FPSBanana
- Plinko
- Server Admin
- Posts: 8568
- Joined: Fri May 23, 2008 11:23 am
- Location: Georgia, USA
-
Games Played
Ville Awards
Re: FPSBanana
What I was able to read up on it, it's a bootkit, which is somewhat different. It actually forces itself into the boot sequence for Windows. What I've read was somewhat confusing, but every report I found seemed that traditional rootkit remedies don't work for it and most people seemed unable to remove it entirely.
I continue to find it jaw-dropping that Windows allows anything like this to ingrain itself into your OS.
I continue to find it jaw-dropping that Windows allows anything like this to ingrain itself into your OS.
"I made all my gold into pants" - Ignatius

- Stevo
- Everlasting Villun
- Posts: 8753
- Joined: Sun Oct 22, 2006 10:01 pm
- Location: Orange County, CA
- Minecraft name: StevoTVR
- Uplay name: StevoTVR
- Contact:
-
Games Played
Ville Awards
Re: FPSBanana
You just have to replace the MBR using the Windows installer/recovery disk to stop it from loading.
- frostdillicus
- Retired Admin
- Posts: 1100
- Joined: Fri Dec 14, 2007 1:04 pm
-
Games Played
Ville Awards
Re: FPSBanana
From what I read, it's not an IE exploit, but rather a Java based attack and therefore all browsers are susceptible unless you are running AdBlock or the like.
- Plinko
- Server Admin
- Posts: 8568
- Joined: Fri May 23, 2008 11:23 am
- Location: Georgia, USA
-
Games Played
Ville Awards
Re: FPSBanana
Yeah, I got mine via Firefox, but the fact that Java can even install things into your Windows boot record is insane, why would you allow that at all?
"I made all my gold into pants" - Ignatius

- frostdillicus
- Retired Admin
- Posts: 1100
- Joined: Fri Dec 14, 2007 1:04 pm
-
Games Played
Ville Awards
Re: FPSBanana
I did a bit of research but I don't know if this was the attack vector. It seems that there is a way using properly formatted HTML to essentially have the command line version of java run well, anything. Yes, it's a simplistic description, but I'm not a security expert so I don't know the full story.
Sun pretty much said it wasn't a big enough threat to patch when the exploit was brought to their attention, and will only patch it when they release their quarterly patch.
Sun pretty much said it wasn't a big enough threat to patch when the exploit was brought to their attention, and will only patch it when they release their quarterly patch.
- Fox_Blaze
- Villun
- Posts: 1070
- Joined: Tue May 12, 2009 5:40 pm
- Location: Bozeman, Montana
- Contact:
-
Games Played
Ville Awards
Re: FPSBanana
I have the smss.exe file, but not the loader.exe or the iexplorer.exe file in the processes tab in the task manager.
I don't know what's going on.
I don't know what's going on.

Thanks Nerevarine King for the banner!
TVC '10-Hale's Angels (3rd place)
TVC '11-League of Evil Villuns (2nd place)[/spoiler]
- frostdillicus
- Retired Admin
- Posts: 1100
- Joined: Fri Dec 14, 2007 1:04 pm
-
Games Played
Ville Awards
Re: FPSBanana
smss.exe is a normal windows process. As long as the version of smss.exe is in your windows\system32 directory it is legit. If you don't have the other two processes, you shouldn't have anything to worry about.
- Clay Pigeon
- Retired Admin
- Posts: 4811
- Joined: Sun Nov 12, 2006 12:45 pm
- Location: Michigan
-
Games Played
Ville Awards
Re: FPSBanana
If this is java-based, couldn't it be used as a vector to compromise just about any system, regardless of OS?
"No dictator, no invader can hold an imprisoned population by force of arms forever. There is no greater power in the universe than the need for freedom. Against that power tyrants and dictators cannot stand." - The prophet G'Kar
Re: FPSBanana
Mind linking to your research?frostdillicus wrote:I did a bit of research but I don't know if this was the attack vector. It seems that there is a way using properly formatted HTML to essentially have the command line version of java run well, anything. Yes, it's a simplistic description, but I'm not a security expert so I don't know the full story.
Sun pretty much said it wasn't a big enough threat to patch when the exploit was brought to their attention, and will only patch it when they release their quarterly patch.
- Fox_Blaze
- Villun
- Posts: 1070
- Joined: Tue May 12, 2009 5:40 pm
- Location: Bozeman, Montana
- Contact:
-
Games Played
Ville Awards
Re: FPSBanana
oh alright. I guess I was getting a bit paranoid about it for a little bit ^^;frostdillicus wrote:smss.exe is a normal windows process. As long as the version of smss.exe is in your windows\system32 directory it is legit. If you don't have the other two processes, you shouldn't have anything to worry about.

Thanks Nerevarine King for the banner!
TVC '10-Hale's Angels (3rd place)
TVC '11-League of Evil Villuns (2nd place)[/spoiler]
- frostdillicus
- Retired Admin
- Posts: 1100
- Joined: Fri Dec 14, 2007 1:04 pm
-
Games Played
Ville Awards
Re: FPSBanana
http://www.zdnet.com/blog/security/java ... ttack/6161
http://www.zdnet.com/blog/security/sun- ... tacks/6082
http://threatpost.com/en_us/blogs/serio ... ers-040910
Not exactly a lot of research. I just read it in passing after I saw on the Steam forums that people were saying it was a Java based attacked embedded in an advertisement. Again, I don't know if this was the attack vector used or not.
This attack seems pretty nefarious as it bypasses DEP and ASLR which are designed to keep crap like this from happening.
http://www.zdnet.com/blog/security/sun- ... tacks/6082
http://threatpost.com/en_us/blogs/serio ... ers-040910
Not exactly a lot of research. I just read it in passing after I saw on the Steam forums that people were saying it was a Java based attacked embedded in an advertisement. Again, I don't know if this was the attack vector used or not.
This attack seems pretty nefarious as it bypasses DEP and ASLR which are designed to keep crap like this from happening.
- Stevo
- Everlasting Villun
- Posts: 8753
- Joined: Sun Oct 22, 2006 10:01 pm
- Location: Orange County, CA
- Minecraft name: StevoTVR
- Uplay name: StevoTVR
- Contact:
-
Games Played
Ville Awards
Re: FPSBanana
I don't think that's the same vulnerability as this, unless people are running outdated versions of Java. There's been 2 updates (1 security patch) to Java since those articles were posted.
- frostdillicus
- Retired Admin
- Posts: 1100
- Joined: Fri Dec 14, 2007 1:04 pm
-
Games Played
Ville Awards
Re: FPSBanana
You're right, it probably isn't this specific exploit. However, it is a cross browser exploit as there are reports of people not using IE getting infected.
Then again, it is entirely possible it is this exploit and people are running out of date versions of Java. I know a lot of non tech savvy people who ignore the "so and so has downloaded an upgrade. Would you like to install it?" boxes as they are of the mindset, "It's working correctly at the moment. Anything I do might break it, so I'm not going to do anything."
There are still people out there running IE6 on Windows XP as their primary browser. I wouldn't put it past a lot of people to still have outdated versions of Java running around.
Then again, it is entirely possible it is this exploit and people are running out of date versions of Java. I know a lot of non tech savvy people who ignore the "so and so has downloaded an upgrade. Would you like to install it?" boxes as they are of the mindset, "It's working correctly at the moment. Anything I do might break it, so I'm not going to do anything."
There are still people out there running IE6 on Windows XP as their primary browser. I wouldn't put it past a lot of people to still have outdated versions of Java running around.

- Darklightr
- Villun
- Posts: 636
- Joined: Fri Jul 09, 2010 5:35 pm
- Location: The real questions is, where are you?
-
Games Played
- Dog
- Server Ops
- Posts: 14317
- Joined: Sun Oct 15, 2006 12:12 am
- Location: In the bath, having a good think....
-
Games Played
Ville Awards
Re: FPSBanana
3.0.410
Running on TVX and TVXV
Major code rewrites and a new gamemode...
I like to test it first before making a commit...
Running on TVX and TVXV
Major code rewrites and a new gamemode...
I like to test it first before making a commit...
Who is online
Users browsing this forum: No registered users and 10 guests