hackers could and already have exploited
this secureity hole and has stolen some accounts,
Stefan has coded a patch to secure this hole, it can
be download at http://www20.brinkster.com/graalonli...l2001patch.zip
we are doing every thing we can to get FTP and Account
functions back, this patch will secure your graal clients
until Stefan releases the next version of Graal2001,
we will find out who has been doing this and take legal
action against these hackers.
-Stephane Portha.
I believe this is fake, I e-mailed it to Stefan and Unixmad
but I don't know
It came from [email protected].

04-17-2001 01:28 PM

Hmm...
that seems definetly fake.
the sender probably the owner of www20.brinkster.com/graalonline whoever that is..

TylerS36 04-17-2001 01:53 PM

wow, I didnt know Unixmad's english has improved so much since I last seen him speak.

omni-m00gle 04-17-2001 02:01 PM

Probably used a mail manipulator or some tinker. Wouldnt trust them..

Lycia 04-17-2001 03:47 PM

Hmmmm, that e-mail sounds awfully familiar.

I got mail bombed with about 100 messages the other day from that same e-mail.

Valder 04-17-2001 05:46 PM

i think the sender is trying to get the accounts by sending the message to ppl...

grim_squeaker_x 04-17-2001 07:17 PM

Blah.
 
That isn't Unixmad I'm extremely sure about that because he would have just posted it io the graal2001 site if this was the case and would then have just ordered us to re-run the setup.exe.
And as someone else said, it uses too good grammar in it (No offence meant to Unixmad of course ;))

Pago 04-17-2001 07:29 PM

All you have to do is catch Unixmad in the streets and ask him to spell "security"... heh ;)

FatherDante 04-17-2001 09:30 PM

He also would have put the accent in his name. :)

IceHawk 04-17-2001 10:35 PM

Except that I'm a ***** and I ran the program accidently.

StoneColdRichie 04-17-2001 10:36 PM

Quote:

Originally posted by IceHawk
Except that I'm a ***** and I ran the program accidently.
Hey GUY why are you home from school? DID YOU CUT YOU CUTTER?

IceHawk 04-17-2001 10:36 PM

AND I was on a crack website, and on the request list was Graal 2001, and these people were hackers so maybe the hackers are from the "Ebola Virus Crew"

activeconvict 04-17-2001 10:42 PM

If you guys are looking for grammar problems, IM AudioSonyX (AIM/AOL)

G_yoshi 04-17-2001 11:57 PM

what happend when you ran the program?

Cyboars 04-18-2001 12:10 AM

Probally didn't look like it ran and stole his stuff and starting to delete his HD, its basicly the same as the program at:

http://graalcheat2001.homestead.com/

then again i COULD be wrong..

omni-m00gle 04-18-2001 03:37 AM

Still wouldnt trust someone that works for graal that knew that much english. No offense..

sniperjoe10 04-18-2001 03:43 AM

I wouldn't trust it, if I were you ..

IceHawk 04-18-2001 06:39 AM

Absolutely nothing happened when i ran the program.

04-18-2001 06:42 AM

It probably did something that allowed access to your PC.
I opened a fake gserver by accident once, nothing happend but the next day i was MATRIXHAXORRED.

FatherDante 04-18-2001 07:12 AM

I've had 1 virus before, it was a nasty little bugger. I was proud of myself for sweeping it out by myself after about half an hour, but in retrospect, it's kind of stupid, a good virus scan would have gotten rid of it in seconds. Oh well.

Valder 04-18-2001 07:14 AM

hmmm......i don't really recommend opening it though

04-18-2001 07:16 AM

Quote:

Originally posted by IceHawk
Absolutely nothing happened when i ran the program.
h0h0 you are screwed.
Most likely sub7, they just renamed server.exe (the virus) to a different name and made it a different icon.
Go to start>run>win.ini
see if there is anything after "load=" or "run=".
Heh, it is fun to sub7 yourself and play around with the features. You just have to remember to hit the remove button when you're done playing around.

juztin890 04-18-2001 07:20 AM

It contains a trojan.

