LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-29-2010, 02:43 AM   #1
phantompgr
Member
 
Registered: Sep 2002
Location: South Wales, UK
Distribution: Fedora Core & Mandrake
Posts: 83

Rep: Reputation: 15
firefox redirection oddity


Morning people,

Had a phone call from my Mum last night. She is running Mandriva 10 on her laptop, connected wirelessly to a router. Other Windows computers sit on the internal network.

She has found that when loading firefox in the last couple of days, clicking on her google bookmark redirects her to AssociationVoice dot com. Also, the general network speed of her browser has slowed. I thought she was going through a proxy so I asked her (over the phone) to bring up her firefox proxy settings. This were set to the default option of "Use system proxy settings" so she changed it to "connect directory". This seemed to sort the problem as google would then load when entering it in the addressbar or clicking her boookmark.

However, my concern is that either firefox or her computer has been compromised. I cannot quiet believe it is her computer since she is running Mandriva rather than Windows, keeps it updated and does not generally surf for anything dodgy. Still, the possibility remains. Has anyone seen this behaviour before? I am going to see her tonight so will have a chance to poke around further.

She is not very computer savvy but likes to research on the internet on various historical sites. The redirect behaviour seems to tally with her deciding to play Patience online (KPatience is installed but she didnt know that) so picked the first google listing she came to. The site had music playing, flash game etc... Whether this was the cuplrit for changing the proxy settings on her machine, I have no idea but seems the only likely possibility.

The problem appears at this moment to be confined to her laptop. Other computers connect to google etc... without any issues.

Any thoughts would be much appreciated.

Cheers

phantomjinx
 
Old 04-29-2010, 07:58 PM   #2
disturbed1
Senior Member
 
Registered: Mar 2005
Location: USA
Distribution: Slackware
Posts: 1,133
Blog Entries: 6

Rep: Reputation: 224Reputation: 224Reputation: 224
Inadvertent installation of some plugin or add on. It's not impossible for these to be cross platform. After all, I've seen Microsoft targeted infections attempting an installation through Firefox on Linux.

Install ad block and no-script. Shameful that many sites rely on adverts for income - too bad the advertising agencies don't have enough scruples to insure the safety of the customer. Some sites do have safe ads. LQ is on my safe list
 
Old 04-30-2010, 06:35 AM   #3
phantompgr
Member
 
Registered: Sep 2002
Location: South Wales, UK
Distribution: Fedora Core & Mandrake
Posts: 83

Original Poster
Rep: Reputation: 15
I am afraid this took a turn for the worst last night and today. First, some minor facts.

Firefox is a 3.6 version (Mandriva latest rpm update)
Extensions installed are noScript, Adblock+ and KDE's plasma notify.
Plugins installed are flash and totem.
Laptop is wirelessly connected to BT home hub downstairs.

I emptied the cache, history etc... and set these to be dumped upon exiting of the browser.

The problem sporadically occurs. I think it seems to be when the wireless signal is particularly weak. The reason for this is that the redirection occurred for me as Mum walked into the room (maybe blocking the signal). It is irrelevant which webpage I clicked on as all her boookmarks usually redirected back to this one site. However, few seconds later and clearing the cache, things were fine.

I say usually as occasionally an IIS status screen would appear instead showing that the given webpage was missing. Kind of like a page missing in a cache. This was external since it was IIS but also showed the directory of the cached page to be D:\Web... (cannot remember the full path).

So I thought all this may be DNS hijacking of some kind so I have changed the DNS settings of the laptop to openDNS servers to see if that would make a difference. So far so good.

This morning...

My father received a call from a gentleman claiming to be from BT who had noted a problem in their region concerning google redirects and had a patch that would fix the problem. Dad said he would phone me and I would call the guy back. Of course, I rang BT who confirmed the call was fraudulent. Now I want to know how they got my parent's phone number.

My father surfs the internet with Mandriva same as my Mother. However, he does have a dual booted computer (Windows). Assuming for instance, the Windows partition was compromised, how would it be possible to compromise the networking/router. I just cannot believe linux is the source of the attack vector, especially since konqueror did not show any of this behaviour last night.

Getting a little worried now....

Thanks

phantomjinx
 
Old 04-30-2010, 07:02 AM   #4
disturbed1
Senior Member
 
Registered: Mar 2005
Location: USA
Distribution: Slackware
Posts: 1,133
Blog Entries: 6

Rep: Reputation: 224Reputation: 224Reputation: 224
Sounds quite similar to the following.
http://www.dslreports.com/shownews/A...Results-108155
 
Old 04-30-2010, 07:31 AM   #5
phantompgr
Member
 
Registered: Sep 2002
Location: South Wales, UK
Distribution: Fedora Core & Mandrake
Posts: 83

Original Poster
Rep: Reputation: 15
Interesting. Thanks for the link.

Seems the phone call might have been a coincidence since this is very close to a scareware scam that is on the rise in the UK at the moment.

phantompgr
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
A strange Ubuntu 9.10 Karmic Koala/Firefox 3.5 cursor oddity/bug...? lupusarcanus Linux - Software 2 02-28-2010 10:31 AM
block firefox automatic redirection bong.mau Linux - Software 2 06-09-2006 03:07 PM
Firefox Profile redirection and usage johnnybhoy67 Linux - Software 4 02-27-2006 12:21 PM
More of an oddity than a problem... Neowulf Linux - Newbie 3 11-09-2005 04:49 PM
Gnome 2.8 Oddity inescapeableus Linux - Software 2 01-10-2005 03:00 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:32 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration