republican-creole
site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
4855
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
page: 1 · 2 · 3
AuthorAll Replies


justin
Australian
join:1999-05-28
New York, NY
kudos:7
Host:
IPv6
Business Connectiv..
Console/Handheld g..
Console Tech
Home/Office setup ..

Does anyone know anything about this advert?

Click for full size
from a non registered user, complaint sent by email..


I clicked on the banner ad and my pc is completely unusable now. Trojans, viruses, etc. My Symanetc Corp 10 and spybot lit up like fireworks were goin off. Whats the story here? Can you help? I just fucked my work PC. How can this happen on a trusted site like dslreports? What now?


I don't recognize that advert but maybe someone here knows where it goes to so I can tell this person whether it is really malware or not..


Its a Secret
Please speak into the microphone
Premium
join:2008-02-23
Da wet coast
kudos:3

I've sent a request to have this looked at by the mods. Hopefully, we'll know something soon...
--
A triple espresso, please...



nil
Java Geek
join:2000-11-27
kudos:1
Host:
Webmasters and Dev..
Forum Feature Requ..

4 edits

reply to justin

Click for full size
I just got a similar one..

Yah, same one leads here:
http://www.eskimo.com/dsl/?gclid=CIi9u9613pICFQMelgodJlsH-g
 

Can anyone confirm any issue? I'm on a mac..
--
Life is too short to be boring


n1zuk
Break out the checkbook
Premium
join:2001-10-24
Malta
kudos:2

reply to justin
I saw it earlier, when I was at work. I (thankfully) didn't click on it.

It did seem out of the normal to me...
--
New to Forum Life? Click here and learn.



nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
kudos:7
Reviews:
·AT&T U-Verse

reply to justin
The main link redirects to http://www.eskimo.com/dsl/?gclid=CMbU0pK03pICFQhusgodDghp-w and there is a suspicious iframe near the end of that page.

iframe content is http://cdpuvbhfzz.com/dl/adv598.php and that contains obfuscated javascript.
--
AT&T dsl; Westell 327w modem/router; SuSE 10.1; firefox 2.0.0.13



skj
Welcome to the far side of reality
Premium,Mod
join:2002-04-04
Gone South
Host:
Charter Internet/TV
Earthlink DSL
CenturyLink
ISP b2b etc
Cisco

There is a thread at CastleCops regarding: cdpuvbhfzz.com

http://www.castlecops.com/p1079008-iframe_loading_hxxp_cdpuvbhfzz_com_dl_adv598_php.html
--


The foundations of character are built not by lecture, but by bricks of good example, laid day by day.



nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
kudos:7

Thanks for that CastleCops reference. Quite interesting.



skj
Welcome to the far side of reality
Premium,Mod
join:2002-04-04
Gone South
Host:
Charter Internet/TV
Earthlink DSL
CenturyLink
ISP b2b etc
Cisco

Yes, it is. That thread was also posted today, so it looks like this nasty may have recently started ciruclating around the net.
--


The foundations of character are built not by lecture, but by bricks of good example, laid day by day.



nil
Java Geek
join:2000-11-27
kudos:1
Host:
Webmasters and Dev..
Forum Feature Requ..

1 edit

Domain created 3/31/08.. so looks recent.

Domain name: cdpuvbhfzz.com
er, removed domain info.. see this:

»www.chiriquichatter.net/blog/2008/04/12/an
--
Life is too short to be boring



Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX

1 edit

reply to justin
Linkscanner doesn't like that ad's URL:
»linkscanner.explabs.com/linkscan···odJlsH-g

Nor does it like the one in the iframe, which it says is
on a disreputable hosting provider, known to host malicious
code.

It calls the former an orphaned lure site.

The iframe one's WHOIS data:

OrgName:    RIPE Network Coordination Centre 
OrgID:      RIPE
Address:    P.O. Box 10096
City:       Amsterdam
StateProv:  
PostalCode: 1001EB
Country:    NL
 
ReferralServer: whois://whois.ripe.net:43
 
NetRange:   85.0.0.0 - 85.255.255.255 
CIDR:       85.0.0.0/8 
NetName:    85-RIPE
NetHandle:  NET-85-0-0-0-1
Parent:     
NetType:    Allocated to RIPE NCC
NameServer: NS-PRI.RIPE.NET
NameServer: NS3.NIC.FR
NameServer: SEC1.APNIC.NET
NameServer: SEC3.APNIC.NET
NameServer: SUNIC.SUNET.SE
NameServer: TINNIE.ARIN.NET
NameServer: NS.LACNIC.NET
Comment:    These addresses have been further assigned to users in
Comment:    the RIPE NCC region. Contact information can be found in
Comment:    the RIPE database at http://www.ripe.net/whois
RegDate:    2004-04-01
Updated:    2004-04-06
 

--
"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)


nil
Java Geek
join:2000-11-27
kudos:1

Based on a brief google search, it appears to be an exploit script targeting word press, vbulletin, coppermine, etc. Php exploit, maybe?
--
Life is too short to be boring



justin
Australian
join:1999-05-28
New York, NY
kudos:7

reply to nil
If you can make the ad appear again, can you click the "ads by google" link at the right and drill down, open up and keep drilling until you get the part where you can report a bad ad to adsense?



nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
kudos:7

I can reproduce the original url (to googlesyndication) if that's any help



justin
Australian
join:1999-05-28
New York, NY
kudos:7
Host:
IPv6
Business Connectiv..
Console/Handheld g..
Console Tech
Home/Office setup ..

I've blocked eskimo.com and also emailed our adsense rep with a complaint. Unfortunately I really don't see how this can be avoided in future. I doubt any ad network is smart enough to vet and clean the click stream from any ad, and if they did when the ad was lodged what is to stop the landing page getting modified later?



cabana
Department of Adjustments
Assistant
join:2000-07-07
New York, NY
Host:
AT&T Southeast
56k Lookout! (broa..

reply to nwrickert
I recreated similar ads with the coloring and "feel" -- but I am not sure if they are related -- properties showed:

pagead2.googlesyndication.com/pagead/imgad?id=CJ_1t5_n5bHiowEQ2AUYTzIIQhaO6-aqw3E

pagead2.googlesyndication.com/pagead/imgad?id=CPvFnZC4uc-M0AEQ2AUYTzIIxm5IBBA487w

pagead2.googlesyndication.com/pagead/imgad?id=CPvFnZC4uc-M0AEQ2AUYTzIIxm5IBBA487w

The thing I noticed on the screenshot that was strange - was to the right the "served by google" was missing (usually shows next to our banners on the homepage)-- could be that it was there and just not caught on the screen shot.



nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
kudos:7

reply to justin
Yes, I agree there is not a lot you can do to prevent this.



nil
Java Geek
join:2000-11-27
kudos:1

Based on a google search, eskimo.com was exploited, not doing this on purpose.
--
Life is too short to be boring



nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
kudos:7

I assumed that.

Unfortunately, other sites will be similarly exploited.



nil
Java Geek
join:2000-11-27
kudos:1
Host:
Webmasters and Dev..
Forum Feature Requ..

It's definitely a php-based exploit, but not targeting all open source php apps (that I can tell so far), so probably looking for some specific code problem. An analysis of the source and libraries used by the known targets would probably narrow it down..
--
Life is too short to be boring



Its a Secret
Please speak into the microphone
Premium
join:2008-02-23
Da wet coast
kudos:3

reply to justin
ZA has ad block which I've used without regret. This is only one more reason...
--
A triple espresso, please...


Tuesday, 29-May 20:50:37 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics