LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-28-2007, 10:25 AM   #1
r00ster
Member
 
Registered: May 2007
Location: boundary beach, bc
Distribution: 3.2.0-4-686-pae #1 SMP Debian 3.2.60-1+deb7u3 i686 GNU/Linux
Posts: 224

Rep: Reputation: 15
ActiveX FFox Hijack


Deb Etch/KDE/Iceweasel
Stand alone DT

I've been unable to stop/interdict the following message in my Iceweasel Browser, even after restarts. I didn't get any warning that it might be an unsafe site: I was looking for instances of allergic responses to certain cosmetics. i.e., "Body Shop" scented oils for the bathroom.

"The page @ http://the moviesite.com says:
Video ActiveX Object Error. Your browser cannot play this image file. Click [OK] to download and install missing ActiveX Object".

It seems to be trying to access:
http://82.103.87.14/download/502/919/0/

How do I 'kill' this connection without downloading it?

The Icedove (Firefox) pid is 3951 "firefox-bin".
Do I just enter "# kill 3951" as root? Or is there a more appropriate command?

Happy trails,

r

Last edited by r00ster; 12-29-2007 at 02:17 AM. Reason: clarification
 
Old 12-29-2007, 03:22 AM   #2
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by r00ster View Post
I've been unable to stop/interdict the following message in my Iceweasel Browser, even after restarts. I didn't get any warning that it might be an unsafe site: I was looking for instances of allergic responses to certain cosmetics. i.e., "Body Shop" scented oils for the bathroom.

"The page @ http://the moviesite.com says:
Video ActiveX Object Error. Your browser cannot play this image file. Click [OK] to download and install missing ActiveX Object".
That themoviesite.com site looks to me like some wannabe-cybersquatter's site. You can sort of tell just by looking at it, but additionally - at the time of this post - Google doesn't show any links to it, and SiteAdvisor doesn't have it in its database. Also, the coding really sucks.

Quote:
The Icedove (Firefox) pid is 3951 "firefox-bin".
Do I just enter "# kill 3951" as root? Or is there a more appropriate command?
Yeah, if you browser froze or something, you could kill it. But you don't need to be root for this. Just issue the kill+PID command as the user which the browser is running as. I typically just do a:
Code:
killall firefox-bin
(I had to do this frequently when using older versions of the Flash plugin.)

PS: I didn't get any prompts like that when I went to the site, but I've got NoScript enabled and have no plans on disabling it for a site like that.

Last edited by win32sux; 12-29-2007 at 03:27 AM.
 
Old 12-29-2007, 04:32 AM   #3
r00ster
Member
 
Registered: May 2007
Location: boundary beach, bc
Distribution: 3.2.0-4-686-pae #1 SMP Debian 3.2.60-1+deb7u3 i686 GNU/Linux
Posts: 224

Original Poster
Rep: Reputation: 15
Win32;

Thanks a bunch. That's the first time I've encountered this kind of installation imperative in linux. Some of the reading I did prior to posting suggests this is beginning to occur more frequently.

I'm not sure just which entry I clicked on in google, but the search involved "Allergic Reactions Doxycycline". Funny place to stick a tick; but then these goofs will do what they will.

Happy New Year;

r
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
FC5 - Ffox 1.5.0.7 Java and Fash not working polemon Fedora 4 10-08-2006 04:54 PM
how to hijack a browser (legally) kscott121 Linux - Networking 2 08-19-2006 06:43 PM
Browser hijack from the LQ website bernied LQ Suggestions & Feedback 37 07-10-2006 02:17 AM
Using Downlaod Manager(kGet) with FFox nuka_t Linux - Software 2 09-25-2004 01:53 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:59 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration