CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 949
Comments: 28
block bottom
spacer spacer

Everyone Please Uninstall your Frog Immediately
Goto page 1, 2, 3, 4, 5  Next
 
This forum is locked you cannot post, reply to or edit topics   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Blue Security [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Captgosnold

Blue Angel


Joined: May 02, 2006
Posts: 107
Location: USA
Blue Security Team F@H

PostPosted: Wed May 17, 2006 10:33 pm    Post subject: Everyone Please Uninstall your Frog Immediately
Reply with quote

If you leave our frog client running now that Blue has closed down, it can be abused by hackers to attack whatever website they like.

Back to top
View users profile Send private message
Bad_Frogger

Captain
Captain


Joined: May 12, 2006
Posts: 507
Location: Canada

PostPosted: Wed May 17, 2006 10:54 pm    Post subject:
Reply with quote

Could someone get it yoinked from CNet Downloads .com before things get worse. If that,s possible.


_________________
MS's "New Coke"
Back to top
View users profile Send private message
DangerNerd

Sergeant
Sergeant


Joined: May 04, 2006
Posts: 86
Location: USA

PostPosted: Wed May 17, 2006 11:00 pm    Post subject: Re: Everyone Please Uninstall your Frog Immediately
Reply with quote

Captgosnold wrote:
If you leave our frog client running now that Blue has closed down, it can be abused by hackers to attack whatever website they like.


Is this why so many of us have gotten letters from our ISPs saying that we were launching attacks on websites?

Was if actually a massive security flaw in the BF client?

That would explain a lot, actually.

Thanks for the heads-up!

DN.


_________________
Make CERTAIN you get into the fanclub. We will be keeping people updated until a better solution comes along.
---
http://www.bluefrogfanclub.com/
Back to top
View users profile Send private message Visit posters website
s0tet

PIRT Handler


Joined: May 21, 2005
Posts: 2840

Phishing Squad

PostPosted: Wed May 17, 2006 11:24 pm    Post subject: blue frog uninstall??
Reply with quote

I uninstalled blue frog just now, however, it still pops up in my Firefox browser as I got my web-based mail account.

Any other suggestions?
Should I try to reboot?



Last edited by s0tet on Wed May 17, 2006 11:33 pm, edited 1 time in total
Back to top
View users profile Send private message Send email
Bad_Frogger

Captain
Captain


Joined: May 12, 2006
Posts: 507
Location: Canada

PostPosted: Wed May 17, 2006 11:27 pm    Post subject:
Reply with quote

In Firefox Tools Extensions Uninstall extension.
Restart Firefox.
Should do it.


_________________
MS's "New Coke"
Back to top
View users profile Send private message
s0tet

PIRT Handler


Joined: May 21, 2005
Posts: 2840

Phishing Squad

PostPosted: Wed May 17, 2006 11:34 pm    Post subject:
Reply with quote

thanks for the quick help, that worked.

Back to top
View users profile Send private message Send email
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Wed May 17, 2006 11:40 pm    Post subject:
Reply with quote

Although not critical, don't forget to uninstall the T'Bird one as well.

Back to top
View users profile Send private message
stanjnz

Trooper
Trooper


Joined: Apr 10, 2006
Posts: 13


PostPosted: Wed May 17, 2006 11:49 pm    Post subject:
Reply with quote

s0tet wrote:
thanks for the quick help, that worked.


Yes, but I used a 3-step method, thus:
1 Uninstall via Firefox Tools as above
2 Untick the Enable box for BF in Mailwasher
3 Uninstall BF via Programs in Windows XP

This removed all icons etc to do with Blue Frog & got rid of its column in Mailwasher.


_________________
From Ole Stan in Kiwiland.

"Man will always stoop to commit any folly of which he is capable." - Bertrand Russell
Back to top
View users profile Send private message
DangerNerd

Sergeant
Sergeant


Joined: May 04, 2006
Posts: 86
Location: USA

PostPosted: Wed May 17, 2006 11:53 pm    Post subject:
Reply with quote

PCBruiser wrote:
Although not critical, don't forget to uninstall the T'Bird one as well.


