Help - Search - Members - Calendar
Full Version: Vitalsecurity resigns from ASAP
B.I.S.S. Forums > Bluetack Forums > Global News
paperghost
A formal announcement that, as of this moment, I formally resign my site from ASAP and I also resign from ASAP as a member.

Spywareinfo.com chose to absolutely slaughter my website without apparently bothering to check the facts first, and has caused me a huge amount of grief in doing so.

Despite posting about this on the Spywareinfo forum and also addressing this in the Admin section of this site, no reply was forthcoming.

The newsletter was eventually pulled for a short while, only to come back with the following addition:

QUOTE
Update

It has come to my attention that several people have sent hate mail to the authors of the articles linked below. Don't do that. That is foolish. If you are going to disagree with the writer(s), do it politely. Save the hate mail for people who write spam and spyware.


Absolutely unbelievable, not acceptable and a total disgrace.

Since when did ASAP allow member sites to attack each other in such a fashion?

My site was accused of "libelous" remarks, when in actual fact the only libel appears to be coming from Spywareinfo.com.

I cannot allow my site to be totally dragged through the mud unchecked, and be expected to pretend nothing has happened. And I certainly cannot keep my site on the same listing as the site that caused this mess.

If you'd like more information on this - the original article:

http://www.vitalsecurity.org/2005/03/firef...infects-ie.html

The newsletter:

http://www.spywareinfo.com/newsletter/arch.../2005/mar13.php

The forum entry at Spywareinfo:

http://forums.spywareinfo.com/index.php?showtopic=43194

My response on Vitalsecurity:

http://www.vitalsecurity.org/2005/03/spywa...alsecurity.html

I'm still waiting for some response, though at present nothing is forthcoming. I waited over a whole day for a reply - more than adequete for someone to get back to me. If I'm expected to simply lie down and die over this, you're very much mistaken and I'm considering taking this further.

Outrageous.

As of this moment, I am no longer a member of ASAP and will remain so until I recieve a proper apology, or Spywareinfo.com is removed from ASAP. And as neither of those is likely to happen, I will happily remain a voice in the wilderness.

Paperghost

Vitalsecurity.org

http://forums.maddoktor2.com/index.php?showtopic=3428
paperghost
im in the "just plain dumb" section of mike healans weblog!

man, this sucks :\
Moore
Very disappointing newsletter to say the least..

From what I see so far the linking of your site in that newsletter is basically saying the comments by Mike Healan are aimed at you and your article , I cant see how anyone could think otherwise..

As always you have our full support.
paperghost
Thanks, its appreciated smile.gif

From the looks of it that newsletter has gone down like a lead balloon all round.
Moore
I would hope Mike is honest enough with himself to at least clear up the confusion his newsletter causes and attempt to correct the misleading information , instead of just sweeping it all under the rug like I think will be the case.
paperghost
QUOTE (Moore @ Mar 14 2005, 10:05 PM)
I would hope Mike is honest enough with himself to at least clear up the confusion his newsletter causes and attempt to correct the misleading information , instead of just sweeping it all under the rug like I think will be the case.

im not sure theres any way to sweep this one under, though it just makes me laugh that i had to resign from ASAP to get this noticed - all ive had since yesterday from SWI was a wall of silence.

however looks like that wall is now doing me a favour with every passing second - and he really should be more careful who he attempts to tread on in future. Not everyone squashes so easily!

It'll be so interesting to actually hear what he has to say about all this.
Moore
Well he could choose to just ignore it altogether , but I dont see how that could last for too long , I'm sure Mikey could tell you about a few of his experiences when trying to get any kind of response.

QUOTE
It'll be so interesting to actually hear what he has to say about all this.


Yes, I'll be very interested to hear his explanation on why he chose to target you and your article for his attack, as I'm sure you definitely are.

I hope that you do get a proper explanation , and an apology with that explanation.

In my opinion your articles are always well researched and honest , and definitely informative.
paperghost
Thanks smile.gif

I'll keep you posted wink.gif
paperghost
hes online now...let us see where this goes...
paperghost
my god - cnm just posted in the SWI thread with the lamest damn thing i ever saw.

what the hell is going on?!?

