Stopping Redirect Ads

Ask for help about NoScript, no registration needed to post
myBad

Re: Stopping Redirect Ads

Post by myBad »

...or not :?

I just had a redirect @ BTJunkie(I've got google-analytics blocked there)...
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.10) Gecko/2009042316 Firefox/3.0.10
Tom T.
Field Marshal
Posts: 3620
Joined: Fri Mar 20, 2009 6:58 am

Re: Stopping Redirect Ads

Post by Tom T. »

myBad wrote:...or not :?

I just had a redirect @ BTJunkie(I've got google-analytics blocked there)...
Assume we're referring to btjunkie.org? I just went there. Script allowed. No redirect. Tried clicking a random page. No redirect. If it was an internal page, please provide exact URL.

I should also mention that Adblock Original shows two blocked subdocument iFrames, both from bluelithium.com, an ad server. This was also true at a related post that I just marked "resolved". (Warning: @dult site.)

I like Adblock Original -- it blocks all that stuff by default, with no user action. I use it all the time. You might try it and see if it helps.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US at an expert level; rv:1.8.1.20) Gecko/20081217 Firefox/2.0.0.20 diehard
User avatar
AlphaCentauri
Posts: 13
Joined: Fri Mar 27, 2009 12:09 am
Contact:

Re: Stopping Redirect Ads

Post by AlphaCentauri »

Tom T. wrote:
AlphaCentauri wrote:...I'd love to know who downloaded the malware in the first place and from where (shared work computer),
Why are you going to all those sites on the company's computer and time? :P
lol, I haven't seen anyone doing personal websurfing there, but since the computer is on a desk used by a part time employee and is the closest computer to the break room and the time clock, it's quite possible they were doing it on their breaks. There are so many innocent sites hacked, it wasn't necessarily anything more suspicious than checking to see when their kids have early dismissal from school to request time off.

But I sure would have liked to have seen the browser history! :evil:
Mozilla/5.0 (Windows; U; Windows NT 5.1; rv:1.9.1b3pre) Gecko/20090223 SeaMonkey/2.0a3
myBad

Re: Stopping Redirect Ads

Post by myBad »

Tom T. wrote: Assume we're referring to btjunkie.org? I just went there. Script allowed. No redirect. Tried clicking a random page. No redirect. If it was an internal page, please provide exact URL.

I should also mention that Adblock Original shows two blocked subdocument iFrames, both from bluelithium.com, an ad server. This was also true at a related post that I just marked "resolved". (Warning: @dult site.)

I like Adblock Original -- it blocks all that stuff by default, with no user action. I use it all the time. You might try it and see if it helps.
The btjunkie redirects occur shortly after performing a search. The query of the search has been irrelevant in my experiences.

I'll give AdBlock Original a try and let you know the results later.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.10) Gecko/2009042316 Firefox/3.0.10
Tom T.
Field Marshal
Posts: 3620
Joined: Fri Mar 20, 2009 6:58 am

Re: Stopping Redirect Ads

Post by Tom T. »

myBad wrote:...The btjunkie redirects occur shortly after performing a search. The query of the search has been irrelevant in my experiences....
I allowed "everything" on the page in NS, disabled Adblock, disabled Fx pop-up blocker, did several searches, and still couldn't reproduce.

Only remaining possibilities that I can think of:
1) Fx Image blocking, but neither bluelithium nor adbrite were in that list;
2) It only happens in F3 (I run F2, earning permanent scorn from "certain other" team members, but ya'd be surprised how much stuff like this only runs in F3);
3) Malware.

Yet the issue was fixed at the other sites, correct? (block Meta redirect). So BT is doing something different. Will be interesting to see if the Adblock of the subdocument iFrames has any effect.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US at an expert level; rv:1.8.1.20) Gecko/20081217 Firefox/2.0.0.20 diehard
Tom T.
Field Marshal
Posts: 3620
Joined: Fri Mar 20, 2009 6:58 am

Re: Stopping Redirect Ads

Post by Tom T. »

AlphaCentauri wrote:
Tom T. wrote: Why are you going to all those sites on the company's computer and time? :P
lol, I haven't seen anyone doing personal websurfing there, but since the computer is on a desk used by a part time employee and is the closest computer to the break room and the time clock, it's quite possible they were doing it on their breaks. There are so many innocent sites hacked, it wasn't necessarily anything more suspicious than checking to see when their kids have early dismissal from school to request time off.

But I sure would have liked to have seen the browser history! :evil:
Sounds like a Sysadmin Group Policy problem to me! (and don't all kids today have cell phones and text messaging anyway? lol)
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US at an expert level; rv:1.8.1.20) Gecko/20081217 Firefox/2.0.0.20 diehard
myBad

Re: Stopping Redirect Ads

Post by myBad »

I just got a redirect to the "Terminator Salvation Screensaver" again by trying to view a video on DailyMotion...and even a pop-up(?!) from visiting Yahoo(?!?!) for that same damn video hosted on Metacafe.

I'm unable to find Adblock Original. I guess Mozilla took it off of their site.

It's obvious malware. At this point, I think I'm just going to wipe the disk.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.10) Gecko/2009042316 Firefox/3.0.10
User avatar
therube
Ambassador
Posts: 7929
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: Stopping Redirect Ads

Post by therube »

Yes, I understood your comment on JavaScript as relating to Adobe Acrobat.
Be aware, your Acrobat needs updating. Exploits exist against it.

And while you're at it, how about Flash & Java? Are they current - the most recent versions. If not, you're leaving yourself open there too.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1pre) Gecko/20090525 SeaMonkey/2.0b1pre
Tom T.
Field Marshal
Posts: 3620
Joined: Fri Mar 20, 2009 6:58 am

Re: Stopping Redirect Ads

Post by Tom T. »

myBad wrote:I'm unable to find Adblock Original. I guess Mozilla took it off of their site.
http://adblock.mozdev.org/
It's obvious malware. At this point, I think I'm just going to wipe the disk.
It's worth a try before wiping the disk. Or after. GL.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US at an expert level; rv:1.8.1.20) Gecko/20081217 Firefox/2.0.0.20 diehard
Post Reply