LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > LinuxQuestions.org > LQ Suggestions & Feedback
User Name
Password
LQ Suggestions & Feedback Do you have a suggestion for this site or an idea that will make the site better? This forum is for you.
PLEASE READ THIS FORUM - Information and status updates will also be posted here.

Notices


Reply
  Search this Thread
Old 07-24-2007, 01:09 AM   #1
blackhole54
Senior Member
 
Registered: Mar 2006
Posts: 1,896

Rep: Reputation: 61
LQ Safe from malicious Java Script uploads?


Once again there is news of the problems that can be caused by malicious java script. This is particularly of concern on sites that allows users to upload content. (And, in fact, maybe about a year ago, Yahoo had problems with this very thing.) Normally I leave Java Script disabled; LQ is one of the few sites I enable it for because it makes the editing of posts so much more sane. So I just want to double check that LQ does what is necessary to make sure that functional Java Script cannot be uploaded by users. Within this question (and something I don't know due to my lack of HTML knowledge) is whether when sombody posts Java Script (within code tags or not) whether there is any way a browser might end up executing it.

For the record, prior to posting this, I searched this thread for Java Script, and ended up reading the entire thread from last year about the pop up issues. I could not find that this issue has been specifically addressed before.
 
Old 07-24-2007, 02:38 AM   #2
AceofSpades19
Senior Member
 
Registered: Feb 2007
Location: Chilliwack,BC.Canada
Distribution: Slackware64 -current
Posts: 2,079

Rep: Reputation: 58
I doubt Jermey would let malicious javascript uploads on this site
 
Old 07-24-2007, 04:01 AM   #3
blackhole54
Senior Member
 
Registered: Mar 2006
Posts: 1,896

Original Poster
Rep: Reputation: 61
Quote:
Originally Posted by AceofSpades19
I doubt Jermey would let malicious javascript uploads on this site
I am sure it would not be intentional. As I said, Yahoo got caught with their pants down and I just wanted to make sure it is something that has been thought about here.
 
Old 07-24-2007, 10:45 AM   #4
jeremy
root
 
Registered: Jun 2000
Distribution: Debian, Red Hat, Slackware, Fedora, Ubuntu
Posts: 13,600

Rep: Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083
We do everything we possibly can to prevent things like what you are describing. The issue in the thread you linked to was a client issue and unrelated to LQ.

--jeremy
 
Old 07-27-2007, 03:05 PM   #5
berbae
Member
 
Registered: Jul 2005
Location: France
Distribution: Arch Linux
Posts: 540

Rep: Reputation: Disabled
The problem which is described in the second link of the OP about the pop up issue, happened twice on my machine since yesterday.
It is as described in the link
My machine runs Arch Linux, not Windows.
And it happens only when I visit the LQ site.
It's very annoying because the LQ page disappears and is not available again until Firefox is restarted. Before that, nothing can be done with the browser because it is hijacked by the spurious site (even the window size where the browser stands is changed).
I cannot but think that it is related with something at the LQ site.
Can somebody search for a possible cause please ?
It's the first time since I run Linux on my machine that something like that happens, it reminds me of the Windows vulnerabilities when surfing the Web.
 
Old 07-27-2007, 03:29 PM   #6
XavierP
Moderator
 
Registered: Nov 2002
Location: Kent, England
Distribution: Debian Testing
Posts: 19,192
Blog Entries: 4

Rep: Reputation: 475Reputation: 475Reputation: 475Reputation: 475Reputation: 475
Which page? In all of the time that I have been visiting LQ I have never seen this. Can you get the URL for the ad?
 
Old 07-27-2007, 03:50 PM   #7
jlliagre
Moderator
 
Registered: Feb 2004
Location: Outside Paris
Distribution: Solaris 11.4, Oracle Linux, Mint, Debian/WSL
Posts: 9,789

Rep: Reputation: 492Reputation: 492Reputation: 492Reputation: 492Reputation: 492
I have been hit by the very same malware yesterday night.
Brand new O/S installation (Solaris Express build 66 + Firefox 2.0.0.3).
The only site visited before LQ were the Firefox Google welcome page then a google search.
While browsing LQ, I was redirected to that URL (found in Firefox history):
http://
fr.errorsafe.com
/pages/scanner/index.php?ax=1&ex=1&ed=2&aid=which95k_rdt&lid=intl&affid=&mpt=[CACHEBUSTER]
 
Old 07-27-2007, 04:19 PM   #8
colucix
LQ Guru
 
Registered: Sep 2003
Location: Bologna
Distribution: CentOS 6.5 OpenSuSE 12.3
Posts: 10,509

Rep: Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983
Me too. It happened three times in the last two days and only when I was browsing the LQ site. Next time I will log and post all the relevant information, if this can help to go deep inside the question.

Last edited by colucix; 07-27-2007 at 04:21 PM.
 
Old 07-27-2007, 05:04 PM   #9
XavierP
Moderator
 
Registered: Nov 2002
Location: Kent, England
Distribution: Debian Testing
Posts: 19,192
Blog Entries: 4

Rep: Reputation: 475Reputation: 475Reputation: 475Reputation: 475Reputation: 475
I wonder if an ad has either been compromised (they all come from third party providers) or if an ad has been coded to do this. Just an idea.

I can say, with all confidence, that this is nothing of Jeremy's doing and if my ideas are correct, he will kill the ads.
 
Old 07-27-2007, 05:21 PM   #10
colucix
LQ Guru
 
Registered: Sep 2003
Location: Bologna
Distribution: CentOS 6.5 OpenSuSE 12.3
Posts: 10,509

Rep: Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983
Yes, I agree. I never thought it could be caused from Jeremy's doing. I wonder how can it happen, but unfortunately I am not an expert in these issues.
 
Old 07-28-2007, 10:42 AM   #11
jeremy
root
 
Registered: Jun 2000
Distribution: Debian, Red Hat, Slackware, Fedora, Ubuntu
Posts: 13,600

Rep: Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083
I've not seen this happen, but any additional information that will help me track down if it's LQ ad server related would be appreciated. We will work to kill the ad ASAP if it did sneak in somehow.

--jeremy
 
Old 07-28-2007, 03:44 PM   #12
berbae
Member
 
Registered: Jul 2005
Location: France
Distribution: Arch Linux
Posts: 540

Rep: Reputation: Disabled
It happened again to-night just before this post.
I enter LQ directly at the forum page and I didn't click anything before the problem occurred.
The site responsible for the hijacking is saved in the Firefox history as
h..p://www.drivecleaner.com/.freeware/?p=56&ax=1&ex=1&ed=2&aid=which95k&lid=intl&affid=&aid=which95k&mpt=[CACHEBUSTER]&aid=which95k_rdt
('h..p' is for 'http' for preventing the url tags)
I cannot identify which ad may cause that because the browser is pushed out of the LQ site before I could see anything.
I think it may be caused by one of the ads, as it doesn't happen every times.
Edit: I'm now sure that this is from a javascript execution, because I had allowed scripts to move or resize existing windows in the Firefox preferences options. And that is what happened.

Last edited by berbae; 07-28-2007 at 04:10 PM.
 
Old 07-28-2007, 05:23 PM   #13
colucix
LQ Guru
 
Registered: Sep 2003
Location: Bologna
Distribution: CentOS 6.5 OpenSuSE 12.3
Posts: 10,509

Rep: Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983
Similar behaviour just happen to me again. I have just started to navigate the LQ site and the pop-up has shown again (always the same for me but different from those reported above). In detail: the browser resize to a little square windows (about 1 inch) and a pop-up appear with the following message
Quote:
The page at h..p://amaena.com says:
NOTICE: If your computer has been running slower than normal, it may be infected with Viruses, Adware or Spyware.
WinAntiVirus PRO can perform a quick and completely FREE scan of your system for malicious programs.
Download WinAntiVirus PRO FREE now!
I can take any action and the browser resize again to the maximum screen size and connect to the URL h..p://amaena.com/securityworm58/index.php?aid=which95k_rdt_it_en_ed2&lid=intl&affid=&ax=1&p=&ex=1&h=0&j=0
Again I can take any action (this time I tried to reconnect to LQ from my bookmarks) and a new pop-up appears:
Quote:
The page at h..p://amaena.com says:
NOTICE: You have not completed viruses and spyware scan. If your computer has viruses, spyware and adware trojans, it can cause your private and billing information leaks, unpredictable or erratic system behaviour, freezes, crashes or permanent damage to your PC.
WinAntiVirus PRO can perform a quick and completely FREE scan of your system for viral and spyware infections.
Would you like WinAntiVirus PRO to scan for and, if found, remove any malicious software now? (Recommended)
If I close the pop-up, the browser goes under my control again and can reconnect to LQ following my previous request. It does not seems so malicious, but undoubtfully is very annoying! I know these informations are not valuable to figure out where the problem resides. If you need some info from my system, as the system log, I will provide them. Thank you and sorry for the long post.
 
Old 07-28-2007, 06:08 PM   #14
jeremy
root
 
Registered: Jun 2000
Distribution: Debian, Red Hat, Slackware, Fedora, Ubuntu
Posts: 13,600

Rep: Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083
Is this happening only on specific pages? I'm completely unable to replicate this or find any indication that it's coming from LQ at this time. We only use two ad providers and both of them have been extremely reliable in the past. Only one (Google) allows for arbitrary ad placement, but they do not allow javascript at all. The one commonality I see here is the "which95k" string. Any additional information will help.

--jeremy
 
Old 07-29-2007, 03:51 PM   #15
jeremy
root
 
Registered: Jun 2000
Distribution: Debian, Red Hat, Slackware, Fedora, Ubuntu
Posts: 13,600

Rep: Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083Reputation: 4083
An update: The culprit here has potentially been tracked down. It was not directly related to LQ itself, but rather an aberrant ad. We'll be working with our ad provider to ensure this doesn't happen again. Thanks for the patience. Your security and privacy are extremely important to us and I'm happy to say that neither were impacted in this case. We do apologize for the annoyance.

--jeremy
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
malicious script in tmp - (cpanel/fc4) ddaas Linux - Security 6 09-25-2017 05:01 PM
Is this firewall script safe? eponymous Linux - Security 26 01-20-2007 06:00 PM
Wanted: Batch Email Script for Snapfish photo-uploads mpm Linux - Software 1 05-28-2006 11:48 PM
Malicious Script jspsandhu Linux - General 12 09-29-2005 05:05 PM
safe script parameters Guttorm Programming 1 03-04-2005 12:19 PM

LinuxQuestions.org > Forums > LinuxQuestions.org > LQ Suggestions & Feedback

All times are GMT -5. The time now is 06:07 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration