LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-25-2015, 12:55 AM   #1
telemeister
Member
 
Registered: Dec 2007
Location: Brisbane Australia
Distribution: Slackware
Posts: 63

Rep: Reputation: 16
Firefox / seamonkey being 'hijacked' by optus.com.au


Running Slackware 14.1 on my home machine, with Firefox browser.
When I go to one particular site (Open Webmail server for my work email), as soon as I log in the session is 'hijacked' and I end up on an unrelated site (basically an ad for optus australia).

http://www.optus.com.au/

I have never voluntarily gone to that site.

If I try again to get to my webmail, same thing happens.

If I delete my ~/.mozilla directory I can then get to my mail
for a while. Then it all happens again.

Same thing with Seamonkey.

Appreciate any suggestions as to how I can investigate further or block this.

Thanks

Steve
 
Old 04-25-2015, 02:34 AM   #2
allend
LQ 5k Club
 
Registered: Oct 2003
Location: Melbourne
Distribution: Slackware64-15.0
Posts: 6,367

Rep: Reputation: 2748Reputation: 2748Reputation: 2748Reputation: 2748Reputation: 2748Reputation: 2748Reputation: 2748Reputation: 2748Reputation: 2748Reputation: 2748Reputation: 2748
I have no problem with Optus webmail using this https://webmail.optusnet.com.au
You are aware that the old mail web address was made defunct and replaced with the one above near the end of March this year? You may be experiencing some redirect arising from this.
 
Old 04-25-2015, 06:42 AM   #3
telemeister
Member
 
Registered: Dec 2007
Location: Brisbane Australia
Distribution: Slackware
Posts: 63

Original Poster
Rep: Reputation: 16
My webmail has got nothing to do with Optus.

It is Open Webmail run on a private server at my work.

STeve
 
Old 04-25-2015, 06:59 AM   #4
fatmac
LQ Guru
 
Registered: Sep 2011
Location: Upper Hale, Surrey/Hants Border, UK
Distribution: Mainly Devuan, antiX, & Void, with Tiny Core, Fatdog, & BSD thrown in.
Posts: 5,478

Rep: Reputation: Disabled
Maybe you have somewhere on your system where it can be blacklisted, (I'm not a Slacker).
 
Old 04-25-2015, 07:54 AM   #5
allend
LQ 5k Club
 
Registered: Oct 2003
Location: Melbourne
Distribution: Slackware64-15.0
Posts: 6,367

Rep: Reputation: 2748Reputation: 2748Reputation: 2748Reputation: 2748Reputation: 2748Reputation: 2748Reputation: 2748Reputation: 2748Reputation: 2748Reputation: 2748Reputation: 2748
Quote:
My webmail has got nothing to do with Optus.
My apologies. I have misread your original post. Sorry.
 
Old 04-25-2015, 09:47 PM   #6
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,311
Blog Entries: 28

Rep: Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137Reputation: 6137
I would suggest testing this in other browsers, such as Konqueror, Opera, or Midori. That might cast some more light on what's going on.
 
Old 04-26-2015, 08:34 AM   #7
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Quote:
Originally Posted by frankbell View Post
I would suggest testing this in other browsers, such as Konqueror, Opera, or Midori. That might cast some more light on what's going on.
+1 .
What happens with a new profile and you don't go to webmail?
 
Old 04-26-2015, 03:10 PM   #8
telemeister
Member
 
Registered: Dec 2007
Location: Brisbane Australia
Distribution: Slackware
Posts: 63

Original Poster
Rep: Reputation: 16
Hello Habitual

I have only ever seen the problem when I go to my webmail address.

Once it starts, I can't get to the mebmail.

If I delete my ~/.mozilla and start a new profile, then I can get into
webmail for a while (maybe 1 day) but inevitably the 'diversion' takes
over again.

Thanks

Steve

PS I have been trying now shutting down my webmail tab immediately after
reading mail. Am not yet sure if this helps.
 
Old 04-26-2015, 04:26 PM   #9
John VV
LQ Muse
 
Registered: Aug 2005
Location: A2 area Mi.
Posts: 17,623

Rep: Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651
it sounds more like your ISP
HAS!!!
hijacked your DNS and maybe search

try using google's DNS
https://developers.google.com/speed/...dns/docs/using

ipv4 --- 8.8.8.8 and 8.8.4.4

ipv6 2001:4860:4860::8888 and 2001:4860:4860::8844
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
firefox 3.6.13 hijacked sirius57 Linux - Security 5 01-09-2011 08:51 AM
Firefox homepage hijacked by barnsandnoble.com walterbyrd Linux - Desktop 6 10-18-2006 05:57 PM
firefox hijacked? dcdbutler Linux - Software 10 02-20-2006 08:13 PM
firefox homepage hijacked?? pinkfloyd Linux - Security 2 01-31-2005 04:58 PM
Firefox Hijacked? (MDK 9.2) DoddyUK Linux - Software 9 12-27-2004 11:21 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:02 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration