CCcam 2.3.0 spyware installed

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Data7
    Top Poster
    • May 2009
    • 112

    #1

    CCcam 2.3.0 spyware installed

    CCcam 2.3.0 Spyware installed.
    Taken from another forum. (chinese dream box)
    Quelle: Cccamforum

    Zitat:
    CCCAM 2.3.0 is taking the backdoor crap even a step further.

    The lowest scum of the earth, UVADI TEAM, have done it even better this time. Making sure sharing will die for sure if they keep this crap up.

    Before I continue, I would urge people with BRAINS and PROGRAMMING SKILLS, to download IDA PRO (torrent) and decompile it for themselfs to find the ******** remotely triggered backdoor.

    How it works.

    When you install CCcam 2.3.0 , nothing special is happening at first, and cccam will check for input activity on the pc or box to make sure nobody is watching. When it finds itself comfortably alone, it will start sending your ENTIRE CCCAM.CFG info to this IP 176.9.242.159 (a rented root server in germany).
    Now I recompiled a version so I could trigger the backdoor myself, and TADA, some ******** ITALIAN dialup asswipe connected to the server I just set up , IP : 2.32.190.9. So traffic on my card started. THIS THEY CAN NOT HIDE in Cccam, it shows as a CONNECTED CLIENT from one of your clients in cccam.cfg where the dyndns has been removed (still lack of cccam, if dyndns is non-existing) the security feature doesn't work anymore and everybody can connect on that user.

    I have 2 words for UVADI TEAM -> YOU SUCK !!!!!!

    The future of CCcam is dead thanks to these low life asswipes , just after free sharing and making their own "spidernetwork" on your card.

    BLOCK ALL CLIENTS that have 2.3.0 connected to your server as it will still read all connected clients from the server, trough the client !!

    latest original CCcam 2.1.3 and 2.1.4 which are secure and don't have this backdoor code.


    ps: AGAIN , if you don't want to take the warning for granted, decompile and look for yourself !!!!!!! "

    __________________________________________________ _____________

    Test these commands with Telnet :

    netstat (will work also on dreambox, as well as PC Linux)

    tcpdump (PC Linux)
  • satsmo
    V.I.P. Member
    • Jun 2008
    • 6397

    #2
    Been cut and pasted across numerous forums over the last few days, and I have seen a few decompiles but not any posted.

    But one or two small servers I know have been hacked, (hijacked is probably a better word). CCcam doesn't need a backdoor, there are many other CAMs to avail of.
    Last edited by satsmo; 8 January, 2012, 01:08.
    I refuse to answer that question on the grounds that I don't know the answer. - Douglas Adams

    Comment

    • TheCoder
      DK Veteran
      • Jun 2011
      • 693

      #3
      lmfao !

      Come on ffs, install dodgy software from god knows where to do dodgy things and its almost inevitable it will be infested with some kinds of trojan !!!

      The description of the above sounds like a pretty basic trojan. If the coders had been half decent it would of been damn near impossible to detect.

      Comment

      • garry1312
        DK Veteran
        • Oct 2010
        • 2178

        #4
        noticed 2.2.1 was not mentioned is this ok to use?


        Rest In Peace Michael Mcharg, A true friend and although gone never forgotten. 11-10-08.

        Comment

        • mdt
          V.I.P. Member
          • Feb 2009
          • 3034

          #5
          the general train of thought has always been that anything after 2.1.04 was risky as the c**am team was dead although i always take anything i hear/read with a pinch of salt. as with anything in this game you/we all do it at our own risk. regards mdt
          DM800HDSE SIM 2.10. SSL84D OPEN-ATV ORBITAL 80CM/DARK MOTOR/IBU/53E-30W

          Comment

          • garry1312
            DK Veteran
            • Oct 2010
            • 2178

            #6
            So whats the verdict on this is CCcam 2.3.0 best to stay clear of it or is it safe as any other may be?


            Rest In Peace Michael Mcharg, A true friend and although gone never forgotten. 11-10-08.

            Comment

            • blueflash234
              DK Veteran
              • Mar 2009
              • 904

              #7
              the same story was going about with cccam 2.2.1 and 2.2.0 many people thought sly had something to do with it so they can read the cards being used i think its safer to use 2.1.4 or lower have read some servers are using 2.0.5 or try mgcamd/newcamd
              Last edited by blueflash234; 9 January, 2012, 16:56.

              Comment

              • garry1312
                DK Veteran
                • Oct 2010
                • 2178

                #8
                I use Oscam only, but more thinking about other receivers on the server, but all changed to lower than 2.3.0 now.


                Rest In Peace Michael Mcharg, A true friend and although gone never forgotten. 11-10-08.

                Comment

                • davvo
                  DK Veteran
                  • Apr 2009
                  • 666

                  #9
                  you think TS-Panel has Spyware
                  Last edited by davvo; 9 January, 2012, 20:43.

                  Comment

                  • garry1312
                    DK Veteran
                    • Oct 2010
                    • 2178

                    #10
                    Originally posted by davvo
                    you think TS-Panel has Spyware
                    No idea mate. Never seen any concern towards ts-panel.


                    Rest In Peace Michael Mcharg, A true friend and although gone never forgotten. 11-10-08.

                    Comment

                    • davvo
                      DK Veteran
                      • Apr 2009
                      • 666

                      #11
                      something like this

                      you connect to a server via your box
                      that server then has your ip

                      that server then auto issues this command

                      # wget your-dream-ip/var/etc/cccam.cfg

                      your cccam.cfg file has just been nicked
                      Last edited by davvo; 9 January, 2012, 21:19.

                      Comment

                      • garry1312
                        DK Veteran
                        • Oct 2010
                        • 2178

                        #12
                        so are you saying ts-panel is a concern?


                        Rest In Peace Michael Mcharg, A true friend and although gone never forgotten. 11-10-08.

                        Comment

                        • davvo
                          DK Veteran
                          • Apr 2009
                          • 666

                          #13
                          i always have

                          Comment

                          • satsmo
                            V.I.P. Member
                            • Jun 2008
                            • 6397

                            #14
                            TS Panel doesn't have spyware I think Davvo is using what it's intention is as a means of using it as an example when something is taken out of context.

                            If not I can get the author here to have a discussion about it.

                            Regards:

                            # wget your-dream-ip/var/etc/cccam.cfg
                            I don't know about you are any others' set up but I presume that you would change your server/client default password etc?

                            After this we can go back on topic
                            I refuse to answer that question on the grounds that I don't know the answer. - Douglas Adams

                            Comment

                            • davvo
                              DK Veteran
                              • Apr 2009
                              • 666

                              #15
                              not just TS Panel
                              but any plugin thats installed

                              also the programs that you install on your pc
                              then that program ask for your dream login details
                              netbios spring to mind

                              have you seen how many c lines google can bring in
                              thats not some bloke trying his luck with filezilla
                              Last edited by davvo; 9 January, 2012, 21:48.

                              Comment

                              Working...