Pwned by [porn link deleted]
-
- Posts: 4
- Joined: Wed Feb 16, 2011 1:34 am
Pwned by [porn link deleted]
I looked up "googlehammer" on Google and clicked on the hit for http:/www.googlehammer.com/ and NoScript failed to stop the JS there from executing, rendering FF unusable. I had to kill it a couple times from Task Manager before I could get a "recover session" window that let me disable that site's tab from reloading. (I didn't want to lose my other tabs from the session.)
Here's a direct link to the JS:
http:/www.googlehammer.com/main.js
Here's a direct link to the JS:
http:/www.googlehammer.com/main.js
Last edited by Alan Baxter on Wed Feb 16, 2011 2:14 am, edited 2 times in total.
Reason: clickable links to porn disabled
Reason: clickable links to porn disabled
Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13 (.NET CLR 3.5.30729)
-
- Ambassador
- Posts: 1586
- Joined: Fri Mar 20, 2009 4:47 am
- Location: Colorado, USA
Re: Pwned by [porn link deleted]
The site's scripts do not execute unless googlehammer.com is allowed. Make sure you uncheck
NoScript Options > General > Temporarily allow top-level sites by default
By the way, please don't post any more clickable links to malicious web sites.
NoScript Options > General > Temporarily allow top-level sites by default
By the way, please don't post any more clickable links to malicious web sites.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
-
- Posts: 4
- Joined: Wed Feb 16, 2011 1:34 am
Re: Pwned by [porn link deleted]
It's not checked, and that site isn't in the whitelist. Hence I don't understand why it ran.
Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13 (.NET CLR 3.5.30729)
-
- Ambassador
- Posts: 1586
- Joined: Fri Mar 20, 2009 4:47 am
- Location: Colorado, USA
Re: Pwned by [porn link deleted]
Neither do I. The site did not run for me with NoScript's default settings until I allowed googlehammer.com. (And allowed the other sites on the page too, but I don't know if the other sites were necessary.)
Export your whitelist and/or your NoScript settings -- for safekeeping -- and reset the NoScript Options.
By the way, I'm running these tests with Firefox inside Sandboxie so any malicious scripts can't damage my system.
Export your whitelist and/or your NoScript settings -- for safekeeping -- and reset the NoScript Options.
By the way, I'm running these tests with Firefox inside Sandboxie so any malicious scripts can't damage my system.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
- GµårÐïåñ
- Lieutenant Colonel
- Posts: 3369
- Joined: Fri Mar 20, 2009 5:19 am
- Location: PST - USA
- Contact:
Re: Pwned by [porn link deleted]
I have confirmed what Alan has said and when visiting the site, it doesn't run squat unless allowed, so not sure where you are opening yourself up but its not the default behavior. Take a closer look and if you still feel its something that needs to be looked into, we'll take another crack at it (no pun intended).
BTW, for me the first thing and only thing I see is this:
BTW, for me the first thing and only thing I see is this:
I see three items in the NoScript menu:Loading Marketing Plugin.
Google Hammer is your marketing resource for the right way to thrust yourself into Internet Marketing. After you experience the thrill of marketing the Google Hammer way, you'll wonder how you ever managed without it.
Is it possible you are allowing one of these and that's where its finding a backdoor into your profile? Otherwise, I see no way that NoScript is at fault here and allowing anything. Furthermore, since it seems to be trying to launch and install a plugin, you might have already allowed that and that's how its bypassing it, check your plugin list. And unlike my dedicated colleague here, I ran it on my main system with no precautions (except for NoScript, RequestPolicy (which wasn't needed) and Adblock Plus (for a bit more fine tuning)), so it clearly shows the application is doing its job (confirmed on a profile with NS ONLY).googlehammer.com
jquery.com
getclicky.com
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
________________ .: [ Major Mike's ] :. ________________
Mozilla/6.0 (en-US; rv:6.9.6.9) Gecko/66666666 Firefox/6.6.6
-
- Posts: 4
- Joined: Wed Feb 16, 2011 1:34 am
Re: Pwned by [porn link deleted]
I see both jquery and getclicky in the whitelist, so I just removed those.
Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13 (.NET CLR 3.5.30729)
- GµårÐïåñ
- Lieutenant Colonel
- Posts: 3369
- Joined: Fri Mar 20, 2009 5:19 am
- Location: PST - USA
- Contact:
Re: Pwned by [porn link deleted]
Ok, read up on ABE and use some USER rules to limit their scope in your profile, or use domain specific blocking using ABP which I don't recommend but you can try at your own risk. Good luck.SpareSimian wrote:I see both jquery and getclicky in the whitelist, so I just removed those.
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
________________ .: [ Major Mike's ] :. ________________
Mozilla/6.0 (en-US; rv:6.9.6.9) Gecko/66666666 Firefox/6.6.6
- Giorgio Maone
- Site Admin
- Posts: 9524
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: Pwned by [porn link deleted]
What's your extensions list?
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13
-
- Posts: 4
- Joined: Wed Feb 16, 2011 1:34 am
Re: Pwned by [porn link deleted]
Is there a way to just export the addon list? Meanwhile, I'll just transcribe the list. Currently enabled:
AddThis 3.1.1
BetterPrivacy 1.48.3
ChatZilla 0.9.86
Facebook Toolbar 1.6
Flashblock 1.5.14.2
HTTPS-Everywhere 0.9.4
Java Console 6.0.23
Microsoft .NET Framework Assistant 0.0.0
NoScript 2.0.9.8
Personas 1.6.1
SQLite Manager 0.6.8
TinEye Reverse Image Search 1.0
I have a bunch more in disabled state. I'd switched to Chrome for awhile because FF was getting really slow but got tired of pop-unders, so switched back to FF and disabled about 2/3 of my addons. That seemed to help.
AddThis 3.1.1
BetterPrivacy 1.48.3
ChatZilla 0.9.86
Facebook Toolbar 1.6
Flashblock 1.5.14.2
HTTPS-Everywhere 0.9.4
Java Console 6.0.23
Microsoft .NET Framework Assistant 0.0.0
NoScript 2.0.9.8
Personas 1.6.1
SQLite Manager 0.6.8
TinEye Reverse Image Search 1.0
I have a bunch more in disabled state. I'd switched to Chrome for awhile because FF was getting really slow but got tired of pop-unders, so switched back to FF and disabled about 2/3 of my addons. That seemed to help.
Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13 (.NET CLR 3.5.30729)
Re: Pwned by [porn link deleted]
Enter about:support into the URL bar.SpareSimian wrote:Is there a way to just export the addon list?
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0b11) Gecko/20100101 Firefox/4.0b11
- GµårÐïåñ
- Lieutenant Colonel
- Posts: 3369
- Joined: Fri Mar 20, 2009 5:19 am
- Location: PST - USA
- Contact:
Re: Pwned by [porn link deleted]
As already stated @dhouwn, you can use the built in support system but if you are weary of sharing TOO MUCH, then there are reliable addons that allow you to format and customize the scope of them and will output them for you as well. Just another option, although personally I have to say about:support is quite sufficient and pretty efficient in doing it for you.SpareSimian wrote:Is there a way to just export the addon list?
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
________________ .: [ Major Mike's ] :. ________________
Mozilla/6.0 (en-US; rv:6.9.6.9) Gecko/66666666 Firefox/6.6.6