What the heck? Attack Site?

Page 3 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

Anand Lal Shimpi

Boss Emeritus
Staff member
Oct 9, 1999
663
1
0
Hey guys, we've seen it too and we're trying to track down which ad is causing it. If you do get the above error and are willing/able to could you email me the source to the page? It looks like the malware may be served by a 3rd party's ad server that we have no control over, so as soon as we know exactly which ad it is, we can kill it. I'm working on getting some suspect ads pulled right now.

You can email the page source to me directly at anand@anandtech.com.

Take care,
Anand
 

lxskllr

No Lifer
Nov 30, 2004
57,525
7,731
126
Hey guys, we've seen it too and we're trying to track down which ad is causing it. If you do get the above error and are willing/able to could you email me the source to the page? It looks like the malware may be served by a 3rd party's ad server that we have no control over, so as soon as we know exactly which ad it is, we can kill it. I'm working on getting some suspect ads pulled right now.

You can email the page source to me directly at anand@anandtech.com.

Take care,
Anand

Sent
 

Fritzo

Lifer
Jan 3, 2001
41,888
2,131
126
I got that warning last night in Chrome. Someone reported Anandtech as a malicious site.
 

HeXen

Diamond Member
Dec 13, 2009
7,832
38
91
It looks like the malware may be served by a 3rd party's ad server that we have no control over,

as i suspected. many sites have this problem regularly, i feel sorry for those who think their so smart about comptuers they dont need AV's and layered protection and continue to use Windows not realizing hackers are always finding new ways to do things.
 

Meghan54

Lifer
Oct 18, 2009
11,542
5,063
136
Don't be a jackass.

A variety of people reporting the same problem...hmm!


Paige, you know Mike Gayner can't help it...it's in his nature to be a jackass. Congenital defect. To expect anything else from him is like expecting Tiger Woods to turn down a piece of "strange", just isn't gonna happen.
 

Zillatech

Senior member
Jul 25, 2006
213
0
76
Mark me down as another "Reported Attack Page!"

When I click the GTX480 Review logo, it blocks the page and gives me the BIG RED WARNING!
 

BoomerD

No Lifer
Feb 26, 2006
63,142
11,531
136
This makes me wonder if the "Congratulations! You Won!" that many of us experienced last week is related.
 

rcpratt

Lifer
Jul 2, 2009
10,433
110
116
This is unfortunate, and one of the reasons I will never turn AdBlock off, even on sites that I know and trust.
 

JEDIYoda

Lifer
Jul 13, 2005
33,982
3,318
126
Hey guys, we've seen it too and we're trying to track down which ad is causing it. If you do get the above error and are willing/able to could you email me the source to the page? It looks like the malware may be served by a 3rd party's ad server that we have no control over, so as soon as we know exactly which ad it is, we can kill it. I'm working on getting some suspect ads pulled right now.

You can email the page source to me directly at anand@anandtech.com.

Take care,
Anand

Damn I missed all the fun!!!

But hey our fearless leader posted, rallying the troops with a all out call for finding and exterminating the enemy!!!!

You Go Anand!!!!!!!!!!
 

JEDIYoda

Lifer
Jul 13, 2005
33,982
3,318
126
as i suspected. many sites have this problem regularly, i feel sorry for those who think their so smart about comptuers they dont need AV's and layered protection and continue to use Windows not realizing hackers are always finding new ways to do things.

To be honest as much as I am on this site, I was never invited to the party iether!!
But hey 10+ years working for Nortons....
 

sgtwiltan

Junior Member
Jun 29, 2009
17
0
0
Eh, I use Chrome and have never had an issue like this. PEBKAC, like 99.99999% of all virus problems.

PEBKAC?? You're probably infected if your browser didn't detect it. Running FF 3.6.2 on Linux from 2 different distros with ADblock warn of it. Same with Win7 on FF
 

dredd2929

Senior member
Jun 4, 2005
230
0
0
I get "Reported Attack Page" when trying to click on the link to the new GeForce GTX 480 article.

I try to get the page source (View > Page Source) and it just displays the same error message instead of the source code.

I'm using FF 3.6.2

I would post a screen shot if someone will explain to me how.
 
Last edited:

AnonymouseUser

Diamond Member
May 14, 2003
9,943
107
106
Man, everyone else is having all the fun! I even started an XP VM, installed Flash and Firefox, no AV is running, no adblocks, no flashblock, and have been reloading the Anandtech Fermi review over and over again. I just can't get infected! :\

I get "Reported Attack Page" when trying to click on the link to the new GeForce GTX 480 article.

I try to get the page source (View > Page Source) and it just displays the same error message instead of the source code.

I'm using FF 3.6.2

I would post a screen shot if someone will explain to me how.

Right click > Save Page As...
 

AnonymouseUser

Diamond Member
May 14, 2003
9,943
107
106
I finally got it, was prompted to install the Adobe Reader plugin. As soon as I did, got the 3D parser error, and was toast. Will send the info to Anand asap.

 

davecason

Member
Jun 4, 2000
100
0
0
Safe Browsing
Diagnostic page for anandtech.com/mobile

What is the current listing status for anandtech.com/mobile?
Site is listed as suspicious - visiting this web site may harm your computer.

Part of this site was listed for suspicious activity 2 time(s) over the past 90 days.

What happened when Google visited this site?
Of the 18 pages we tested on the site over the past 90 days, 4 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2010-03-27, and the last time suspicious content was found on this site was on 2010-03-27.
Malicious software includes 7 trojan(s). Successful infection resulted in an average of 2 new process(es) on the target machine.

Malicious software is hosted on 4 domain(s), including googleanalyticsz.com/, mjgjo.com/, green-fast.net/.

1 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including whoiz.shit.la/.

This site was hosted on 1 network(s) including AS36643 (EICOMM).

Has this site acted as an intermediary resulting in further distribution of malware?
Over the past 90 days, anandtech.com/mobile did not appear to function as an intermediary for the infection of any sites.

Has this site hosted malware?
No, this site has not hosted malicious software over the past 90 days.

How did this happen?
In some cases, third parties can add malicious code to legitimate sites, which would cause us to show the warning message.

Next steps:
Return to the previous page.
 
Dec 10, 2005
24,237
7,093
136
Haven't seen any problems on my end, but that might be because of NoScript+AdBlock+Firefox.

Edit:
Also checked my computer with HiJackThis! and using the analyzer tool available online, didn't see any problems. Though, I haven't seen any indication that something tried to install itself either.
 
Last edited:
Dec 10, 2005
24,237
7,093
136
I highly recommend anyone still using Adobe Reader to uninstall it and install Foxit Reader.

I would use Foxit, but Foxit won't open secured PDF files and sometimes it gives me trouble printing to a networked printer. I did disable the Adobe Firefox plugin (I hate opening PDFs in the browser).

Edit:
Just checked the latest Nvidia GPU review that's up and got the warning in Firefox; but I didn't get it earlier today when I had glanced at it...

Edit again:

And on a bunch of other reviews available.

Of the 18 pages we tested on the site over the past 90 days, 4 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2010-03-27, and the last time suspicious content was found on this site was on 2010-03-27.

Malicious software includes 7 trojan(s). Successful infection resulted in an average of 2 new process(es) on the target machine.

Malicious software is hosted on 4 domain(s), including googleanalyticsz.com/, mjgjo.com/, green-fast.net/.

1 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including whoiz.shit.la/.

This site was hosted on 1 network(s) including AS36643 (EICOMM).
 
Last edited:
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |