What the heck? Attack Site?

Page 9 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

Red Squirrel

No Lifer
May 24, 2003
69,939
13,460
126
www.anyf.ca
Did anyone actually get infected with anything through firefox? I'm assuming I'm safe, but I don't want to assume wrong, maybe something did attack me and I just don't know it. Running a Malwarebyte scan now so far so good.
 

ponyo

Lifer
Feb 14, 2002
19,688
2,810
126
I got hit last night using Chrome. That was one nasty malware. Spent about 2 hours removing it using malwarebytes. Spybot did nothing.

Now I'm back to using Firefox, adblock plus, and no script on all my computers.
 

Hacp

Lifer
Jun 8, 2005
13,923
2
81
Did anyone actually get infected with anything through firefox? I'm assuming I'm safe, but I don't want to assume wrong, maybe something did attack me and I just don't know it. Running a Malwarebyte scan now so far so good.

If nothing happened to you, chances are you're infected.
 

Zorkorist

Diamond Member
Apr 17, 2007
6,861
3
76
Did anyone actually get infected with anything through firefox? I'm assuming I'm safe, but I don't want to assume wrong, maybe something did attack me and I just don't know it. Running a Malwarebyte scan now so far so good.
While I was attacjed more than once, I don't believe the code actually ran.

-John
 

Red Squirrel

No Lifer
May 24, 2003
69,939
13,460
126
www.anyf.ca
If nothing happened to you, chances are you're infected.

I did get that firefox warning, but thinking there's always the possibility that something else got through.

Ironicly as I read your post I got an avira popup about some trojan in my temp internet files. I hope it never got executed.... but this can't be good.

Worse thing is, I have noscript for crap like this to be stopped, but this site is white listed... too bad you can't white list on a per script bassis or per function bassis. At least block out the js functions that are capable of accessing your computer. There's zero reason why JS should even have access to stuff outside of it's own scope variables.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
As I mentioned in the Technical Forum Issues thread, this would be a good time for a checkup. To save some typing...

This would be a good time for Windows users to give their rigs a check with the Secunia PSI utility, and for users of other OSes to manually confirm that their Adobe Flash Player and Adobe Reader installations (if present) are fully up-to-date.


http://secunia.com/vulnerability_scanning/personal/ Secunia says 98&#37; of first-time scans find at least one program that needs a security patch. You?

http://get.adobe.com/flashplayer/

http://get.adobe.com/reader/

Moar security tweaks for Windows: http://www.mechbgon.com/security Vista/7 users, note the new SEHOP item.

Also make sure your Data Execution Prevention's fully enabled:

 

AnonymouseUser

Diamond Member
May 14, 2003
9,943
107
106
Images are the source of the problem.

Wrong. Javascript loads a malicious PDF, and if you have the Adobe Reader plugin you get hosed.

Did anyone actually get infected with anything through firefox? I'm assuming I'm safe, but I don't want to assume wrong, maybe something did attack me and I just don't know it. Running a Malwarebyte scan now so far so good.

I would suspect that all browsers that have enabled the Adobe Reader plugin are susceptible.
 
Last edited:

Zorkorist

Diamond Member
Apr 17, 2007
6,861
3
76
The only real lesson to be learned here is that Anandtech has no idea when, why, or where they are serving up viruses.

The rest of us, that pracrice safe browsing will remove them from white-list.

How can you POSSIBLY RUN a website, and not whitelist your ads?

-John
 

miri

Diamond Member
Jun 16, 2003
3,679
0
76
If you use firefox + adblock + noscript are you safe from the recent attacks?
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
I would suspect that all browsers that have enabled the Adobe Reader plugin are susceptible.

In IE Protected Mode, you would get a "this program will open outside of Protected Mode" prompt that you could cancel, ending the attack. Here's a screenshot of an actual visit to the attack site:



Protected Mode FTW. If you get unexpected Protected Mode dialogue boxes out of the blue, like the one pictured above, obviously you should not allow them.
 
Last edited:

Red Squirrel

No Lifer
May 24, 2003
69,939
13,460
126
www.anyf.ca
How do I check if that PDF plugin is enabled? I have foxit, but come to think of it, I still have adobe installed. Uninstalling it now...
 

Zorkorist

Diamond Member
Apr 17, 2007
6,861
3
76
From my understanding, if you have the virus, you know it.

If your computer is operating normally, you do not have the virus.

-John
 

vi edit

Elite Member
Super Moderator
Oct 28, 1999
62,484
8,345
126
From my experience it was an obvious problem -

1) I had popups in my lower right hand icon tray saying stuff like "You have internet attacks from IP 204.XXX.XXX" and a host of others. And a window's security agent looking popup menu would come up asking if I wanted to run antivirus.

2) If you opened up IE it would redirect to some fakesecurity.microsoft.com domain (a result of the Proxy hijack)

3) If I tried to run any legitimate antivirus on my machine or msconfig I'd get an error that some exe was infected and that I needed to pay to upgrade my security software

Oh and even if I disabled my NIC I still had this thing popping up telling me I had various IP addresses attacking me.
 

JEDIYoda

Lifer
Jul 13, 2005
33,986
3,321
126
The only real lesson to be learned here is that Anandtech has no idea when, why, or where they are serving up viruses.

The rest of us, that pracrice safe browsing will remove them from white-list.

How can you POSSIBLY RUN a website, and not whitelist your ads?

-John

obviously you have no clue.......
If you read Anands response earlier you would understand that what you just said was plain stupid!!
 

Anubis

No Lifer
Aug 31, 2001
78,712
427
126
tbqhwy.com
As I mentioned in the Technical Forum Issues thread, this would be a good time for a checkup. To save some typing...


stuff
Also make sure your Data Execution Prevention's fully enabled:

funny thing about Secunia, i cant seem to get flash to show up as anything but insecure, even after downloading the solution
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
funny thing about Secunia, i cant seem to get flash to show up as anything but insecure, even after downloading the solution

1) Try a reboot.

2) if a subsequent scan still shows vulnerable versions of Flash after rebooting, run the Flash Player Uninstaller, then reboot, then install the latest version of Flash into whichever browser(s) you use.

Any good?
 

Anand Lal Shimpi

Boss Emeritus
Staff member
Oct 9, 1999
663
1
0
Quick update:

1) All ads are off the site.

2) We've submitted a review request to Google. These usually take several hours to complete. Once we come back clean, the malware warnings will disappear.

3) At the same time, we're working to fix the root cause of the problem.

More updates as I get them. Thank you all for helping each another out and being patient with us while we work through this.

Take care,
Anand
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |