Help Forum How To | General Corvetteforum Questions | Feedback

CF Admins: More deep linking redirect attacks

Thread Tools
 
Search this Thread
 
Old Sep 7, 2019 | 03:16 AM
  #1  
larrysb's Avatar
larrysb
Thread Starter
Race Director
20 Year Member
Active Streak: 30 Days
Community Builder
Community Influencer
 
Joined: Aug 2002
Posts: 16,695
Likes: 1
From: Redacted
Default CF Admins: More deep linking redirect attacks

Just started getting embedded redirects off of Corvette Forum. These are damned annoying, they come through your advertisers, who are inserting encrypted redirects embedded in javascript.

I've brought this up before, they disappeared for a while. But this weekend, they're back on.

This happens just sitting viewing the Corvette Forum page. No clicking required. Then a rapid series of uncommanded redirects, which finally sent my browser to a malware site that my router blocked cold.

Again - no clicking required. Just viewing the CF page.
Old Sep 7, 2019 | 10:36 AM
  #2  
J T's Avatar
J T
IB Staff
15 Year Member
Photogenic
Photoriffic
Shutterbug
 
Joined: Feb 2009
Posts: 10,573
Likes: 4
Default

Please provide some of the information you're stating so that we can investigate with some specific details.

I assume this is also related to a blank/black ad box that may appear either up top or bottom?

I know the advertising team was aware of this issue and was reviewing it the last time.

Originally Posted by larrysb
Just started getting embedded redirects off of Corvette Forum. These are damned annoying, they come through your advertisers, who are inserting encrypted redirects embedded in javascript.

I've brought this up before, they disappeared for a while. But this weekend, they're back on.

This happens just sitting viewing the Corvette Forum page. No clicking required. Then a rapid series of uncommanded redirects, which finally sent my browser to a malware site that my router blocked cold.

Again - no clicking required. Just viewing the CF page.
Old Sep 8, 2019 | 02:51 AM
  #3  
larrysb's Avatar
larrysb
Thread Starter
Race Director
20 Year Member
Active Streak: 30 Days
Community Builder
Community Influencer
 
Joined: Aug 2002
Posts: 16,695
Likes: 1
From: Redacted
Default

Got another redirect moments ago. The thing is, I don't know what element on the page causes it, as there are many active JS running. One of them is almost certainly eval'ing an image, which contains an encoded URL that's been tagged as a image or jpg or some such.

Again - I did nothing. I was just reading a post. No clicking, so it comes through an ad re-load. There's so freaking many of them on the CF site, that I'm not sure how to tell what element it was.

They go by so fast but it landed at this URL after several redirects (the usual "virus detected...download this" scam:

WARNING this URL is poison do not click!!!!



Other URL's in the redirect chain:



Code:
xttp://your-mac-security-analysis.net.ahrauchd.h5pg5hj9fyamcrwakp091o16mp5sjsne6izdq.xyz/fx/en/index.php?browser=Safari&fred=1&app=Mac%20Speedup%20Pro&hul=rs.eujmj3g.space&cep=y-ROUxf_tJrZ4x_Qz0mXCaBogauuVNs-eYfCtpYmdS-ehZemKFETwGKN0zli4hX7qTmy19jfmPtumtRRM_gu3vxgeSfHzURxsyFap-DpR65J9PXaDwpQ4_rfkhfTVKm5ktLp5o4EOxweiQAIlG6LZL9dCrOdECHgy0o6N1LABxgos1UpxaeJfBGklDyPmrVmK8sTb6H-BTPh5kDwTTWp9H5ugH8QCf6yujLNApZTPVYfpV3SBc8vg8VkIbGHc68bMlE__eEnv_a9_nySxrkjQtqMEzbolkuq7negwon7_H8nf6ocBZFcG5MYAPwNnMcg9shiOgQRmQinzYOGL9OFqOqT9iUmyVtTUxUKy3Kws8OaolqXfEJoHxIICP-8dexWzlhPCaMJJaL3Iw5A-hQrzDf-TDYOhXCcjWtCLXLbo-GMu1huhdce3x7TITcdSin1xK-5RF3asdcW6MBvU-tZuPYl1nGwbTMecxMz3nEV7MTto51OdP0_wOTwVD3qefy2n-ttBjibdc4xKkRM49kmF4FUKFasdmjrWmZzZWEUyWqx9vkS2JS7w1LVH_5Yrllv&_=BAoAXXSjUwFddKNTgAGBAcAAIPhDKrP9QjG5-heUhAEtFhN6wtI9psHZFSwKGy343M1MwQAgZPHWsccHmGyCRxQvpCIz1WLFxfV25DEBBAf-pO3Bot3CACDBrYscC8QDvs76dVlH5tBu8QnfpV1oGwVWHoMMKZjN48QAECYBBkaMAIudLLfZFH0P26vFABBZa4IItEn7cGMhHa-AunvrwwAgXAwcYevxT1AMk2M05VXU1_qNUYsu1Ftmg8IhpOPtKJI#b

xttp://the.bestoffersonline.stream/?utm_term=6734188736508067961&clickverify=1&utm_content=e7cacbe0c0dbc9c1a2a391979e97a49c8f8db888becabcc8b2b381878383b48dbfb988bdbcbf8cbfb28380b086878485a89bd9e9eef3f9bdd1fcfde1e3e3f1e7c6cba1878dc1ecdfd6e3d2d5e6e7e491888e9df9fecefcccc4cbc0f1c7c7c1c5cacbc850

xttp://the.bestoffersonline.stream/?utm_term=6734188745081225418&clickverify=1&utm_content=e7cacbe0c0dbc9c1a2a391979e97a49c8f8db888becabcc8b2b381878383b48dbfb988bdbcbf8cbd8283b181868784b79adae8e9f2fabcdefdfee0e4e2f2e6b9caa2868ac0efded9e2d1d4e1e6e790978f9ef8f9cfffcdcbcac3f0c0c6c2c4f5cacbda

xttps://0fficial.page/l/Mac/Cleaner/_index.php?lpk=15a367bb92bb58e901&language=en-US&img=sys2&uclick=fta9qdbl

xttps://0fficial.page/ll/click.php?key=kf1hssv4d6kqatpev3cz&subid=6734188745081225418&t1=847&t2=847-6d15a6fz&t3=6734188745081225418&t4=US


<meta http-equiv="refresh" content="0;URL='https://d5dijku3y67x2.cloudfront.net/?os=mac&amp;x-context=wB0KILCOU4LT9V6P1IMSV908&amp;utm_source=mmfxmrktddl3&amp;utm_campaign=mmfxmrktddl3o&amp;pxl=MMF4072_MMF3976_RUNT&amp;utm_pubid=17521&amp;x-at=f25a69b9-4af8-4553-895a-2041761e8173&amp;override=1'">

Last edited by larrysb; Sep 8, 2019 at 03:16 AM.
Old Sep 8, 2019 | 04:17 AM
  #4  
J T's Avatar
J T
IB Staff
15 Year Member
Photogenic
Photoriffic
Shutterbug
 
Joined: Feb 2009
Posts: 10,573
Likes: 4
Default

I think this is related to the blank/black ad block that is also causing other issues in the network. If you can confirm that, again, that would help. We're investigating the issue and working the ad team.

Yes, there is a lot of JS. Not all JS is bad. Over the years, websites like CorvetteForum have grown and evolved as technology has changed and how people use and expect of the site has as well. The site is not a static site with text and images. You've got Infinite Scroll and Related Threads enabled, Auto Save Draft, Advanced Image Uploader, etc., that are all features that been developed and take coding (such as JS) to function. Not to mention legacy functions that also require JS (such as the drop-down menus). Turning off JS and browsing popular sites will show just how much JS is used to the point some sites will not load properly.

Originally Posted by larrysb
Got another redirect moments ago. The thing is, I don't know what element on the page causes it, as there are many active JS running. One of them is almost certainly eval'ing an image, which contains an encoded URL that's been tagged as a image or jpg or some such.

Again - I did nothing. I was just reading a post. No clicking, so it comes through an ad re-load. There's so freaking many of them on the CF site, that I'm not sure how to tell what element it was.

They go by so fast but it landed at this URL after several redirects (the usual "virus detected...download this" scam:

WARNING this URL is poison do not click!!!!



Other URL's in the redirect chain:



Code:
xttp://your-mac-security-analysis.net.ahrauchd.h5pg5hj9fyamcrwakp091o16mp5sjsne6izdq.xyz/fx/en/index.php?browser=Safari&fred=1&app=Mac%20Speedup%20Pro&hul=rs.eujmj3g.space&cep=y-ROUxf_tJrZ4x_Qz0mXCaBogauuVNs-eYfCtpYmdS-ehZemKFETwGKN0zli4hX7qTmy19jfmPtumtRRM_gu3vxgeSfHzURxsyFap-DpR65J9PXaDwpQ4_rfkhfTVKm5ktLp5o4EOxweiQAIlG6LZL9dCrOdECHgy0o6N1LABxgos1UpxaeJfBGklDyPmrVmK8sTb6H-BTPh5kDwTTWp9H5ugH8QCf6yujLNApZTPVYfpV3SBc8vg8VkIbGHc68bMlE__eEnv_a9_nySxrkjQtqMEzbolkuq7negwon7_H8nf6ocBZFcG5MYAPwNnMcg9shiOgQRmQinzYOGL9OFqOqT9iUmyVtTUxUKy3Kws8OaolqXfEJoHxIICP-8dexWzlhPCaMJJaL3Iw5A-hQrzDf-TDYOhXCcjWtCLXLbo-GMu1huhdce3x7TITcdSin1xK-5RF3asdcW6MBvU-tZuPYl1nGwbTMecxMz3nEV7MTto51OdP0_wOTwVD3qefy2n-ttBjibdc4xKkRM49kmF4FUKFasdmjrWmZzZWEUyWqx9vkS2JS7w1LVH_5Yrllv&_=BAoAXXSjUwFddKNTgAGBAcAAIPhDKrP9QjG5-heUhAEtFhN6wtI9psHZFSwKGy343M1MwQAgZPHWsccHmGyCRxQvpCIz1WLFxfV25DEBBAf-pO3Bot3CACDBrYscC8QDvs76dVlH5tBu8QnfpV1oGwVWHoMMKZjN48QAECYBBkaMAIudLLfZFH0P26vFABBZa4IItEn7cGMhHa-AunvrwwAgXAwcYevxT1AMk2M05VXU1_qNUYsu1Ftmg8IhpOPtKJI#b

xttp://the.bestoffersonline.stream/?utm_term=6734188736508067961&clickverify=1&utm_content=e7cacbe0c0dbc9c1a2a391979e97a49c8f8db888becabcc8b2b381878383b48dbfb988bdbcbf8cbfb28380b086878485a89bd9e9eef3f9bdd1fcfde1e3e3f1e7c6cba1878dc1ecdfd6e3d2d5e6e7e491888e9df9fecefcccc4cbc0f1c7c7c1c5cacbc850

xttp://the.bestoffersonline.stream/?utm_term=6734188745081225418&clickverify=1&utm_content=e7cacbe0c0dbc9c1a2a391979e97a49c8f8db888becabcc8b2b381878383b48dbfb988bdbcbf8cbd8283b181868784b79adae8e9f2fabcdefdfee0e4e2f2e6b9caa2868ac0efded9e2d1d4e1e6e790978f9ef8f9cfffcdcbcac3f0c0c6c2c4f5cacbda

xttps://0fficial.page/l/Mac/Cleaner/_index.php?lpk=15a367bb92bb58e901&language=en-US&img=sys2&uclick=fta9qdbl

xttps://0fficial.page/ll/click.php?key=kf1hssv4d6kqatpev3cz&subid=6734188745081225418&t1=847&t2=847-6d15a6fz&t3=6734188745081225418&t4=US