This will get worse before it gets better.
firstaid
Hey, paperghost

I read your report before all this happened and I liked your work.

The most important part is that this message get out to peeps so they know what to do when the time comes. wink.gif My first thoughts were why do I even install java, but thats what I say about windows as well. laugh.gif

keep up the good work


firstaid
paperghost
Thanks smile.gif
pruttel
Hi paperghost,

just to say good research, nice catch, whatever those 'ignorant' ppl say ...

pruttel smile.gif
paperghost
Thanks Pruttel smile.gif the longer they leave it without responding, the worse it looks for them.

hes already damaged the name of spywareinfo forever imho.
Moore
Well I sent off an email to this guy , asking him to do some research before mindlessly reproducing other peoples garbage , and his comments equally dissapointing and baseless.


The text in BOLD are the comments added by Ken Harthun , who didnt bother to do any other research of his own or comprehend the full article at Vitalsecurity. :

QUOTE
False Claims Of Firefox Spyware Epidemic
03.14.2005 @ 09:12 PM PT | Ken Harthun | Comment | Send to Friends | Google It

http://channels.lockergnome.com/windows/ar..._epidemic.phtml

An article in the latest Spyware Weekly newsletter has a headline that screams “Epidemic Of Firefox Spyware Infecting Computers Worldwide!” It certainly got my attention. I read on to find that some publications (Alternative browser spyware infects IE, Firefox Spyware infects IE?) are claiming that a Java-based malware installer is a Firefox flaw that causes infections in IE.

Sometimes I just want to bang my head on the desk and keep doing it until the desk surrenders unconditionally. If you were to believe several online news sites, there is an epidemic of spyware infecting Internet Explorer by way of Firefox. If you were also to believe that these accounts were written by competant journalists who have checked their facts, you would be wrong on both counts.


Sometimes I wonder if some journalists who write tech-related material even know anything about the technology. I don't expect them to be engineers, but, hey, a basic understanding of how things work should be a requirement. At any rate, here is the real download on the issue:

Sometimes I wonder why people try to pass themselves off as having any journalistic abilities at all - Moore

The Java applet causing the current ruckus installs a number of spyware and adware programs. However, before it can do that, a security prompt pops up. The pop-up is labeled "Warning - Security". It warns that the "Publisher authenticity can not be verified", that "the security certficate was issued by a company that is not trusted" and that "the security certificate has expired or is not yet valid". Under no circumstance does this rogue Java applet install software without the user giving it permission to do that. And to be honest, you'd have to be pretty dense to click "Yes" to such a prompt arriving out of nowhere.


This situation will affect ANY browser that uses Java--which is all of them, not just Firefox--so the claims that IE is being infected by Firefox are untrue. Spyware Weekly's James Healan sets the record straight, and I agree with him:

My frustration with this is that people are calling it a problem with Firefox. That is patently untrue. Every single browser is going to pop up a similar warning when it encounters this particular Java applet. If this had been labeled a problem with all web browsers, it still would be untrue, but at least it would not slander a particular browser. The people publishing this libelous nonsense should be ashamed of themselves and should print a prominent correction.


rolleyes.gif and so it continues.. blink.gif


Mike said it best , too bad he doesnt believe in his own words..

QUOTE
The people publishing this libelous nonsense should be ashamed of themselves and should print a prominent correction


I can think of two people who should now be printing corrections to their misleading information and being ashamed of themselves .. and Paperghost is not one of them .
paperghost
apparently his REAL name is James - though at present it appears to be mud.

though he's more of a ghost than i am!
Moore
Ah ok , so he was right in the name but wrong on everything else. biggrin.gif

I guess Mike|James is either to busy to even comment or hoping if he ignores it all it will go away sometime in the future.
paperghost
in about 500 years maybe wink.gif

he'll find out im in this for the long haul. just made a nice addition to my last post over at swi too wink.gif
Kimberly
Hi paperghost,

If people are to lazy or just flash on headlines without reading the whole article before making comments, they shouldn't even write a comment.

