The Naked Scientists
  • Login
  • Register
  • Podcasts
      • The Naked Scientists
      • eLife
      • Naked Genetics
      • Naked Astronomy
      • In short
      • Naked Neuroscience
      • Ask! The Naked Scientists
      • Question of the Week
      • Archive
      • Video
      • SUBSCRIBE to our Podcasts
  • Articles
      • Science News
      • Features
      • Interviews
      • Answers to Science Questions
  • Get Naked
      • Donate
      • Do an Experiment
      • Science Forum
      • Ask a Question
  • About
      • Meet the team
      • Our Sponsors
      • Site Map
      • Contact us

User menu

  • Login
  • Register
  • Home
  • Help
  • Search
  • Tags
  • Member Map
  • Recent Topics
  • Login
  • Register
  1. Naked Science Forum
  2. Non Life Sciences
  3. Geek Speak
  4. Where is the redirection to a scam site occurring?
« previous next »
  • Print
Pages: [1]   Go Down

Where is the redirection to a scam site occurring?

  • 7 Replies
  • 7516 Views
  • 0 Tags

0 Members and 1 Guest are viewing this topic.

Offline Igor (OP)

  • Full Member
  • ***
  • 59
  • Activity:
    0%
    • View Profile
Where is the redirection to a scam site occurring?
« on: 07/06/2011 09:02:50 »
I posted a link in a forum to a legitimate long-established website.
When people click on that link in the forum sometimes they are redirected to a fake anti-virus scam.


* redirected to scam  URL.png (59.44 kB . 800x102 - viewed 5016 times)

Where is the hijack occurring ?, in the forum where I posted the link or the legitimate website ?.

(the website is run by computer literate individuals, the forum is run by computer novices) 
« Last Edit: 15/08/2018 23:13:05 by chris »
Logged
 
 



Offline CliffordK

  • Naked Science Forum King!
  • ******
  • 6596
  • Activity:
    0.5%
  • Thanked: 59 times
  • Site Moderator
    • View Profile
Re: Where is the redirection to a scam site occurring?
« Reply #1 on: 07/06/2011 10:15:11 »
I am assuming this has happened to several people, and not just to you.

Is this the only link on the BBS that does this?

If many links on the BBS do the same thing, then it would be the BBS.

If this is the only link on the BBS that takes you to the fake site, then it would be specific to the link.

Carefully review the link to the "legit" website to make sure that it is NOT actually a link to a 3rd party intermediary website.

If the link is correct, then I'd be looking at the "legit" website for problems, and make sure they also run a battery of antivirus/antispyware programs.

I would encourage you to verify that your own antivirus is up to date.  And, also run a battery of antispyware on your computer. 

There are some suggestions here:
http://www.thenakedscientists.com/forum/index.php?topic=38107.0
Logged
 

Offline Igor (OP)

  • Full Member
  • ***
  • 59
  • Activity:
    0%
    • View Profile
Re: Where is the redirection to a scam site occurring?
« Reply #2 on: 07/06/2011 11:57:45 »
Quote from: CliffordK on 07/06/2011 10:15:11
I am assuming this has happened to several people, and not just to you.

Yes, apparently only Internet Explorer users.  The redirection is intermittent, approx 1 time in 5, i.e. approximately 4 out of 5 times the link works correctly.

Quote from: CliffordK on 07/06/2011 10:15:11
Is this the only link on the BBS that does this?

Don’t know, I have not tried other links on that forum : (I don’t fancy playing any more Russian roulette today).

« Last Edit: 07/06/2011 12:01:02 by Igor »
Logged
 
 

Offline CliffordK

  • Naked Science Forum King!
  • ******
  • 6596
  • Activity:
    0.5%
  • Thanked: 59 times
  • Site Moderator
    • View Profile
Re: Where is the redirection to a scam site occurring?
« Reply #3 on: 07/06/2011 12:40:34 »
Quote from: Igor on 07/06/2011 11:57:45
Quote from: CliffordK on 07/06/2011 10:15:11
I am assuming this has happened to several people, and not just to you.
Yes, apparently only Internet Explorer users.  The redirection is intermittent, approx 1 time in 5, i.e. approximately 4 out of 5 times the link works correctly.
Interesting observation.

You know, I haven't had a website pop up and tell me that my computer was infected by a virus since I rid myself of all Microsoft Software.

It kind of makes you think what the virus might have been!!!

Actually, I'm now getting a little curious.

Post (or send me a PM)
with all 3 websites.
The BBS where the link is posted.
The intended link.
The place it sends you.
Logged
 

Offline Igor (OP)

  • Full Member
  • ***
  • 59
  • Activity:
    0%
    • View Profile
Re: Where is the redirection to a scam site occurring?
« Reply #4 on: 07/06/2011 13:13:41 »
Quote
The BBS where the link is posted.

The forum thread has now been deleted to prevent others falling into the booby trap.

Quote
The place it sends you.

Partial URL of the redirect is attached to the first post. It’s a fake antivirus scan scam.
Most of the time the link works correctly rather than being redirected.

Thanks for your interest Clifford. It does seem that it is the (amateur) forum which has been compromised rather than the website I linked to which is run by IT pros.


* fake anti-virus warning (scam).png (7.73 kB, 413x165 - viewed 766 times.)
« Last Edit: 07/06/2011 13:24:00 by Igor »
Logged
 
 



Offline RD

  • Naked Science Forum GOD!
  • *******
  • 9094
  • Activity:
    0%
  • Thanked: 161 times
    • View Profile
Re: Where is the redirection to a scam site occurring?
« Reply #5 on: 07/06/2011 23:32:09 »
Quote
"we recommend you to check your system immediately"

Grammarians would have spotted that was bogus.
« Last Edit: 07/06/2011 23:52:56 by RD »
Logged
 

Offline chris

  • Naked Science Forum King!
  • ******
  • 7985
  • Activity:
    1.5%
  • Thanked: 285 times
  • The Naked Scientist
    • View Profile
    • The Naked Scientists
Re: Where is the redirection to a scam site occurring?
« Reply #6 on: 15/08/2018 23:12:31 »
Old thread, I know, but I chanced upon it and thought I'd revive it because it might prove helpful to someone.

The symptom described above looks like what's called a "watering hole" attack; fraudsters compromise a server and replace existing code or add malicious scripts that are called when some or all of the site webpages care called.

The inserted code adds a handler to the affected pages that can do several things: sometimes it bounces people on to another target - like a product page for something someone is selling - from the original page; another one I have seen tells people that they need a security update for their browser and offers the download link; it looks deceptively like a real chrome update screen; people then click the link in good faith and supply their admin password, running the hacker's executable, which then modifies the client machine and grants the hacker a back door in.

The people who do this are bloody crafty. One attack  saw involved over-writing a single javascript file on an installation with a new version of the file that contained one extra line of script. This grabbed the content that was being inserted into the generated webpages from a third party site, making the affected file that was doing the naughty behaviour much harder to track down.

The moral of the story - lock it or lose it!

 
Logged
I never forget a face, but in your case I'll make an exception - Groucho Marx - https://www.thenakedscientists.com/
 

Offline nicephotog

  • Sr. Member
  • ****
  • 448
  • Activity:
    0%
  • Thanked: 11 times
  • [ censored ]
    • View Profile
Re: Where is the redirection to a scam site occurring?
« Reply #7 on: 14/02/2019 02:24:52 »
Possibly done by "cookie poisoning" whether javascript called and placed or server side cookies.
(nb: interesting note, there is such a things as a "literal cookie header" but usually requires the server output stream STDOUT to be edited and written into before the head section of an HTML page or the HTML page itself , the rules for it cam be found in one of the IETF RFC's for internet  https://www.ietf.org/standards/rfcs/ )
HOWEVER, free sites or such as forums where the user is a non paying member, some advertising is permissible.
That old adage "nuthins ever free bud" !
« Last Edit: 14/02/2019 02:29:08 by nicephotog »
Logged
How To Tutorial (all Java servers) HttpOutPutTools (port to .jar Hell Pig Entelodont) 7th January 2022
https://drive.google.com/file/d/1gbz54O8aOUEFOdRa40ZlRM7AtpS4Uj_C/view?usp=sharing
 



  • Print
Pages: [1]   Go Up
« previous next »
Tags:
 

Similar topics (5)

Can we rewind the expansion of the Universe to pinpoint the site of the Big Bang?

Started by thedocBoard Physics, Astronomy & Cosmology

Replies: 2
Views: 3862
Last post 31/01/2014 17:52:22
by Bill S
Victim of an Adult Site Blackmail Email Hoax?

Started by chrisBoard Geek Speak

Replies: 41
Views: 27390
Last post 28/01/2022 17:00:19
by chris
What is the Trinity Nuclear Test site like today?

Started by thedocBoard The Environment

Replies: 5
Views: 8489
Last post 23/07/2010 02:03:42
by LeeE
Interesting site for maths freaks

Started by DoctorBeaverBoard General Science

Replies: 4
Views: 4225
Last post 22/02/2006 01:50:45
by Solvay_1927
Why couldn't they find the site of the crash?

Started by lynerBoard Technology

Replies: 20
Views: 13381
Last post 09/06/2009 20:36:46
by LeeE
There was an error while thanking
Thanking...
  • SMF 2.0.15 | SMF © 2017, Simple Machines
    Privacy Policy
    SMFAds for Free Forums
  • Naked Science Forum ©

Page created in 0.188 seconds with 55 queries.

  • Podcasts
  • Articles
  • Get Naked
  • About
  • Contact us
  • Advertise
  • Privacy Policy
  • Subscribe to newsletter
  • We love feedback

Follow us

cambridge_logo_footer.png

©The Naked Scientists® 2000–2017 | The Naked Scientists® and Naked Science® are registered trademarks created by Dr Chris Smith. Information presented on this website is the opinion of the individual contributors and does not reflect the general views of the administrators, editors, moderators, sponsors, Cambridge University or the public at large.