hi,
heute bin ich auf etwas gestosen was mich ein wenig in panik versetzt hat und zwar diese seite:
VORSICHT, KÖNNTE GEFÄRLICH SEIN BESSER NUR IN SANDBOX/VIRTUELLER MASCHIENE ÖFFNEN http://www.supersonicads.com/delivery/toolbar.php?&applicationKey=2acafbdd&country=DE&language=DE&dynamicParameter=2033001-5669-x1-50008-120d7c97-129017-135675-0-15-1-133-DE-24-1-0.141-0-0-0-1e4a8842&destination=click.php%3FdynamicParameter%3D2033001-5669-x1-50008-120d7c97-129017-135675-0-15-1-133-DE-24-1-0.141-0-0-0-1e4a8842 bzw fals link ablaufen sollte: http://www.dleasy.net/FCR/?ref=233004&guid=23f4518a-dc3d-4103-b4b0-9972783d9112 oder: http://www.dleasy.net/FCR/
hat bei mir das komplette einfrieren meines thinkpads hervorgerufen, ohne dass ich etwas gedownloadet oder explizit ausgefürt habe. ich hoffe stark dass der schadcode nur einen speichervollauf hervorgerufen hat und nicht aus der firefox javascript sandbox ausbrechen konnte, so lässt es auf jeden fall die logfile vermuten die ich nach dem harten ausschalten und neustarten mir durchgesehen hatte:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 | ....... Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398169] Pid: 32361, comm: firefox Tainted: G W 2.6.32-5-686-bigmem #1 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398172] Call Trace: Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398181] [<c108fda8>] ? oom_kill_process+0x60/0x201 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398185] [<c1090325>] ? __out_of_memory+0xf4/0x107 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398188] [<c1090392>] ? out_of_memory+0x5a/0x7c Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398192] [<c1092c54>] ? __alloc_pages_nodemask+0x3ef/0x4d9 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398196] [<c1092d4a>] ? __get_free_pages+0xc/0x17 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398199] [<c10b6821>] ? __kmalloc_track_caller+0x34/0x124 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398204] [<c11dff26>] ? sock_alloc_send_pskb+0x8e/0x257 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398207] [<c11e3cf2>] ? __alloc_skb+0x4a/0x115 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398211] [<c11dff26>] ? sock_alloc_send_pskb+0x8e/0x257 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398215] [<c10b52c3>] ? __slab_free+0x66/0x21c Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398219] [<c1143b33>] ? copy_from_user+0x27/0x10e Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398222] [<c11e00fb>] ? sock_alloc_send_skb+0xc/0xf Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398226] [<c1240d6f>] ? unix_stream_sendmsg+0x134/0x2c4 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398230] [<c11dd239>] ? __sock_sendmsg+0x43/0x4a Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398233] [<c11dd2e3>] ? sock_aio_write+0xa3/0xb0 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398238] [<c10bac89>] ? do_sync_readv_writev+0xb8/0xf9 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398242] [<c100c705>] ? sched_clock+0x5/0x7 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398247] [<c104a65a>] ? autoremove_wake_function+0x0/0x2d Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398250] [<c10bab36>] ? rw_copy_check_uvector+0x59/0xc3 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398254] [<c104c8e0>] ? hrtimer_forward+0x10c/0x124 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398258] [<c110a5ec>] ? security_file_permission+0xc/0xd Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398262] [<c10bb2ea>] ? do_readv_writev+0x81/0xd6 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398265] [<c11dd240>] ? sock_aio_write+0x0/0xb0 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398269] [<c1075ab9>] ? __rcu_process_callbacks+0x6c/0x227 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398272] [<c1075ca7>] ? rcu_process_callbacks+0x33/0x39 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398276] [<c10bb376>] ? vfs_writev+0x37/0x43 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398279] [<c10bb457>] ? sys_writev+0x3c/0x91 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398282] [<c100813b>] ? sysenter_do_call+0x12/0x28 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398284] Mem-Info: Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398286] DMA per-cpu: Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398288] CPU 0: hi: 0, btch: 1 usd: 0 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398290] CPU 1: hi: 0, btch: 1 usd: 0 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398292] Normal per-cpu: Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398294] CPU 0: hi: 186, btch: 31 usd: 158 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398296] CPU 1: hi: 186, btch: 31 usd: 189 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398298] HighMem per-cpu: Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398300] CPU 0: hi: 186, btch: 31 usd: 180 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398302] CPU 1: hi: 186, btch: 31 usd: 131 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398307] active_anon:505339 inactive_anon:84227 isolated_anon:0 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398308] active_file:21609 inactive_file:18610 isolated_file:0 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398310] unevictable:31 dirty:0 writeback:0 unstable:0 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398311] free:706391 slab_reclaimable:6236 slab_unreclaimable:159285 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398312] mapped:33948 shmem:68371 pagetables:5214 bounce:0 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398319] DMA free:3520kB min:64kB low:80kB high:96kB active_anon:0kB inactive_anon:0kB active_file:0kB inactive_file:0kB unevictable:0kB isolated(anon):0kB isolated(file):0kB present:15868kB mlocked:0kB dirty:0kB writeback:0kB mapped:0kB shmem:0kB slab_reclaimable:32kB slab_unreclaimable:12176kB kernel_stack:0kB pagetables:0kB unstable:0kB bounce:0kB writeback_tmp:0kB pages_scanned:0 all_unreclaimable? yes Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398324] lowmem_reserve[]: 0 865 5909 5909 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398332] Normal free:159364kB min:3728kB low:4660kB high:5592kB active_anon:0kB inactive_anon:0kB active_file:4kB inactive_file:160kB unevictable:0kB isolated(anon):0kB isolated(file):0kB present:885944kB mlocked:0kB dirty:0kB writeback:0kB mapped:76kB shmem:0kB slab_reclaimable:24912kB slab_unreclaimable:624964kB kernel_stack:3856kB pagetables:48kB unstable:0kB bounce:0kB writeback_tmp:0kB pages_scanned:33 all_unreclaimable? no Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398338] lowmem_reserve[]: 0 0 40353 40353 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398346] HighMem free:2662680kB min:512kB low:5944kB high:11380kB active_anon:2021356kB inactive_anon:336908kB active_file:86432kB inactive_file:74280kB unevictable:124kB isolated(anon):0kB isolated(file):0kB present:5165244kB mlocked:124kB dirty:0kB writeback:0kB mapped:135716kB shmem:273484kB slab_reclaimable:0kB slab_unreclaimable:0kB kernel_stack:0kB pagetables:20808kB unstable:0kB bounce:0kB writeback_tmp:0kB pages_scanned:131 all_unreclaimable? no Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398352] lowmem_reserve[]: 0 0 0 0 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398356] DMA: 8*4kB 8*8kB 40*16kB 27*32kB 4*64kB 1*128kB 2*256kB 0*512kB 1*1024kB 0*2048kB 0*4096kB = 3520kB Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398365] Normal: 12843*4kB 13385*8kB 32*16kB 1*32kB 2*64kB 2*128kB 0*256kB 0*512kB 0*1024kB 0*2048kB 0*4096kB = 159380kB Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398374] HighMem: 172906*4kB 173762*8kB 31570*16kB 2326*32kB 22*64kB 0*128kB 0*256kB 0*512kB 0*1024kB 0*2048kB 0*4096kB = 2662680kB Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398383] 120411 total pagecache pages Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398385] 11818 pages in swap cache Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398387] Swap cache stats: add 1286408, delete 1274590, find 5271573/5322802 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398389] Free swap = 3352164kB Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.398391] Total swap = 3788792kB Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.423704] 1835008 pages RAM Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.423707] 1607682 pages HighMem Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.423709] 319701 pages reserved Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.423710] 157612 pages shared Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.423712] 753369 pages non-shared Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.423715] Out of memory: kill process 3004 (gnome-session) score 111255 or a child Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.423719] Killed process 3110 (gnome-power-man) Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648779] multiload-apple invoked oom-killer: gfp_mask=0x44d0, order=2, oom_adj=0 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648785] multiload-apple cpuset=/ mems_allowed=0 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648789] Pid: 22400, comm: multiload-apple Tainted: G W 2.6.32-5-686-bigmem #1 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648792] Call Trace: Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648801] [<c108fda8>] ? oom_kill_process+0x60/0x201 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648805] [<c1090325>] ? __out_of_memory+0xf4/0x107 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648808] [<c1090392>] ? out_of_memory+0x5a/0x7c Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648812] [<c1092c54>] ? __alloc_pages_nodemask+0x3ef/0x4d9 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648816] [<c1092d4a>] ? __get_free_pages+0xc/0x17 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648820] [<c10b6821>] ? __kmalloc_track_caller+0x34/0x124 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648825] [<c11dff26>] ? sock_alloc_send_pskb+0x8e/0x257 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648829] [<c11e3cf2>] ? __alloc_skb+0x4a/0x115 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648832] [<c11dff26>] ? sock_alloc_send_pskb+0x8e/0x257 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648838] [<c102a97c>] ? __wake_up_sync_key+0x33/0x49 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648842] [<c1143b33>] ? copy_from_user+0x27/0x10e Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648845] [<c11e00fb>] ? sock_alloc_send_skb+0xc/0xf Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648850] [<c1240d6f>] ? unix_stream_sendmsg+0x134/0x2c4 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648853] [<c11dd239>] ? __sock_sendmsg+0x43/0x4a Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648856] [<c11dd2e3>] ? sock_aio_write+0xa3/0xb0 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648861] [<c10bac89>] ? do_sync_readv_writev+0xb8/0xf9 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648866] [<c104a65a>] ? autoremove_wake_function+0x0/0x2d Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648869] [<c10bab36>] ? rw_copy_check_uvector+0x59/0xc3 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648874] [<c110a5ec>] ? security_file_permission+0xc/0xd Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648877] [<c10bb2ea>] ? do_readv_writev+0x81/0xd6 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648880] [<c11dd240>] ? sock_aio_write+0x0/0xb0 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648883] [<c10baa75>] ? fsnotify_access+0x5a/0x61 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648887] [<c110a5ec>] ? security_file_permission+0xc/0xd Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648890] [<c10bb376>] ? vfs_writev+0x37/0x43 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648893] [<c10bb457>] ? sys_writev+0x3c/0x91 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648897] [<c100813b>] ? sysenter_do_call+0x12/0x28 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648899] Mem-Info: Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648901] DMA per-cpu: Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648903] CPU 0: hi: 0, btch: 1 usd: 0 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648905] CPU 1: hi: 0, btch: 1 usd: 0 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648907] Normal per-cpu: Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648909] CPU 0: hi: 186, btch: 31 usd: 160 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648912] CPU 1: hi: 186, btch: 31 usd: 163 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648913] HighMem per-cpu: Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648915] CPU 0: hi: 186, btch: 31 usd: 155 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648917] CPU 1: hi: 186, btch: 31 usd: 57 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648922] active_anon:504901 inactive_anon:84376 isolated_anon:0 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648923] active_file:21614 inactive_file:18600 isolated_file:0 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648925] unevictable:31 dirty:0 writeback:0 unstable:0 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648926] free:706732 slab_reclaimable:6236 slab_unreclaimable:159285 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648927] mapped:34012 shmem:68435 pagetables:5192 bounce:0 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648934] DMA free:3520kB min:64kB low:80kB high:96kB active_anon:0kB inactive_anon:0kB active_file:0kB inactive_file:0kB unevictable:0kB isolated(anon):0kB isolated(file):0kB present:15868kB mlocked:0kB dirty:0kB writeback:0kB mapped:0kB shmem:0kB slab_reclaimable:32kB slab_unreclaimable:12176kB kernel_stack:0kB pagetables:0kB unstable:0kB bounce:0kB writeback_tmp:0kB pages_scanned:0 all_unreclaimable? yes Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648939] lowmem_reserve[]: 0 865 5909 5909 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648948] Normal free:159240kB min:3728kB low:4660kB high:5592kB active_anon:0kB inactive_anon:0kB active_file:24kB inactive_file:120kB unevictable:0kB isolated(anon):0kB isolated(file):0kB present:885944kB mlocked:0kB dirty:0kB writeback:0kB mapped:76kB shmem:0kB slab_reclaimable:24912kB slab_unreclaimable:624964kB kernel_stack:3856kB pagetables:48kB unstable:0kB bounce:0kB writeback_tmp:0kB pages_scanned:33 all_unreclaimable? no Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648954] lowmem_reserve[]: 0 0 40353 40353 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648962] HighMem free:2664168kB min:512kB low:5944kB high:11380kB active_anon:2019604kB inactive_anon:337504kB active_file:86432kB inactive_file:74280kB unevictable:124kB isolated(anon):0kB isolated(file):0kB present:5165244kB mlocked:124kB dirty:0kB writeback:0kB mapped:135972kB shmem:273740kB slab_reclaimable:0kB slab_unreclaimable:0kB kernel_stack:0kB pagetables:20720kB unstable:0kB bounce:0kB writeback_tmp:0kB pages_scanned:0 all_unreclaimable? no Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648968] lowmem_reserve[]: 0 0 0 0 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648972] DMA: 8*4kB 8*8kB 40*16kB 27*32kB 4*64kB 1*128kB 2*256kB 0*512kB 1*1024kB 0*2048kB 0*4096kB = 3520kB Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648981] Normal: 12786*4kB 13373*8kB 42*16kB 1*32kB 2*64kB 2*128kB 0*256kB 0*512kB 0*1024kB 0*2048kB 0*4096kB = 159216kB Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.648989] HighMem: 173036*4kB 173797*8kB 31603*16kB 2331*32kB 22*64kB 0*128kB 0*256kB 0*512kB 0*1024kB 0*2048kB 0*4096kB = 2664168kB Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.649020] 120496 total pagecache pages Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.649022] 11811 pages in swap cache Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.649024] Swap cache stats: add 1286440, delete 1274629, find 5271578/5322819 Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.649026] Free swap = 3352764kB Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.649027] Total swap = 3788792kB Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.674722] 1835008 pages RAM Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.674724] 1607682 pages HighMem Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.674726] 319701 pages reserved Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.674727] 157768 pages shared Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.674729] 751777 pages non-shared Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.674732] Out of memory: kill process 3004 (gnome-session) score 109504 or a child Jan 29 21:20:22 treakis-thinkpad kernel: [2102398.674736] Killed process 3128 (metacity) ........ |
sieht für mich auf jedenfall so aus als wenn firefox so viel arrbeitsspeicher frisst und deshalb der kernel mit dem swappen nicht hinterherkommt und aufräumt
ich habe dann die seite nochmal in einer vm mit windows xp aufgerufen, dort hat sophos antivirus das ding aber geblockt. siehe anhang und erkennt es als Mal/HTMLGen-A
http://www.sophos.com/de-de/threat-center/threat-analyses/viruses-and-spyware/Mal~HTMLGen-A.aspx
meine fragen nun: - wie finde ich raus ob dieser exploit meinen rechner zum einfrieren gebracht hat und währenddessen im firefox gefangen war oder ob er tatsächlich rausgekommen ist. - wie schütze ich mich vor sowas - gibt es ein kostenloses antimalewareprogramm was mein linux schützt so wie sophos es in diesem fall bei windows tut.



2004 – 2012 ubuntuusers.de • Einige Rechte vorbehalten