----------------
Date: 18/04/01, Time: 00:10:48, Default
The file GraalCheat2001.exe in the compressed file
C:\PERSONAL\Justin\Graal\TEST\Graal2001patch.zip
is infected with the Trojan Horse virus.
----------------


dats what meh virus checker said.

Immitat0r 04-18-2001 07:43 AM

Probably a server for your comp so they can access it, another reason Unixmad does not speak that good english(seriously), and also if they made something like that he would probably post it on the main g2k1 webpage, because he just wouldnt e-mail people to download it.

juztin890 04-18-2001 07:46 AM

I doubt it was a server tho... i mean it coulda been but like my firewall never came up with the usual things: asking if the program can be allowed a pass to the net.
I know it sounds stupid virus software needing permission to access the net but like they all do for me... well, sub seven did when i had it and lodza other *** viruses i have contracted in the past =/

Immitat0r 04-18-2001 07:48 AM

Thats what I am saying, probably a sub7 server, I have got so many people who think I am dumb to go over and download a gif file thats 400kb and zipped, I would never be that stupid but apperenlty now they can get as small as 50k, so its more harder to tell.

IceHawk 04-18-2001 07:51 AM

Good thing i downloaded a couple of firewalls

IceHawk 04-18-2001 07:52 AM

Does the "remove" button work for other servers on your computer?

04-18-2001 07:53 AM

an image file isn't an executable...it can't contain a virus.
Ohhh you mean the zip. Nevermind. =/

Immitat0r 04-18-2001 07:55 AM

Now they can hide servers in Mp3s, just to warn people, someone fooled me the other day with it, and noticed they where trying to get my icq password and deleted it. So if anyones like "Download a Mp3 file!" I would rather you not do that and rather go on napster or search it somewhere.

galen 04-18-2001 01:54 PM

Trojan.Win32.Munga

Lycia 04-18-2001 02:40 PM

My virus detector picked up no viruses from those mailbomb messages I got.

Maybe its a randomizer.

grim_squeaker_x 04-18-2001 07:43 PM

Blah.
 
I extracted something from the source of that actual E-Mail:
Quote:

X-Sieve: cmu-sieve 2.0
Return-Path: <[email protected]>
Received: from server0010.freedom2surf.net (server0010.freedom2surf.net [194.106.56.10])
by server0034.freedom2surf.net (8.9.3/8.9.3/Debian 8.9.3-21) with ESMTP id XAA16109
for <[email protected]>; Mon, 16 Apr 2001 23:20:40 GMT
From: [email protected]
Received: from scaup.mail.pas.earthlink.net (scaup.mail.pas.earthlink.net [207.217.121.49])
by server0010.freedom2surf.net (8.9.3/8.9.3/Debian/GNU/f2s) with ESMTP id XAA05963
for <[email protected]>; Mon, 16 Apr 2001 23:20:38 GMT
Received: from mail.graal2001.com (evrtwa1-ar1-252-228.elnk.dsl.gtei.net [4.34.252.228])
by scaup.mail.pas.earthlink.net (EL-8_9_3_3/8.9.3) with SMTP id QAA01983
for <[email protected]>; Mon, 16 Apr 2001 16:20:38 -0700 (PDT)
Date: Mon, 16 Apr 2001 16:20:38 -0700 (PDT)
Message-Id: <[email protected] t>
To: [email protected]
Subject: Critical Security holes found in Graal2001 clients, Download Patch update to keep your accounts secure.
If yo pay good attention to the above stuff you will notice the:
"From: [email protected]
Received: from scaup.mail.pas.earthlink.net (scaup.mail.pas.earthlink.net [207.217.121.49])"
Which means that it actually was sent using earthlink.net, and that "scaup.mail.pas.earthlink.net [207.217.121.49]" is in it several times.

zwr 04-18-2001 08:06 PM

it's Hard Drive Killer Pro 5.0 Beta

IceHawk 04-18-2001 10:55 PM

Harddrive killer?!

Cyboars 04-19-2001 12:30 AM

Yeah...downloads your Hard Drive and then deletes it from your computer...be careful if you turn your computer on and theres an image on your desktop talking about sending or receiving....

zwr 04-19-2001 04:21 AM

according to the official site of that thing it formats all your hd's in 2 seconds.


All times are GMT +2. The time now is 05:19 PM.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.