Re: Site shutdown today from .RAR virus files uploaded?

21
boytoy wrote: Sun Jul 02, 2023 9:04 pm Hang on not doubting you just want to know how you are certain your broker account got exposed via the rar files? Cos I downloaded two or three of those rar files and opened them up just saw lots of screenshot files and even extracted a few onto my desktop but the pics wouldnt open but no one got into my broker or anything else and I was trading at the time and even left my machine on... scanned all my files after Mrtools or Jimmy's post about it and it said there was a trojan in the archive. Sounds like you were already having some security issues perhaps your e-mail has been guessed... what antivirus you running? ESET internet security you said? Is that any good?
i don't believe in coincidences and it happened exactly after i opened the rar. If you want some absolute certainty i have none, i don't even know how they did it.
as far as i remember i just extracted that first file on the rar, not the folder, and tried to open it and got a weird error msg, that's what i recall.
i taught ESET was good, apparently not that good.
Be the casino, not the gambler




Re: Site shutdown today from .RAR virus files uploaded?

26
Actually, this is a very interesting topic.
Maybe I'm wrong, but in my very humble opinion, any compiled file ex4,
especially coming from an unknown source, can contain a code allowing
to harm or devastate in some way your account, (e.g. through redirecting, copying, etc.).
And the antiviruses will not catch this, because it wouldn't be strictly a virus.

Re: Site shutdown today from .RAR virus files uploaded?

27
chris006 wrote: Mon Jul 03, 2023 12:30 am @Jimmy
Are rar files still allowed / enabled?
See these 2 fresh posts here:

viewtopic.php?p=1295517357#p1295517357

viewtopic.php?p=1295517360#p1295517360
Good work man thank you for the heads up I'll check those two posts out:

  • One RAR file had an indicator called SBNR Arrows 2.01 NEWw.mq4
  • The other file I couldn't see any contents so those have been binned 🚮

Member Hydra has been deactivated, emailed for account reactivation and a password changed.

I am temporarily enabling RAR files on and off during the testing phase to access them and run benchmarks to check if this upload scanner will impact CPU load.

More testing to be done today but RAR files are disabled.
These users thanked the author Jimmy for the post (total 3):
Forexlearner, boytoy, Chickenspicy
Guide to the "All Averages" Filters (ADXvma, Laguerre etc.) 🆕
Use Fibonacci numbers for indicator settings + How to draw Fibonacci Extensions
An easy trick for drawing Support & Resistance

Re: Site shutdown today from .RAR virus files uploaded?

28
wojtek wrote: Mon Jul 03, 2023 12:58 am Actually, this is a very interesting topic.
Maybe I'm wrong, but in my very humble opinion, any compiled file ex4,
especially coming from an unknown source, can contain a code allowing
to harm or devastate in some way your account, (e.g. through redirecting, copying, etc.).
And the antiviruses will not catch this, because it wouldn't be strictly a virus.
i'm not an expert on this, but are you sure. Because i've downloaded for almost 1 year so many ex4 files from so many places and never had any issue. I think if that was the case the internet would be full of warnings about this. I think it's a issue with these weird rars that we can't know what's inside.
Maybe i'm also curious now, do ex4 files can be dangerous too?

In my humble opinion just avoid any packed files, zip or rar, unless you absolutely trust the ones sharing them.
These users thanked the author Forexlearner for the post:
wojtek
Be the casino, not the gambler

Re: Site shutdown today from .RAR virus files uploaded?

30
Forexlearner wrote: Mon Jul 03, 2023 2:03 am they used my forex factory acc to share the same crap there, i only now got to this type of accounts to change passwords, a bit to late apparently. :/

I have no idea what they have and what they can still do. I changed it here now, and with so many cleaning i hope this is over
Am suspended there too currently for the same reason.
These users thanked the author mrtools for the post (total 2):
Forexlearner, Chickenspicy


Who is online

Users browsing this forum: No registered users and 3 guests