As well as the experimental IE reporting tool. That's all IE needs is another security hole. Wink


_________________
Make CERTAIN you get into the fanclub. We will be keeping people updated until a better solution comes along.
---
http://www.bluefrogfanclub.com/
Back to top
View users profile Send private message Visit posters website
VikingBlade

Trooper
Trooper


Joined: Aug 02, 2004
Posts: 16
Location: USA

PostPosted: Thu May 18, 2006 12:19 am    Post subject:
Reply with quote

Isn't the only way that could happen would be if Blue Security domain expired (2010), and got picked up by someone else?

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2765

Premium

PostPosted: Thu May 18, 2006 12:43 am    Post subject:
Reply with quote

Is there any reason when I log off my desktop and then on again (XP/SP2) my computer repeatedly tries to configure Microsoft MySQL server (which it can't do for whatever reason)?

Back to top
View users profile Send private message
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2897

Blue Security Premium

PostPosted: Thu May 18, 2006 12:52 am    Post subject:
Reply with quote

LOL!

This is not the opportune time to make wild assumptions about the security of DNS systems.

I will not enumerate the ways that this could be implemented, as I feel sure that it is already in train. The attackers are working on that.

Remove the Blue Frog, all extension/plug-ins, firewall permissions for it, and do it now. (Sorry to be so authoritarian, but it has to be said). Too many people who read the attackers' plans in advance, thought they were too stupid to be able to carry them out. A summary of their original announced attack plan -

1. Gain access to over 70% of the DNIR (done)

2. Mount a massive 20-fold spam attack increase on Blue Security members (done)

3. Shut down the Blue Security primary site with a massive DDOS attack (done)

4. Shut down all the other Blue Security sites the same way (done)

5. Subvert the Blue Frog application itself and make it launch spam and DDOS attacks. (in progress)

We have seen 1-4 completed. Stopping step 5 depends on YOU.

REMOVE THE BLUE FROG APPLICATION AND REMOVE IT NOW.

(Sorry I shouted)

Terry



Last edited by tembow on Thu May 18, 2006 2:27 am, edited 2 times in total
Back to top
View users profile Send private message Visit posters website AIM Address
stanjnz

Trooper
Trooper


Joined: Apr 10, 2006
Posts: 13


PostPosted: Thu May 18, 2006 1:07 am    Post subject:
Reply with quote

tembow wrote:


Remove the Blue Frog, all extension/plug-ins, firewall permissions for it, and do it now.
Terry


Thank you Terry for reminding me about the firewall permissions. In Norton, this helps to remove all references to the application.

Kiwis of the world unite, you have nothing to lose but your spammers.


_________________
From Ole Stan in Kiwiland.

"Man will always stoop to commit any folly of which he is capable." - Bertrand Russell
Back to top
View users profile Send private message
Tapper62

Sergeant
Sergeant
Premium Member

Joined: May 08, 2006
Posts: 125
Location: USA
Premium

PostPosted: Thu May 18, 2006 1:42 am    Post subject:
Reply with quote

Yes, thank you very much Tembow for posting that helpful reminder for everyone to remove our once proud Frogs to avoid hackers revenge as i too had forgotten to remove permission in my own firewall for Freddie which could have been tragic Sad

Back to top
View users profile Send private message
Guest

Guest
IP: 68.210.*.*






PostPosted: Thu May 18, 2006 3:16 am    Post subject: Don't forget the tagline in your email signature
Reply with quote

I had the tagline in my email signature to promote BF. I had to remove that manually (Hotmail).

Back to top
Display posts from previous:   
This forum is locked you cannot post, reply to or edit topics   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Blue Security All times are GMT
Goto page 1, 2, 3, 4, 5  Next
Page 1 of 5

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer