Warning: Autopia.org spreading computer viruses

A General Discussion forum for cars and other topics, and a great place to introduce yourself if you are new to NICO!
User avatar
Thorshammer
Posts: 105
Joined: Fri Jul 10, 2009 2:35 pm
Car: FX35

Post

Autopia.org
Erroneously accepted by some as the internet bible of car care, autopia was exposed earlier this week for using self replicating viruses and malware to attack visitors and it's own members.
The infestation has been growing and has infected another web site.
People are being warned to remove all links to autopia.
The infestation may or not be the result of hackers. Conventional thinking is that the virus should have been removed by now unless someone in management planted tiem.
Here is the last report from Google:
What is the current listing status for autopia.org?

Site is listed as suspicious - visiting this web site may harm your computer.

Part of this site was listed for suspicious activity 4 time(s) over the past 90 days.

What happened when Google visited this site?

Of the 738 pages we tested on the site over the past 90 days, 388 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2010-09-03, and the last time suspicious content was found on this site was on 2010-09-03.
Malicious software includes 8 scripting exploit(s), 8 trojan(s), 6 exploit(s). Successful infection resulted in an average of 3 new process(es) on the target machine.

Malicious software is hosted on 8 domain(s), including plotecco.co.cc/, autourl.in/, browserservices.in/.

1 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including plotecco.co.cc/.

This site was hosted on 2 network(s) including AS31815 (MEDIATEMPLE), AS26496 (PAH).

Has this site acted as an intermediary resulting in further distribution of malware?

Over the past 90 days, autopia.org appeared to function as an intermediary for the infection of 1 site(s) including stumbleupon.com/.

Has this site hosted malware?

No, this site has not hosted malicious software over the past 90 days.

How did this happen?

In some cases, third parties can add malicious code to legitimate sites, which would cause us to show the warning message.

Next steps:

Return to the previous page.
If you are the owner of this web site, you can request a review of your site using Google Webmaster Tools. More information about the review process is available in Google's Webmaster Help Center


User avatar
MellowZ32
Posts: 27320
Joined: Sat Feb 16, 2008 8:29 pm
Car: Pornographer's car
Location: Parts Unknown

Post

who?
thanks for the heads up!

User avatar
TU_MADRE
Posts: 66
Joined: Mon Aug 30, 2010 4:36 pm
Car: Civic With a D17

Post

Never heard of it before but thanks anyways.

User avatar
Red coupe
Posts: 12216
Joined: Wed Sep 15, 2004 6:51 pm
Car: 92 Nissan 240sx Coupe

Post

How did that web page infect other webpages?

Sounds like this could be little more then dumb panic, tbh.
Is the only reason people are worked up because google called it "suspicious"? because that has definitely happened to clean sites before.

User avatar
Thorshammer
Posts: 105
Joined: Fri Jul 10, 2009 2:35 pm
Car: FX35

Post

I think the only thing dumb is a person who would not heed the warnings posted all over the Internet and link on to autopia.
It's not just Google, Its every anti virus software that comes in contact with autopia.org.
The site is dangerous.
Its been over a week and instead of the problem going away, it has only gotten worse.
They either can't remove the virus and malware or they don't want too.
Your guess is as good as mine.
I don't know of any other site that was hit as hard as autopia:
But if you think autopia's safe and you can't live without it, then by all means don't let me stop you.
I would be truly surprised if autopia recovered from this.
It's going to take a long time for people to trust that site again.

What is the current listing status for autopia.org?

Site is listed as suspicious - visiting this web site may harm your computer.

Part of this site was listed for suspicious activity 4 time(s) over the past 90 days.

What happened when Google visited this site?

Of the 827 pages we tested on the site over the past 90 days, 456 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2010-09-05, and the last time suspicious content was found on this site was on 2010-09-05.
Malicious software includes 8 scripting exploit(s), 8 trojan(s), 6 exploit(s). Successful infection resulted in an average of 3 new process(es) on the target machine.

Malicious software is hosted on 8 domain(s), including plotecco.co.cc/, autourl.in/, browserservices.in/.

1 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including plotecco.co.cc/.

This site was hosted on 3 network(s) including AS31815 (MEDIATEMPLE), AS32244 (LIQUID), AS26496 (PAH).

Has this site acted as an intermediary resulting in further distribution of malware?

Over the past 90 days, autopia.org appeared to function as an intermediary for the infection of 1 site(s) including stumbleupon.com/.

Has this site hosted malware?

No, this site has not hosted malicious software over the past 90 days.

How did this happen?

In some cases, third parties can add malicious code to legitimate sites, which would cause us to show the warning message.

Next steps:

Return to the previous page.
If you are the owner of this web site, you can request a review of your site using Google Webmaster Tools. More information about the review process is available in Google's Webmaster Help Center.

Alfador
Posts: 3043
Joined: Thu May 19, 2005 4:55 pm
Car: 1990 Nissan 240SX Hatch
Location: The People's Republic of Taxachusetts
Contact:

Post

"Malicious software is hosted on 8 domain(s), including plotecco.co.cc/, autourl.in/, browserservices.in/."


Noscript FTW. Basic HTML can't deliver malware. Flash and Javascripting can. Most "suspicious" site pages that try to be legit fail because they use a third party advertising provider that does a poor job vetting its s***. It looks like these ads are coming from third party domains, probably with content inserted on the pages, such as ads. If those domains can't load script, they can't dump malware on you.

User avatar
Jesda
Posts: 39644
Joined: Mon May 05, 2003 1:50 pm
Location: STL, DTW
Contact:

Post

Google thinks my university's registrar page is an attack site.

User avatar
skydragoness
Posts: 9394
Joined: Wed Jul 24, 2002 6:49 am
Car: 03' 350z Touring 6spd
92' 240sx 60k survivor :)
Location: North DFW, TEJAS
Contact:

Post

I did a search on car wax on NICO a few days ago and I saw the OP bashing Autopia.org. Do you just really dislike their forum? (Not defending them, I am not registered on their site/forum). Just curious.

User avatar
Thorshammer
Posts: 105
Joined: Fri Jul 10, 2009 2:35 pm
Car: FX35

Post

Some people love clicks others don't
For me autopia.org has the appeal of a roach running across the table of a $500.00 a plate banquet.

User avatar
AZhitman
Administrator
Posts: 54542
Joined: Mon Apr 29, 2002 2:04 am
Car: 58 L210, 63 Bluebird RHD, 64 NL320, 65 SPL310, 66 411 RHD, 67 WRL411, 68 510 SR20, 75 280Z RB25, 77 620 SR20, 79 B310, 90 Z32, 91 GTi-R, 92 Silvia Qs, 98 S14, 23 Z.
Location: Surprise, Arizona
Contact:

Post

Red coupe wrote:How did that web page infect other webpages?

Sounds like this could be little more then dumb panic, tbh.
Actually, no. It's happening to a lot of sites at mediatemple, whose setup sucks. Bad code and hosting accounts that are set up with crappy permissions where one bad site on a server can start to infect others... I'm no expert, but our webdude is. Here's more info:

http://www.inquisitr.com/47860/the-epic ... e-failure/
http://news.cnet.com/8301-27080_3-20005978-245.html
http://community.websense.com/blogs/sec ... t-Kit.aspx
http://johnkary.net/mediatemple-wordpre ... -security/
http://news.softpedia.com/news/New-Mass ... 2263.shtml
http://blog.unmaskparasites.com/2010/08 ... ple-sites/


Return to “General Chat”