Keep up the excellent work you always provide.

Kim
paperghost
Thank you smile.gif

God, I love it round here - nobody shouts at me wink.gif
doggfather
LO PAPERGHOST! I'LL SHOUT TO YOU!

Just kidding biggrin.gif

Keep up the good work, sorry great work.......don't pay attention to people more than they deserve. Let them understand their fault, if that happens, and if they admit it, and if they read it again from the first word until the last without skipping lines, paragraphs, if they understand what it says, and if........well just do what you're good at. The fame comes from what everyone does so do what you're good at and you'll receive respect. wink.gif
Moore
Ok , well at least Ken had the decency to reply to my email , and I thank him for being honest , regardless of the true facts contained in the article.

QUOTE
Re: [Lockergnome's Windows Fanatics] False Claims Of Firefox Spyware Epidemic

Thanks for your feedback. I object to the headline "Firefox Spyware Infects IE?" as it would bias most people immediately, regardless of the facts. I suspect that most persons would not get past the first paragraph, which is also slanted.

Ken 
Moore
Ok , since Mike Healan has disgracefully failed to take any notice of his mistake or address his misleading information , here are the main links so people can see for themselves what has happened..

The initial discussion of a possible browser vulnerability at Tom Coyotes excellent forum :
http://forums.tomcoyote.org/index.php?showtopic=31385

Paperghosts article in question which is the target of the spyware info newsletter:
http://www.vitalsecurity.org/2005/03/firef...infects-ie.html

The same artice also mentioned by the Register:
http://www.theregister.co.uk/2005/03/11/al...tive_slimeware/

The ridiculous and misleading blog / newsletter entry drawing wild conclusions from out of nowhere and linking to paperghosts article :
Epidemic Of Firefox Spyware Infecting Computers Worldwide!
http://www.spywareinfo.com/newsletter/arch.../2005/mar13.php

The fallout from the ridiculous newsletter penned by Mike Healan - Spyware Info [ members only] :
http://forums.spywareinfo.com/index.php?showtopic=43194
Moore
Now even Sponge is picking up on Mike Healans blatantly misleading newlsetter entry :

http://www.geocities.com/yosponge/blockips.txt

QUOTE
Important Note: According to Mike Healan of Spywareinfo.com (http://www.spywareinfo.com/newsletter/archives/2005/mar13.php), there is a new dropper (installer) of spyware out that installs via Sun's Java Runtime Environment (JRE), which comes with and is by default enabled in nearly all browsers, and can also be installed separately. As Mike correctly points out  , this is being falsely attributed to a "flaw" in the Firefox browser. IT IS NOT! All modern browsers enable Java by default.


Where will this end ? rolleyes.gif



Good to see Ken has realised that the Spyware Info Newsletter was misleading and has issued an apology for his comments:

http://channels.lockergnome.com/windows/ar...revisited.phtml
paperghost
Interestingly many security researchers and journalists are now agreeing with me. There are many more articles out there like this appearing now, which in my opinion validates absolutely everything i said 100%.

http://www.edbott.com/weblog/archives/000562.html

for a rundown on the windows install

and

http://www.edbott.com/weblog/archives/000568.html

for a look at the general hysteria that greeted the intial exploration of the install.
Tozzano
From Sans.Org - March 15th - Handler on Duty: Dan Goldberg
Updated March 16th 2005 03:16 UTC

http://isc.sans.org/diary.php?date=2005-03-15

QUOTE
Alternative browser java exploit
Lastly for now there is now a cross browser exploit for Mozilla browsers. It is written up in the register. The affected page calls a java applet which looks like it is signed with a bogus code signing cert that expired in February. If you click yes the applet launches IE and installs a bunch of spyware nasties.
As far as I can tell it does not penetrate the sandbox directly since user intervention is required, though I could be wrong. The article is here: http://www.theregister.co.uk/2005/03/11/al...tive_slimeware/ This is yet another thing for users to look out for, my opinion is that we will see more if this type of cross browser exploit in the future, and that we will start to see it for malware instead of spyware.
paperghost
cool, on sans twice in 12 months smile.gif

i saw this and i couldnt resist stepping into the lions den - im curious to see if i can clear up misconceptions in the firefox "community" about the original article:

http://www.spreadfirefox.com/?q=node/view/12886

also interesting to see the SWI thread rumbling on..!
Moore
I wonder how many of those replying in the firefox thread are capabale of even understanding the facts. Oh you said something about firefox and it didnt include that its the greatest thing since sliced bread... you must now die !! lol..
paperghost
lol yeah - the best one was that my article was "disgraceful" because i only had 77 members on the forum(!)

ive actually had a lot of email from "regular" ff users thanking me for pointing out that they shouldnt click java applets under the notion that FF makes them "safe". more than anything else, thats the only vindication i need smile.gif

Also - a little off topic - what is this?

CODE
http://www.risorse.net/vai.asp?url=www.vitalsecurity.org/2005/03/firefox-spyware-infects-ie.html



its my site, but stuck in a frame or something. any reason why they would do that?
Moore
QUOTE
Also - a little off topic - what is this?
CODE
http://www.risorse.net/vai.asp?url=www.vitalsecurity.org/2005/03/firefox-spyware-infects-ie.html


its my site, but stuck in a frame or something. any reason why they would do that?


?? thats weird .. I guess a simple link to your sites article wasnt enough for those guys .. ph34r.gif
paperghost
im sure there was a site that did something similar with grinlers place - he wasnt too happy either, though i cant remember the reason why.

gaaaah......my poor brain....
Tozzano
Hi paperghost,

I hope the furor has subsided and that people of good sense can see the common goal again.

Have you rejoined the ASAP team? Did they offer input and support during this episode? tongue.gif

Just curious.

Mike
paperghost
Well, as im sure you can appreciate, i cant go into details with regards what ASAP attempted internally.

however, what i CAN say (which is no great surprise) is that Mike Healan never got back to me at all. The silence speaks louder than words in this case - especially as its since transpired that the lyricspy site that caused all the fuss actually WAS trying to serve up an .xpi that, if loaded into firefox, infected IE with the xxx toolbar.

so the one resort that people had against the article - the title - was effectively sliced and diced, because the answer was an emphatic "yes".

wink.gif

As for ASAP, I've rejoined and that should hopefully be the end of it.

The interesting thing will be whats in SWI's next newsletter. i think it'd be commercial suicide to send out another rant (espcially in light of the firefox .xpi), so we'll have to wait and see.

Whats interesting is that the SWI newsletter has now apparently caused a fallout in the firefox community and they're the ones who arent too happy about what he said. Quite an interesting twist there!

I feel totally and utterly vindicated at this point - its been a long, hard battle but i'd like to think the integrity of my site and what it stands for is intact smile.gif

Thanks for the support you guys have shown smile.gif
Setsune
Heh, I don't allow downloading by websites, and with Javascript only able to change images in Firefox (by my own settings), it was funny going to the lyricspy site and having absolutely NOTHING happen on my end smile.gif

I was aware of this possible "hijack" awhile ago via Secunia advisories. I believe Firefox 1.02 fixes this vulnerability does it not?

As for all of the other mess, well, you know how people can get when their ego is more important than the facts. I happen to value your contributions to the community at large paperghost. Keep up the good work.
paperghost
Thanks smile.gif

With regards the secunia vulnerability, did you mean this one:

http://secunia.com/advisories/13271/

As far as i know, the newest version of FF was for some really obscure exploit that hadn't been used in the wild yet - though i need to do some more digging on this, as im curious to know exactly what the new version fixed. the update page on mozilla is strangely cagey in actually saying what the problem was.

Ah well, time to dl the newest version and test it out wink.gif

/ EDIT - apparently the vulnerability they fixed was to do with buffer overruns caused by coding to do with animated gifs.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2012 Invision Power Services, Inc.