Author Topic: Forum redirect  (Read 9207 times)

0 Members and 1 Guest are viewing this topic.

Offline AcHmed99Topic starter

  • Contributor
  • Posts: 35
  • Country: 00
Forum redirect
« on: January 17, 2015, 11:21:27 am »
Has anyone else gotten redirected when they click on this topic.

The topic is currently on page 3 of Projects, Designs, and Technical Stuff

I’m using firefox with noscript,flashblock and adblock.

I thought I might have some browser hijacker but it only does it in this forum and only for that topic. I scanned with MBAM and security essentials and found nothing. I also used Hijackthis and found nothing odd.

I tried clicking the link with IE, security to the max and it doesn’t redirect.
A screen shot of the site redirected to.


A screenshot of webtraffic when the link is clicked.

 

Offline AndreasF

  • Frequent Contributor
  • **
  • Posts: 251
  • Country: gb
    • mind-dump.net
Re: Forum redirect
« Reply #1 on: January 17, 2015, 11:30:16 am »
I can still see the thread (i.e. don't get forwarded).

The first reply (by EdoNork) contains a gif that links to the site:
Code: [Select]
<img src="http://iranpoliticsclub.net/club/images/smilies/1%20soda%20popcorn.gif" alt="" class="bbc_img">
my random ramblings mind-dump.net
 

Online Psi

  • Super Contributor
  • ***
  • Posts: 9950
  • Country: nz
Re: Forum redirect
« Reply #2 on: January 17, 2015, 11:47:26 am »
There are two img tags, the main one and a smaller one. (red arrow added by me)



This is the img tag urls

Code: [Select]

http://iranpoliticsclub.net/club/images/smilies/1%20soda%20popcorn.gif

http://www.google.es/url?sa=i&rct=j&q=&esrc=s&source=images&cd=&cad=rja&uact=8&ved=0CAcQjRw&url=http%3A%2F%2Firanpoliticsclub.net%2Fclub%2Fviewtopic.php%3Ft%3D562&ei=znq3VOSfBou8Ua7YgvAD&psig=AFQjCNEC6rD-PRRZtibAmMuZy3m_7vqxFg&ust=1421396970646336

« Last Edit: January 17, 2015, 11:59:51 am by Psi »
Greek letter 'Psi' (not Pounds per Square Inch)
 

Offline EEVblog

  • Administrator
  • *****
  • Posts: 37740
  • Country: au
    • EEVblog
Re: Forum redirect
« Reply #3 on: January 17, 2015, 11:58:50 am »
No problem for me, but I have deleted EdoNorks post just in case, it contained nothing of value anyway.
 

Online Psi

  • Super Contributor
  • ***
  • Posts: 9950
  • Country: nz
Re: Forum redirect
« Reply #4 on: January 17, 2015, 12:03:04 pm »
I would worry that your windows install has been compromised in some way that makes it auto-run code when it shouldn't be.
Greek letter 'Psi' (not Pounds per Square Inch)
 

Online Psi

  • Super Contributor
  • ***
  • Posts: 9950
  • Country: nz
Re: Forum redirect
« Reply #5 on: January 17, 2015, 12:17:43 pm »
The URL in that 2nd img tag (the one i pointed the red arrow at) is not actually an image at all.
If you try to download it you get html code with a redirect.

So your web browser is being told to display an image which is not an image but in fact HTML code, and instead of showing the default "no image" icon that the rest of us are getting your browser is running the HTML.
« Last Edit: January 17, 2015, 12:20:56 pm by Psi »
Greek letter 'Psi' (not Pounds per Square Inch)
 

Online Psi

  • Super Contributor
  • ***
  • Posts: 9950
  • Country: nz
Re: Forum redirect
« Reply #6 on: January 17, 2015, 12:22:06 pm »
i always run with UAC turned off, Its too damn annoying.

And i didn't get the redirect.
Greek letter 'Psi' (not Pounds per Square Inch)
 

Offline ElektroQuark

  • Supporter
  • ****
  • Posts: 1244
  • Country: es
    • ElektroQuark
Re: Forum redirect
« Reply #7 on: January 17, 2015, 01:57:32 pm »
Uh.
I copied the GIF URL from a search engine.
Maybe they somewhat protect their content.
Sorry!

Offline ElektroQuark

  • Supporter
  • ****
  • Posts: 1244
  • Country: es
    • ElektroQuark
Re: Forum redirect
« Reply #8 on: January 17, 2015, 02:03:51 pm »
... it contained nothing of value anyway.

It states that I was very interested in the previous post and that I was waiting for the promised images.

Offline Lightages

  • Supporter
  • ****
  • Posts: 4314
  • Country: ca
  • Canadian po
Re: Forum redirect
« Reply #9 on: January 17, 2015, 10:52:42 pm »
After that redirect, I would certainly run MalwareBytes Antimalware and Antirootkit, Super AntiSpyware, Sophos Virus Removal Tool Antirootkit.

 

Offline wraper

  • Supporter
  • ****
  • Posts: 16864
  • Country: lv
Re: Forum redirect
« Reply #10 on: January 18, 2015, 12:11:38 am »
IIRC few years ago it was discovered Opera (not webkit based) and some other browser or browsers would redirect if the page contains bogus link to the image which actually is no image. It remained not fixed for a long time. Probably something similar here.
 

Offline ElektroQuark

  • Supporter
  • ****
  • Posts: 1244
  • Country: es
    • ElektroQuark
Re: Forum redirect
« Reply #11 on: January 18, 2015, 09:53:13 am »
orry guys, I'm really embarrassed with all this.

Offline Lightages

  • Supporter
  • ****
  • Posts: 4314
  • Country: ca
  • Canadian po
Re: Forum redirect
« Reply #12 on: January 18, 2015, 06:48:46 pm »
After that redirect, I would certainly run MalwareBytes Antimalware and Antirootkit, Super AntiSpyware, Sophos Virus Removal Tool Antirootkit.

I used to (operative words being used to) clean virus and browser hijackers off my brother in laws and other family members PC and that was the SOP. It got to be a time consuming PITA so they are on their own now.

It couldn't really do anything other then what it did, redirect me to a crazy ass site, looks like it maybe tried to pick-up some referal clicks or something judging by the f**ingmachines url as well.

But yea pretty Fu*ked up website.

* inserted to spare the kiddies.

If something redirects to a website, you don't know whether that new website has a day zero hijacker or some other malware. The very fact that I got an unexpected website would prompt me to do what I suggested. I too have seen far too many compromised computers in my life to let something like that go. It certainly doesn't hurt to do what I suggest.
 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf