Go Back   FlyerTalk Forums > Support&Services > Technical Support and Feedback
Sign in using an external account

Reply
 
Thread Tools Search this Thread
Old Aug 1, 12, 10:17 am   #241
Internet Brands
 
Join Date: Oct 2007
Location: El Segundo CA
Programs: America Advantage
Posts: 112
We just blocked that url from all channels but it may take a few minutes to process. Please let me know if you keep seeing it.
__________________
Internet Brands
bconver is offline   Reply With Quote
Old Aug 1, 12, 10:26 am   #242
 
Join Date: Aug 2010
Posts: 123
Quote:
Originally Posted by Doug_1970 View Post
Good job.

Just for my academic interest, how hard was this to work out? Was it something that any competent IT person could work out, or was it more specialised?
Thanks

I have no formal IT training, but have always been fairly competent/keen to learn when it comes to IT. I have had some spare time this week and spent a while on this case. I cannot stress how much Google is your friend though.

Anyone with basic website (HTML/java) knowledge could have worked it out, the key though was being able to replicate the problem with a logger tracking all the traffic (the redirect happens within a split second). I found a logger (HTML Analyzer) last night which does exactly that, but couldn't replicate the problem. However, it happened today and I was able look through the history (which is quite in depth) and work back from the redirect site with the malware back to the FT forums.

I think the key thing I missed was the fact that the redirects were intermittent. Initially I mistakenly thought there was an exploit in the forum software as there have been problems previously on other forums being exploited. But the intermittent nature shows it was coming from something on the site that rotates (i.e. a banner/advert).

I would be interested to know how the bogus site was able to operate a banner here. There appears to be no track record of the company/site and the domain name owners have a whois block service so you don't know where they are from.
MoneyBagger is offline   Reply With Quote
Old Aug 1, 12, 11:07 am   #243
 
Join Date: May 2005
Posts: 2,042
Good work, MoneyBagger!

Any ideas on the purpose of the redirect? Is the purpose likely just to "sell" bogus virus-removal programs?
SkeptiCallie is offline   Reply With Quote
Old Aug 1, 12, 11:34 am   #244
 
Join Date: Aug 2010
Posts: 123
Quote:
Originally Posted by SkeptiCallie View Post
Good work, MoneyBagger!

Any ideas on the purpose of the redirect? Is the purpose likely just to "sell" bogus virus-removal programs?
Essentially yes. Here's how it works:

http://www.f-secure.com/weblog/archives/00002053.html
http://www.pcworld.com/businesscente...ssentials.html
http://blogs.technet.com/b/mmpc/arch...ake-innit.aspx

There are some good online sites which you can use to check if a site is legitimate or infected:

http://www.virustotal.com/ - Online virus scanner/site checker
http://urlquery.net/ - Site Scanner
http://www.unmaskparasites.com/ - Site Scanner
http://zulu.zscaler.com/ - Site scanner/inspector
http://www.avgthreatlabs.com/sitereports/ - Site scanner (part of AVG)
MoneyBagger is offline   Reply With Quote
Old Aug 1, 12, 12:06 pm   #245
 
Join Date: Aug 2010
Location: LGA - JFK
Programs: UA, AA, DL, B6 & CX, Latitude, Crown & Anchor
Posts: 1,009
Quote:
Originally Posted by MoneyBagger View Post
Essentially yes ... There are some good online sites which you can use to check if a site is legitimate or infected:
Bravo, kudos & thanks to MoneyBagger for helping FT and rest of us - some of us knew something just isn't right ... Using Firefox on my own laptop now but when on the road, it isn't a matter of choice to avoid or not use IE 8 or 9.

When we had similar issues & popups randomly over at Cruisecritic dot com, it drove some of us nuts for weeks - and it was tracked down only a few weeks ago (the details & threads/links are mostly gone/deleted & no longer available to members) - my best recollection of the summary finding was that it was malware codes/scripts hidden in graphics/logos commonly used by CC members, and it got in & launched itself - very similiar MSE phony threat reports and offering to fix it (as we've saw them here on FT.)

Furthermore, the danger and risks pose is that, one's credit card/names & other personal info were exposed in the course of purchasing/authorizing/downloading the said "fixes" in solving the security problem - escalating and potential risking hundreds if not thousands in charges to one's CC account.