<meta http-equiv="refresh" content="0;URL='https://d5dijku3y67x2.cloudfront.net/?os=mac&amp;x-context=wB0KILCOU4LT9V6P1IMSV908&amp;utm_source=mmfxmrktddl3&amp;utm_campaign=mmfxmrktddl3o&amp;pxl=MMF4072_MMF3976_RUNT&amp;utm_pubid=17521&amp;x-at=f25a69b9-4af8-4553-895a-2041761e8173&amp;override=1'">
Old Sep 19, 2019 | 05:23 PM
  #5  
larrysb's Avatar
larrysb
Thread Starter
Race Director
20 Year Member
Active Streak: 30 Days
Community Builder
Community Influencer
 
Joined: Aug 2002
Posts: 16,695
Likes: 1
From: Redacted
Default

Just happened again moments ago.

Also happens on Rennlist, another Internet Brands site.

I know all about JS, written a fair bit of it myself, but not my speciality. I'm more into embedded C/C++ and python.

The current vector appears to go through c.adsco.re and redirects to MacKeeper and other malware sites.

It's definitely coming through the advertising channel and they're encoding the mal-url in the image data and decoding it with JS.
Old Sep 24, 2019 | 05:55 PM
  #6  
larrysb's Avatar
larrysb
Thread Starter
Race Director
20 Year Member
Active Streak: 30 Days
Community Builder
Community Influencer
 
Joined: Aug 2002
Posts: 16,695
Likes: 1
From: Redacted
Default

So - here's some fun. I blocked all of adscore ( xx.adsco.re) domains at my router level, which causes the redirects to fail. Caught one today here on Corvette Forum.

I changed "http" in the redirect to "xttp" to prevent the hapless from accidentally clicking it.

So the embedded image data, decided by JS, causes a redirect from this rs.eujmj3g.space server, hands it off to adscore (who are providing cover for these kinds of malware redirects).

I'll add this domain to my router blacklist. We'll eventually, hopefully figure out which ad vendor is slipping this crap in. It hits a number of popular web boards, not just corvette forum.

For the users reading along, the scheme is to create a fake "image" file, with the redirect URL embedded as data and a javascript to run on your browser to extract it. They slip this on through adserververs, who kinda scan them looking for this kind of stuff. But they slip through. The ads on the page are active and reload on their own. Sooner or later, the malware redirect comes up on your browser, the fake image data is decoded, then a double-hand-off occurs and you get sent to a "download flash player" or "your mac is infected with three viruses" link.

These people are scum.

I'd love to see more done to stop them. It's BS. It also degrades the business value of ever web provider who gets this garbage slipped in on them.




Code:
xttp://rs.eujmj3g.space/zp-redirect?target=https%3A%2F%2Fc.adsco.re%2Fd%23Qj4hAAAAAAAAEy7UL13RqmPdTwDQ5wnEWeWnCCs%2Cdd2df884-574f-4a2c-8f8c-ee9ae7ed62eb_whiskey-bob-H2d0uBT7%2C3%2C%2CAAIe4oCm8tIO9F6MLp_t9rCVO6NgT_LE9ClqeJ90k09s9uOTNky4KpUkl-NqYIGsXcfka20kdzXjcscKks7_zT8kCf8HBVmn32ql5Gc1pyWsQH4JnPZJYzhjZQUDOlF2CeqSw4liYZqt2dHWkKXrkd-262RmSqqXstpc6unRDYigblZGu9-ztAtx7mT7VwM0cdjwt6hLx29EKvKVMchOu-CPS4WGI1fagLF3dZXWa6NvJ1RIhdWYR4F4DVp-Ej3Lz4IJIxgzeCwh5aYyMjxJIlQMs_SSa3xXW4mspx_S9-Bngy5h4VbvZQytXS17x8bMkoD30momCyqYBT4MqhyTIbtye-FQ_d2i3KqPTqHPCWSxOw%3Fbrowser%3DSafari%26trackingdomain%3Drs.eujmj3g.space%26brand%3DDesktop%26model%3DDesktop%26osversion%3DMacOS%252010.14%2520Mojave%26cep%3D%26cep%3D-MEcx42R5Qz8FxVw2wga2BQ-k7wTZzjgwiWGfOfiquBbHj3Lehss49Gpyq_DYTfKTa-stsR6cUnbMIRuKmEYoovk-PCQ6bVsVHAYuoVd5SDUR_JkMbIIq1S4sSWSHvLM50WcYBmCI1OSughEaBXuAX4UcRCQS0gj65SH-Q3_n6-nqt0MAK-TYFu1m6VKmJ-ohQdbULeQZXt-7odpHKAOoVVTvwnG7KZdyfGB8brXV-Wpwwg1Fe9uSMOOsiHCx2NZlPv-8mbsdJTXM19lYzxcStySwqlR-AQNpwUHmDP4k8r31cb5BopqkH-ITteDQM2G6X3lK7HQ5H7Coou47EaCYVW37XVM-386tuKtkF5bJtnaiGokYlNDIgc8IHWhiZ0DxqLSldSwPIRawdsMdDoYq-2_ajROHEsOT9wLwsTvSzNNP1pNgGH01bz1aCvPvC4454XbQOOw23rgF8dGX4A6E_Ny8K_mjFTxmKby9a8f5PCXyKOcublW2hRM4QYXAH4k5F_UlPFpLi3q-lKV29CKxVDmIvlkjiM3IMw-Deunz6G40unCznB1Qvw-_raP86SB7UqL5TL33jFWsWEMh-BgzA%26lptoken%3D15126962368e279f165c&caid=66a39719-c53a-4764-aff0-d410ed5183ba&zpid=332b01ec-df13-11e9-af87-0ad8dd6ea862&cid=&rt=R

Code:
End of code

Last edited by larrysb; Sep 24, 2019 at 05:56 PM.
Old Sep 24, 2019 | 06:11 PM
  #7  
larrysb's Avatar
larrysb
Thread Starter
Race Director
20 Year Member
Active Streak: 30 Days
Community Builder
Community Influencer
 
Joined: Aug 2002
Posts: 16,695
Likes: 1
From: Redacted
Default

Add another pop up malware redirect.



Code:
xttp://your-mac-security-analysis.net.gwbpobzrv.semumcgfnqvx8lkkrwtso4jdc4upyxz4.xyz/fx/en/index.php?browser=Safari&fred=1&app=Mac%20Speedup%20Pro&hul=rs.eujmj3g.space&cep=4rGtAf_zZWfdYHnohQ1zM0FMErYW0297RETBBUmZvUls0sl1fGMMDG4xflqD_eG-AQvLwX30FrduXWdz4favn-UHNxJy_MNm3SuCEQyXNxqZumC_HDKZInq9EeEjnEja4wm5pD4BZQnUcA0J5c3q8S6aur2SfjRV_dpdBE0C5N0Id7q2zMIrodV0yYSoaf25-_aLTUc-FxTNPO2lgwXLt9QHgH0oEFKY4rJNQb3KwVuufwa9ln_G1x20nxYeMr1j_NAhzZu6_n6I72Pc9BkEv9LdNlwpt9TIcYdG7nIkySzqx3n39HhCqwS7_y4Fdaom1fjnqr4FsNVjR2gj3qdVcMSSxsMeUza9OBjQXbWFrPWgNXQdE5zK-39gUqLinDir0aU71VT2EhhjSLVVUFhu3mqnxJsA4lPbIdromfjzVQp4CAzqAwcvKY81gpYV6dNJIvHZyWK5PG1gTgrzyyZO2d33wCxXRknB4AO14cffasmgN1C2eb4CqI1mQc0ZZOqrJs35ssImTQlaeMi3L4Fc04acrsV_MtM3owZ_1YTHHmLQcFbk202ri7rgkhJJRv4HSzYv5JipLAG8JRKBvlhwEg&_=BAoAXYqSsAFdipKwgAGBAcAAIOqewL68M-URQBcZYa2GURDXRtGaEoMYCzfRTBW6hjBGwQAg8sef7geIWOpTCTkfHiRWQUW-8Imsv9mF6ixmmJjs2P_CACDOiCWDwyNGQ3r7RXVQA2xw3BwcDeBiIBab56lmlXoTbMQAECYBBkaMAIudnX2gwQ_d0SLFABD-f4oawPYy1TUgi7dmzbqNwwAgBhavMuUnpl62ieHv6IbL7cZzj2cmCGN5aokyxAWKh30

end of code
Old Sep 24, 2019 | 06:12 PM
  #8  
larrysb's Avatar
larrysb
Thread Starter
Race Director
20 Year Member
Active Streak: 30 Days
Community Builder
Community Influencer
 
Joined: Aug 2002
Posts: 16,695
Likes: 1
From: Redacted
Default

Adscore implicated multiple times.

They should be considered a malware vector, period.
Corvette Stories

The Best of Corvette for Corvette Enthusiasts

story-0

Top 10 DOs and DON'Ts for Protecting Your Convertible Top!

 Michael S. Palmer
story-1

Top 10 Most Explosive Corvettes Ever Made: Power-to-Weight Ratio Ranked!

 Joe Kucinski
story-2

150 hp to 1,250 hp: Every Corvette Generation Compared by the Specs That Matter

 Joe Kucinski
story-3

8 Coolest Corvette Pace Cars (and Replicas) of All Time

 Verdad Gallardo
story-4

Top 10 Corvette Engines RANKED by Peak Torque (70+ Years of Muscle!)

 Joe Kucinski
story-5

Corvette ZR1X Will Be Pacing the Indy 500, And Could Probably Race, Too!

 Verdad Gallardo
story-6

Top 10 Corvettes Coming to Mecum Indy 2026!

 Brett Foote
story-7

Top 10 C9 Corvette MUST-HAVES to Fix These C8 Generation Flaws!

 Michael S. Palmer
story-8

10 Revolutionary 'Corvette Firsts' Most People Don't Know

 Joe Kucinski
story-9

5 Reasons to Upgrade to an LS6-Powered Corvette; 5 Reasons to Stay LT2

 Michael S. Palmer
Old Sep 27, 2019 | 03:26 AM
  #9  
larrysb's Avatar
larrysb
Thread Starter
Race Director
20 Year Member
Active Streak: 30 Days
Community Builder
Community Influencer
 
Joined: Aug 2002
Posts: 16,695
Likes: 1
From: Redacted
Default Block box banner ad and malware redirects

J T has asked about this before. I'm getting better at intercepting these before they actually do the redirect through adscore to the malvertising site.

I have a screen shot of what happens right before the redirect:


Old Sep 29, 2019 | 03:03 PM
  #10  
GCG's Avatar
GCG
Melting Slicks
10 Year Member
 
Joined: Jan 2009
Posts: 3,275
Likes: 739
From: Miami FL
Default

Originally Posted by larrysb
J T has asked about this before. I'm getting better at intercepting these before they actually do the redirect through adscore to the malvertising site.

I have a screen shot of what happens right before the redirect:...
Thank you for taking the time to do this

I would like to ask you, what do I need to add to my router to block this behavior? You mentioned it above in one of your posts, but could you please tell us exactly what needs to be written to blacklist it?

Thanks again!
Old Sep 29, 2019 | 03:48 PM
  #11  
J T's Avatar
J T
IB Staff
15 Year Member
Photogenic
Photoriffic
Shutterbug
 
Joined: Feb 2009
Posts: 10,573
Likes: 4
Default

Originally Posted by GCG
Thank you for taking the time to do this

I would like to ask you, what do I need to add to my router to block this behavior? You mentioned it above in one of your posts, but could you please tell us exactly what needs to be written to blacklist it?

Thanks again!
There is no easy answer to your question. Filtering on the router level, how you do so is going to vary greatly from one to the next due to all the different brands and models of routers out there. One can filter at the Windows PC level via localhost file. All this goes a bit beyond the scope of this website/forum. Feel free to PM or use Google with your specifics. Additionally, these types of concerns have been part of the Internet (like Spam) and so there is no one permanent solution as sources, strategies, etc., change.

That said, the teams were reviewing and discussing this (and other) material regarding this concern on Friday so the teams continue to address these concerns.
Old Sep 30, 2019 | 11:23 AM
  #12  
FN in MT's Avatar
FN in MT
Racer
 
Joined: Jul 2019
Posts: 490
Likes: 430
From: Cascade, Montana
Default

More "Your MAC is infected" pop ups again this past weekend and TODAY.
Old Sep 30, 2019 | 08:54 PM
  #13  
larrysb's Avatar
larrysb
Thread Starter
Race Director
20 Year Member
Active Streak: 30 Days
Community Builder
Community Influencer
 
Joined: Aug 2002
Posts: 16,695
Likes: 1
From: Redacted
Default

Router level blocking depends a lot on your router. I have a fairly mdoern Asus router, which allows for filtering on keywords in URLS.

You can, at least on MacOSX and Linux systems, edit the 'hosts' file on the system ( in /etc/hosts ).

However, I'm find that for some inexplicable reason, Safari resolves DNS different for HTTP vs HTTPS. It respects /etc/hosts for http, but not https. Who the heck knows why they did that.


I do NOT have an issue with advertisers!!! That' perfectly fine with me. Legitimate advertising is completely OK in my book.

I have a lot hatred for malvertising which is what all these pop-ups and redirects are all about. They're hijacking Internet Brands users to try and trick them into installing malware.

What happens is this:

Internet Brands contracts with ad-insertion providers and get paid for "impressions" and clicks through. There's a rotating banner ad at the top and bottom of the page. If you leave it sit, every few seconds a new banner pops up. These advertisers want to be sure they're not being ripped off with fake views by robots and what not, so they use bot detectors and browser fingerprinting services, like adscore.

The problem comes in when some unscrupulous outfit buys ad impressions and they encode the malware redirects into hidden things, like dummy images. They write little javascripts that decode the blocks, and then they bounce through the robot detection services (who are often on the shady side). The 'bot detection server is supposed to identify real browsers vs. bots and send them the real people a real ad, while sending the robots nothing. The legit purpose is to circumvent click robots.

But - adscore and others, are easily abused (and they don't try real hard not to be abusable) into fingerprinting your browser and redirecting you to a malware vector. That's why Macs get redirected to the "MacKeeper" a-holes, Androids get directed to the "..google user..." scam and Windows users will often get the "your PC is infected...." . All are malvertising and either trying to force-fish you into clicking a link or downloading something harmful to your computer or phone.

Honestly, if I were an exec at Internet Brands, this crap would be way up on my priority list. There is no purpose at all in whoring out your hard-earned users to malware vectors. It's like running a nice restaurant and inviting pick-pockets to wander around and steal what they can from your customers.
Old Sep 30, 2019 | 09:12 PM
  #14  
J T's Avatar
J T
IB Staff
15 Year Member
Photogenic
Photoriffic
Shutterbug
 
Joined: Feb 2009
Posts: 10,573
Likes: 4
Default

Originally Posted by larrysb
They're hijacking Internet Brands users to try and trick them into installing malware.
This (and these types of attacks) are not specific to Internet Brands' sites. Some have stated this is a "CorvetteForum only" issue or "Internet Brands only" issue when, even if that might be what the member sees due to the few websites they use on a daily basis versus the amount of actual websites online, that is not the case.

I would prefer this thread keep on topic for those who want to report they're seeing the issue, along with a screen capture, and please also provide your regional location if you're reporting the issue. Please keep the discussion of router blocking, software blocking, and management operations (use of ads, etc.,) to PMs or email as it technically doesn't follow our guidelines and it sidetracks this topic from being able to provide the assistance needed for the team to continue tracking the issue.

The team is actively working on this issue and some of the information from this thread and outside of CorvetteForum has given some leads in progress of the recent spam.

Thanks
Old Sep 30, 2019 | 10:33 PM
  #15  
larrysb's Avatar
larrysb
Thread Starter
Race Director
20 Year Member
Active Streak: 30 Days
Community Builder
Community Influencer
 
Joined: Aug 2002
Posts: 16,695
Likes: 1
From: Redacted
Default

True, it happens on other sites as well.
Old Oct 1, 2019 | 12:23 AM
  #16  
Greg's Avatar
Greg
Just another Corvette guy
Supporting Lifetime Gold
20 Year Member
 
Joined: Feb 1999
Posts: 8,518
Likes: 3,865
From: Palm Springs, CA.
Default

Larry,
Thanks for the in depth account of this plague. I seem to get a tsunami of it for a couple of days and then it disappears for a while. Only on my hand held, never on my home computer.
Have you been able to determine yet who the responsible party is?
Greg

Get notified of new replies

To CF Admins: More deep linking redirect attacks





All times are GMT -4. The time now is 04:09 PM.

story-0
Top 10 DOs and DON'Ts for Protecting Your Convertible Top!

Slideshow: How to Protect A Convertible Top: 10 DOs & DON'Ts

By Michael S. Palmer | 2026-04-03 00:00:00


VIEW MORE
story-1
Top 10 Most Explosive Corvettes Ever Made: Power-to-Weight Ratio Ranked!

Slideshow: The 10 most explosive Corvettes ever built based on power-to-weight ratio.

By Joe Kucinski | 2026-05-20 07:23:03


VIEW MORE
story-2
150 hp to 1,250 hp: Every Corvette Generation Compared by the Specs That Matter

Slideshow: From C1 to C8 we compare every Corvette generation by the numbers.

By Joe Kucinski | 2026-05-12 16:54:12


VIEW MORE
story-3
8 Coolest Corvette Pace Cars (and Replicas) of All Time

Slideshow: Some Corvette pace cars became collectible legends, while others perfectly captured the look and attitude of their era.

By Verdad Gallardo | 2026-05-11 09:50:51


VIEW MORE
story-4
Top 10 Corvette Engines RANKED by Peak Torque (70+ Years of Muscle!)

Slideshow: Ranking the top 10 Corvette engines by torque output.

By Joe Kucinski | 2026-05-05 11:58:09


VIEW MORE
story-5
Corvette ZR1X Will Be Pacing the Indy 500, And Could Probably Race, Too!

Slideshow: A Corvette pace car nearly matching IndyCar speeds sounds exaggerated, until you look at the numbers.

By Verdad Gallardo | 2026-05-04 20:03:36


VIEW MORE
story-6
Top 10 Corvettes Coming to Mecum Indy 2026!

Among a rather large group of them.

By Brett Foote | 2026-05-04 13:56:44


VIEW MORE
story-7
Top 10 C9 Corvette MUST-HAVES to Fix These C8 Generation Flaws!

Slideshow: the top 10 things Corvette owners want in the C9 Corvette

By Michael S. Palmer | 2026-04-30 12:41:15


VIEW MORE
story-8
10 Revolutionary 'Corvette Firsts' Most People Don't Know

Slideshow: 10 Important Corvette 'firsts' that every fan should know.

By Joe Kucinski | 2026-04-29 17:02:16


VIEW MORE
story-9
5 Reasons to Upgrade to an LS6-Powered Corvette; 5 Reasons to Stay LT2

Slideshow: Should you buy a 2020-2026 Corvette or wait for 2027?

By Michael S. Palmer | 2026-04-22 10:08:58


VIEW MORE