Search found 237 matches

by luntrus
Wed May 12, 2010 7:53 pm
Forum: Security
Topic: Check that code here...
Replies: 0
Views: 2097

Check that code here...

Hi forum friends, This piece of malcode that I took from this report (hidden inline script outside HTML a clear no, no): http://www.unmaskparasites.com/security-report/?page=www.ninjawy.com was tested by me online here: http://testasp.acunetix.com/Search.asp?tfSearch=function+verify_passwords(passwo...
by luntrus
Tue May 11, 2010 7:24 pm
Forum: Web Tech
Topic: Scroogle Scraper service broken...
Replies: 2
Views: 4574

Scroogle Scraper service broken...

Hi forum friends, Just a coincidence? Google changed their searchpage somewhat and Scroogle Scraper service had to throw in the towel. It cannot be used any longer. The anonymous Google service scroogle is no more: http://www.scroogle.org/cgi-bin/nbbw.cgi Google changed around so the simple scroogle...
by luntrus
Fri Apr 30, 2010 7:32 pm
Forum: Security
Topic: Nice for checking...
Replies: 2
Views: 2289

Re: Nice for checking...

Hi dhouwn,

Thanks for the heads-up on this one, my friend, found and installed,

luntrus
by luntrus
Fri Apr 30, 2010 6:16 pm
Forum: Security
Topic: Nice for checking...
Replies: 2
Views: 2289

Nice for checking...

Hi forum friends, I like this extension to be aware of these obtrusive issues with javascript and inline events and have them lined out on the visited site: https://addons.mozilla.org/en-US/firefox/addon/9505 For checking up on javascript and can be used online, JSure javascript checker: http://www....
by luntrus
Tue Apr 27, 2010 8:01 pm
Forum: NoScript General
Topic: How to best handle LinkBucks threats
Replies: 3
Views: 5984

Re: How to best handle LinkBucks threats

Hi dhouwn, Should this skip functionality be added to NS then? Or would that also be controversial? This ad-related nagging is a nuisance really to most users apart from the regular parties that get paid, and also the malcreants that "hook into" these revenues. "Linkbucks Frames"...
by luntrus
Tue Apr 27, 2010 7:12 pm
Forum: NoScript General
Topic: How to best handle LinkBucks threats
Replies: 3
Views: 5984

How to best handle LinkBucks threats

Hi forum friends, Page opened up in my flock browser with latest version of NS, RP, ABP+: htxp://a1b08eb4.linkbucks.com/ Annoying and adware threat i.m.h.o. How to get fully rid of this with NS? It appeared from a site that was apparently hacked, and the redirect would now go exclusively via the Lin...
by luntrus
Mon Apr 19, 2010 11:28 am
Forum: Security
Topic: Can this be used additionally?
Replies: 6
Views: 4077

Can this be used additionally?

Hi forum friends, Are you aware of this service: http://www.sitetruth.com/yhoo.html There is also an add-on for Fx: http://www.sitetruth.com/downloads/adrater.html To be installed from: https://addons.mozilla.org/en-US/firefox/addon/45354 The service is still alpha, but it is different from WOT. I t...
by luntrus
Fri Apr 16, 2010 8:19 pm
Forum: Security
Topic: Unobfuscated Javascript Malware - How to detect - an introdu
Replies: 2
Views: 3673

Re: Unobfuscated Javascript Malware - How to detect - an int

Hi forum friends,

An example of analysis of some packed compressed code ( 100% beningn) to see what it is:
http://jsunpack.jeek.org/dec/go?report= ... 7693618115

luntrus
by luntrus
Tue Apr 13, 2010 8:31 pm
Forum: NoScript General
Topic: Is NS ready for this?
Replies: 1
Views: 1581

Is NS ready for this?

Hi forum friends,

Just stumbled upon a so-called "fun"site to turn normal urls into huge ones. It is not only fun but could also be abused maliciously.
Re: http://forum.avast.com/index.php?topic=58487.0
Does NS protect us there under all circumstances?

luntrus
by luntrus
Sun Apr 04, 2010 5:05 pm
Forum: Security
Topic: Unobfuscated Javascript Malware - How to detect - an introdu
Replies: 2
Views: 3673

Unobfuscated Javascript Malware - How to detect - an introdu

Dear forum friends and users of NS, In websites we will come across loads of obfuscated Javascript code being used by both code protectors for commercial tracking and evaluation purposes but also by malcreants to avoid detection of code they insert into reputable websites. Detecting this process sho...
by luntrus
Thu Apr 01, 2010 8:30 pm
Forum: NoScript General
Topic: NoScript prevents you get RickRolled!
Replies: 5
Views: 3965

Re: NoScript prevents you get RickRolled!

Hi Alan Baxter,

For April Fool's Day Sophos launched their RickRoll Protector: http://www.f-secure.com/weblog/archives/00001924.html

luntrus
by luntrus
Sun Mar 28, 2010 1:51 am
Forum: Security
Topic: Malware installs a malicious timer.xul
Replies: 0
Views: 3291

Malware installs a malicious timer.xul

Hi forum friends, C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content in this folder there is "timer.xul" and it is put there by "trojan:RS/Dursg.B" - mind that particular CLSID used in various malware like W32.RoutrobotWorm, Generic ...
by luntrus
Sun Mar 28, 2010 1:15 am
Forum: NoScript General
Topic: NoScript prevents you get RickRolled!
Replies: 5
Views: 3965

Re: NoScript prevents you get RickRolled!

Hi Alan Baxter,

This is the particular bug filed against this particular rickroll.swf:
https://bugzilla.redhat.com/show_bug.cgi?id=439858
The site it was on was non-malicious: http://wepawet.iseclab.org/view.php?has ... 96&type=js

luntrus
by luntrus
Sat Mar 27, 2010 10:45 pm
Forum: NoScript General
Topic: NoScript prevents you get RickRolled!
Replies: 5
Views: 3965

Re: NoScript prevents you get RickRolled!

Hi Alan Baxter, Thanks for the additional info here, so these issues have been with us quite some time now and they will not be going away either soon. Here is how they tackled the issue in GoogleChrome while getting alert 1: https://bug61098.bugzilla.mozilla.org/attachment.cgi?id=377667 And indeed ...
by luntrus
Sat Mar 27, 2010 10:01 pm
Forum: NoScript General
Topic: NoScript prevents you get RickRolled!
Replies: 5
Views: 3965

NoScript prevents you get RickRolled!

Hi users of NoScript, Another issue where we should be glad we have the additional protection of NoScript, you won't get Rickrolled when you venture out here: http:// 1227.com/ With Fx without NS you are vulnerable to this Browser exploit: JOKE/BrowserMessage or Joke.NoClose JS the endless alert pop...