Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Does anyone know anything about this advert?
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
New Spam Site Found Every Three Seconds »
« (topic move) [BT] Pickedup a Trojan  
AuthorAll Replies


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
·AT&T U-Verse
·AT&T Midwest

reply to nwrickert
Re: Does anyone know anything about this advert?

Here is the iframe definition near the bottom of the eskimo.com page:
Anything obfuscated that way looks suspicious to me.

the content of the iframe has "unescape('%19%04%3C9%0E%60wL0" and that percent encoding goes on for most of the javascript (around 23000 bytes). Clearly somebody was hiding something.

I fetched those pages with "wget", so have local copies.

I later tried loading the page in XP with firefox, scripting turned on, but a limited user account. Nothing bad happened. This probably requires IE on an admin account before it can do anything bad.

Yet another reason to use a limited user account, to use firefox, to use the noscript extension.

--
AT&T dsl; Westell 327w modem/router; SuSE 10.1; firefox 2.0.0.13


EGeezer
Go Bobcats
Premium
join:2002-08-04
Country!
looks like the code in that line directs the user to the aforementiond website's directory: /dl/adv598.php
--
Mayors of New York come from nowhere and go nowhere.
Wallace Sayre (apparently, so do governors... )


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
·AT&T U-Verse
·AT&T Midwest


1 edit
yes it does

I used "lynx -dump" to decode it, before I posted the target link in an earlier post in this thread. That's quicker than trying to do it manually.

I don't currently have a good tool for handling that obfuscated javascript, though.


EGeezer
Go Bobcats
Premium
join:2002-08-04
Country!
·Callcentric
·RoadRunner Cable
·AT&T CallVantage


1 edit
I also see that the adv.php page seems to have a malware warning from stopbadware.org - is that a recent development?

This site is currently (as of 04/15/2008) being reported to StopBadware by the following partners:Google: reported bad

--
Mayors of New York come from nowhere and go nowhere.
Wallace Sayre (apparently, so do governors... )


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
Not sure.

I checked the stopbadware.org site for www.eskimo.com/dsl/ but it isn't listed. Other parts of eskimo.com are listed, but not the one that was used here.

I'm not seeing any warning if I try reloading the original link.


EGeezer
Go Bobcats
Premium
join:2002-08-04
Country!
·Callcentric
·RoadRunner Cable
·AT&T CallVantage

I think I might have loaded Google's link instead - Such a dummy I am!! My GET of the actual link only yielded an apache page .
--
Mayors of New York come from nowhere and go nowhere.
Wallace Sayre (apparently, so do governors... )


newview
Ex .. Ex .. Exactly
Premium
join:2001-10-01
Parsonsburg, MD

reply to nwrickert
said by nwrickert See Profile :

I don't currently have a good tool for handling that obfuscated javascript, though.

If you're looking for a good "de-obfuscator", Net Demon does the trick.
--

Ö¿Ö
The Rules of Spam | Maryland's Newest Anti-Spam Law
Where are we going? And what's with the hand basket?
Forums » Up and Running » Security » SecurityNew Spam Site Found Every Three Seconds »
« (topic move) [BT] Pickedup a Trojan  


Saturday, 28-Nov 19:37:55 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [122] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [80] TiVo Sees Record Customer Losses
· [70] Verizon CEO: Hulu Will Be Dead Soon
· [69] In-Flight Internet Headed For Bumpy Landing?
· [66] Weekend Open Thread
· [62] Thanksgiving Open Thread
· [40] EFF Wages War On Fine Print
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· [Newsgroups] Newzleech down? [Filesharing Software]
· how to use the 2nd line with phone hooked to the 1st line? [VOIP Tech Chat]
· Digital Transport Adapter Unboxing Photos [Comcast Cable TV]
· Gizmo5 has added a Google Voice section in its members area. [VOIP Tech Chat]
· [ PVP] 3.2 DK PvP D/W Spec... [World of Warcraft]
· Why would I want an e reader? [General Questions]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· Why not just turn off the ignition? [Automotive]