The practice goes back to the 1980's when we're surfing AOL and bragging about 56K modems - we've come a long way but the bad apples are still out there, and getting more sophisticated. My firewall, antivirus & spyware logs and reports all looked clean, deep & full scanning sweeps done showing no harm inflicted thus far, yet (fingers crossed )

Last edited by Letitride3c; Aug 2, 12 at 10:51 pm..
Letitride3c is online now   Reply With Quote
Old Aug 1, 12, 12:39 pm   #246
 
Join Date: May 2005
Posts: 2,042
Quote:
Originally Posted by MoneyBagger View Post
Essentially yes. Here's how it works:

http://www.f-secure.com/weblog/archives/00002053.html
http://www.pcworld.com/businesscente...ssentials.html
http://blogs.technet.com/b/mmpc/arch...ake-innit.aspx

There are some good online sites which you can use to check if a site is legitimate or infected:

http://www.virustotal.com/ - Online virus scanner/site checker
http://urlquery.net/ - Site Scanner
http://www.unmaskparasites.com/ - Site Scanner
http://zulu.zscaler.com/ - Site scanner/inspector
http://www.avgthreatlabs.com/sitereports/ - Site scanner (part of AVG)
Thanks for the answer.

This whole matter did get me to download the real MSE yesterday. A quick scan shows no problem. Also, Malwarebytes' Anti-Malware shows no problem.
SkeptiCallie is offline   Reply With Quote
Old Aug 1, 12, 8:47 pm   #247
 
Join Date: Apr 2007
Location: SEA
Programs: Hhonors Gold, National Executive, Grazie Gold, Identity Platinum
Posts: 1,746
Quote:
Originally Posted by Letitride3c View Post
Bravo, kudos & thanks to MoneyBagger for helping FT and rest of us
OverThereTooMuch is offline   Reply With Quote
Old Aug 2, 12, 12:41 am   #248
Community Director
 
Join Date: Oct 2000
Location: Anywhere warm
Posts: 21,514
Thank you, MoneyBagger.
SanDiego1K is offline   Reply With Quote
Old Aug 2, 12, 2:45 am   #249
uk1
 
Join Date: Jan 2004
Location: UK
Posts: 8,207
Well done.
uk1 is offline   Reply With Quote
Old Aug 2, 12, 4:57 am   #250
 
Join Date: Jul 2012
Posts: 21
Well done MoneyBagger!! :0) As someone else said IT should have picked up on this ages ago!
Jay2261 is offline   Reply With Quote
Old Aug 2, 12, 8:12 am   #251
 
Join Date: Jun 2003
Location: Denver CO
Programs: HHonors Gold, National Emerald Club, no airline affinity status
Posts: 1,003
Moneybagger, thanks for the information. Job well done. Hopefully FT recognizes you appropriately.
__________________
Insert witty quote or website here ---->
HawaiiTrvlr is offline   Reply With Quote
Old Aug 2, 12, 4:39 pm   #252
Administrator
 
Join Date: Mar 2011
Location: Los Angeles, CA
Posts: 1,010
Thumbs up

Quote:
Originally Posted by HawaiiTrvlr View Post
Moneybagger, thanks for the information. Job well done. Hopefully FT recognizes you appropriately.
Indeed
IBobi is offline   Reply With Quote
Old Aug 3, 12, 3:46 pm   #253
 
Join Date: Jun 2012
Location: England
Programs: Executive Club Silver
Posts: 614
The warning hasn't appeared so far so it looks like Money has solved the mystery.

If it weren't for you I doubt this issue would have ever been resolved. I hope too many people weren't put off visiting the site because of it.
PotNoodle is offline   Reply With Quote
Old Aug 3, 12, 4:07 pm   #254
 
Join Date: Apr 2009
Posts: 83
Have not had a recurrence today yet....
g-didi is offline   Reply With Quote
Old Aug 3, 12, 6:18 pm   #255
 
Join Date: Mar 2010
Programs: AA Plat, Marriott Plat
Posts: 689
Finally, someone with mad skillz. Now if you could only become a moderator to help us out...
living near shamu is offline   Reply With Quote
 
 
Reply

Bookmarks


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off
Forum Jump


All times are GMT -6. The time now is 9:04 am.




SEO by vBSEO ©2011, Crawlability, Inc.