Reply
Thread Tools
Posts: 73 | Thanked: 141 times | Joined on Oct 2010
#1
Guys, I wanna to warn to a possibility invasion of a troll and lamer

He tells you that you have produced an amazig application but this only a script for delete ALL from your phone and SD!

He infested an italian forum LINK whit a .deb attachement

He wrote in all the section of forum hoping someone will fall into his trap

In the italian forum his name is BELTAMAN TEAM
 

The Following 38 Users Say Thank You to Veleno For This Useful Post:
tzsm98's Avatar
Posts: 500 | Thanked: 437 times | Joined on Nov 2009 @ Oklahoma
#2
Originally Posted by Veleno View Post
Guys, I wanna to warn to a possibility invasion of a troll and lamer

He tells you that you have produced an amazig application but this only a script for delete ALL from your phone and SD!

He infested an italian forum LINK whit a .deb attachement

He wrote in all the section of forum hoping someone will fall into his trap

In the italian forum his name is BELTAMAN TEAM
Here is his post. (minus link to script which appears to have been removed and the user BANNED!)



Ciao tutti, prima volta che vi scrive prego scusa per italiano poco saporito. Abbiamo creato piccolo script saporito che vi sarà molto buono a fare un po di pulizia con files temp di Maemo. Esatta mente, script Beltazor esegui un Clean di lista pacchetti, un refix di dipendenze, un update di libreria per anteprime di thumb e cancellando tutti i files temporanei con solo click. Per utilizzare beltazor dovete essere in rete, prende anche un update della lista pacchetti. Beltazor, contiene righe di codice che, oltre ad eseguire chiacchierato prima, installa nel N900 un driver Video per fotocamera frontale specchio (lrende piu veloce), installa sufinestra di applicazione fotocamera (soli su applicazione Fotocamera) opzione (link dinamico bin) di cattura video (verso gstreamer) o foto direttamente con fotocamera specchio! Bello news vero popoli? Driver di cattura fotocamera anteriore, essendo ottimizzato by the Beltaman.uk team, puo di catturare e registrare ottima qualità fluide direttamente da fotocamera di frontale. In attesa di pubblicare video saporito, concedere deb in allegato. Be sure connessi con internet e pazientare che n900 riavvia piano piano di potere poi usufruire per Beltazor Application e funzioni piu addizionate di applicazione Fotocamera! Ciao, buon anno tutti felice dal team di Beltaman.uk

Scusate se usa nostro Italiano poco pulito presto novo aggionamenti tante piu bellissime novità! Vostro è sito SAPORITO!


Google translate sez:

Hello all, first time you write please excuse for a little Italian flavor. We have created tasty little script that will be very good at doing some cleanup of temp files with Maemo. Exact mind, run a script Beltazor Clean list of packages, a refix of dependencies, update the library for a preview of thumb and delete all temporary files with one click. To use beltazor must be online, also take a list of update packages. Beltazor contains lines of code that not only talked the first run, get a video driver for N900 in the front camera mirror (lrende faster), get the application sufinestra camera (only on camera application) option (dynamic link bin) video capture (to gstreamer) or photos directly to the camera mirror! Bello real news people? Front camera capture driver, being optimized by the Beltaman.uk team can capture and record high quality fluid directly from the camera front. Waiting to publish video tasty grant deb attached. Be sure the Internet and related patient n900 power then restart slowly to enjoy Beltazor Application and add more functions to the camera application! Hello, happy new year all the teams Beltaman.uk

Sorry if you use our neat little Italian soon novo Update on many more wonderful news! Your site is TASTY!

I put this up because if you see the same style of post you'll know to be careful.
__________________
A Thing of Beauty Is a Joy Forever
 

The Following 14 Users Say Thank You to tzsm98 For This Useful Post:
Posts: 2,225 | Thanked: 3,822 times | Joined on Jun 2010 @ Florida
#3
Kinky. Notice how he says you must make sure you have internet? Anyone wanna bet something maliciously deleting your data isn't simultaneously sending it online somewhere?

(If I was a risk taker I'd run Backupmenu on my entire device, save those backup archive files elsewhere off-device, plug it up to a WiFi access point which fakes internet throughput, and then run the distributed file through strace. Then put the backup archives and a kernel image back on the device, reflash kernel, and unpack all the backups. That way if the son-of-a-***** deletes everything, the backups hopefully restore it all. I actually like my N900 too much to do that, but still. Someone willing to reflash probably could make it happen.)

At any rate, thanks for the warning.
 

The Following 3 Users Say Thank You to Mentalist Traceur For This Useful Post:
Posts: 73 | Thanked: 141 times | Joined on Oct 2010
#4
No, i've controlled the .deb and it content only a script whit a series of "rm -r" (sh command to remove a folder)
 

The Following 6 Users Say Thank You to Veleno For This Useful Post:
F2thaK's Avatar
Posts: 4,365 | Thanked: 2,467 times | Joined on Jan 2010 @ Australia Mate
#5
what a dog... thanks a lot for the info.

reminder to think twice before installing a deb from a new user....
 

The Following 5 Users Say Thank You to F2thaK For This Useful Post:
Posts: 2,225 | Thanked: 3,822 times | Joined on Jun 2010 @ Florida
#6
Lol. Yet another moral that closed-source binaries are bad, and need to be handled with caution.

At any rate, any chance you could give an overview of how you ran the .deb in a controlled manner? Or just point me to a link or something - I'm happy learning on my own if I know at least vaguely what direction to head in.
 

The Following 4 Users Say Thank You to Mentalist Traceur For This Useful Post:
ysss's Avatar
Posts: 4,384 | Thanked: 5,524 times | Joined on Jul 2007 @ ˙ǝɹǝɥʍou
#7
That's not a troll.
A Trojan or malware would better describe this $#!+>|^.
__________________
Class .. : Power User
Humor .. : [#####-----] | Alignment: Pragmatist
Patience : [###-------] | Weapon(s): Galaxy Note + BB Bold Touch 9900
Agro ... : [###-------] | Relic(s) : iPhone 4S, Atrix, Milestone, N900, N800, N95, HTC G1, Treos, Zauri, BB 9000, BB 9700, etc

Follow the MeeGo Coding Competition!
 

The Following 6 Users Say Thank You to ysss For This Useful Post:
Guest | Posts: n/a | Thanked: 0 times | Joined on
#8
Makes you wonder how many other times this has happened.
 

The Following 3 Users Say Thank You to For This Useful Post:
Posts: 388 | Thanked: 842 times | Joined on Sep 2009 @ Finland
#9
Originally Posted by Mentalist Traceur View Post
At any rate, any chance you could give an overview of how you ran the .deb in a controlled manner?
It's possible to investigate without installing/running with:

Code:
dpkg -x <package> <dir>
to extract the files in the package

Code:
dpkg -e <package>
to extract the scripty parts

It won't help you see inside binary files, though.
 

The Following 9 Users Say Thank You to hqh For This Useful Post:
stickymick's Avatar
Posts: 1,079 | Thanked: 1,019 times | Joined on Mar 2010
#10
Thanks for the heads up Veleno.

Hate to think how many have already fallen foul of this.
 

The Following 2 Users Say Thank You to stickymick For This Useful Post:
Reply


 
Forum Jump


All times are GMT. The time now is 17:08.