Skip to content
TORNLIFE More

trojun threat

Started by Paladin [1688061] on in General Discussion.

11 replies · 366 views · thread synced · 3 days ago · View on torn.com
About this thread

Posts archived: 12 / 12 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Counted by TornLife from the archived posts.

Archived posts
12
Discussion span
→
People posting
9
Likes on archived posts
5
Authority score
50 / 100
Historical score
23 / 100
Story score
49 / 100
Engagement score
57 / 100
Paladin [1688061]

i was asked to join a faction, when i looked at the profile of the person
it downloaded a file to my pc called "city.php"

i did not click on anything to download that file
and then my computer said it detected a tojun
so i deleted the file, i don't know if thats enough to remove by simply deleting
CravenTHC [1569996]

city.php is the directory for the city page.

http://www.torn.com/city.php

However that's not a file download link, and one could conceivably disguise a file download as anything they wanted. I would suggest contacting staff about the issue so that they can investigate further.

Edit: Please don't link or post any of the profile information as it will only serve to further the spread of the threat, if one exists. Hades, if you really have to know just PM the OP.
Standishlad [28128]

Actually, this happens to me sometimes on Torn. Often I'll find I've accidentally tried to save/download the webpage I'm currently on.

You have no idea how many times City.php, item.php, index.php etc has ended up in my download bar at the bottom of the page.

I don't think it's a virus from a forced download, I think you may have fatfingers like me and often click things without meaning to.


You know, I actually don't know what shortcut or what I've clicked to cause this. Just it happens almost daily.

EDIT: This actually happens on some other websites too. I'd love to know how I'm accidentally doing this, but I don't really care enough to find out for myself.

Proof, my download list from yesterday.

[image: i.gyazo.com]

Notice the (5) and (6) on index.php. That's how many times I've saved those accidentally so far. Also I've downloaded a reddit page too.


Hades [1728299]

Every time you even look at something it comes through your browser. Some times just looking at a small thing like a flash image can infect your computer if there is malicious code behind it.
Mat-Senpai [952164]

there's a difference between requesting a web request vs a DDL

most AV block JS or any scripts which do anything directly to you as it's normally easy to spot, the idea that simply requesting a webpage would force a browser to download externally isn't something possible, as far as i'm aware
Ohadik [424017] Wiki Contributor

You've clearly never heard of "Stealth Downloads" which is one of the most common ways that major virus packages get on someone's system (aside from clicking the "Speed up my PC now" ads).

It's very possible, and very common. Most AV's detect this and block it immediately, however some wont see it til it's already on your system.