possible malicious site appeared in whitelist
possible malicious site appeared in whitelist
Just checked my No-Script Whitelist this morning, and I found this URL in it: "adinterax.com" Know as far as I am aware I have not allowed this, if so it was an accident. Anyway I'm not really sure how it got in my Whitelist, but on doing a google search I got the following Windows popup message: Secure connection failed: adinterax.com: 443 uses an invalid security certificate. The certificate is only valid for "http://www.adinterax.com" (Error code: ssl_error_bad_cert_domain) This could be a problem with the server's configuration or it could be someone trying to impersonate the server. If you have connected to this server successfully in the past the error may be temporary and you can try again later. The site appears at the top of the google search list. I suspect this may be a SEO posioning attack site.
Last edited by eradic8 on Fri Sep 10, 2010 9:53 am, edited 1 time in total.
Mozilla/5.0 (Windows; U; Windows NT 6.0; en-GB; rv:1.9.2.9) Gecko/20100824 Firefox/3.6.9
- Giorgio Maone
- Site Admin
- Posts: 9524
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: possible malicious site appeared in whitelist
This site belongs to Yahoo!, and it's one of its ad networks.
You likely allowed inadvertently by "Allow all on this page", but it's seemingly not malicious.
You likely allowed inadvertently by "Allow all on this page", but it's seemingly not malicious.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.2.9) Gecko/20100824 Firefox/3.6.9
Re: possible malicious site appeared in whitelist
Thanks for the quick reply, but I don't understand why I'm getting the popup saying the certificate is invalid.Giorgio Maone wrote:This site belongs to Yahoo!, and it's one of its ad networks.
You likely allowed inadvertently by "Allow all on this page", but it's seemingly not malicious.
Mozilla/5.0 (Windows; U; Windows NT 6.0; en-GB; rv:1.9.2.9) Gecko/20100824 Firefox/3.6.9
- Giorgio Maone
- Site Admin
- Posts: 9524
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: possible malicious site appeared in whitelist
Because of a server-side misconfiguration.eradic8 wrote:I don't understand why I'm getting the popup saying the certificate is invalid.
- They've got a SSL cert for www.adinterax.com
- You opened http://adinterax.com
- They've got a server-wide directive to redirect any HTTP traffic to HTTPS
- You're redirected to https://adinterax.com. Since the certificate is only for www.adinterax.com, Firefox warns you about the mismatch
Anyway, no malice there, just incompetence.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.2.9) Gecko/20100824 Firefox/3.6.9
Re: possible malicious site appeared in whitelist
O.K thanks for the explanation Giorgio, I understand now.Giorgio Maone wrote:Because of a server-side misconfiguration.eradic8 wrote:I don't understand why I'm getting the popup saying the certificate is invalid.The correct way for them to handle the HTTP->HTTPS redirection should be changing both the protocol (http:->https:) and the host (adinterax.com->www.adinterax.com), rather than the protocol alone.
- They've got a SSL cert for www.adinterax.com
- You opened http://adinterax.com
- They've got a server-wide directive to redirect any HTTP traffic to HTTPS
- You're redirected to https://adinterax.com. Since the certificate is only for www.adinterax.com, Firefox warns you about the mismatch
Anyway, no malice there, just incompetence.
Mozilla/5.0 (Windows; U; Windows NT 6.0; en-GB; rv:1.9.2.9) Gecko/20100824 Firefox/3.6.9
-
- Posts: 1
- Joined: Sat Nov 19, 2011 7:05 pm
Re: possible malicious site appeared in whitelist
hey Giorgio thanks for detail description, I appreciate it !
Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.2 (KHTML, like Gecko) Chrome/15.0.874.121 Safari/535.2
Re: possible malicious site appeared in whitelist
FWIW, this site has a very poor reputation at mywot.com, where it is accused by some users of loading spyware. My HOSTS file blocks it, with the explanation, "Tracking Cookie".
I'll add this to the 'SOME SITES YOU MIGHT NOT WANT TO ALLOW" list.
Thanks for the report.
I'll add this to the 'SOME SITES YOU MIGHT NOT WANT TO ALLOW" list.
Thanks for the report.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.24) Gecko/20111103 Firefox/3.6.24