Free/Paid Message Board Hosting - BbBoy.net
Please read the Manuals and FAQs before posting a question.
 
BbSupport Forums :: Bug Reports :: Malicious code in a popup window.

Who's Online :: Stats :: Search :: Lost Password :: To Do List

If you think you've found a bug, please read here first to see how to post about it, so that we can resolve the issue quickly and more efficiently. Also make sure you leave a link to your board or an example thread for us to examine. Thank you all for your BbSupport and invaluable help with bug reports you've taken time to post.

Welcome, Register :: Log In 
Users active in this forum:
Users active in this thread: Guest

Pages: [ 1 ]

[ Watch ] [ < ] [ LOCKED ] [ > ]

Zack_Morris
Unavailable
23 posts
Newbie


Reply
Malicious code in a popup window. ( 17:24:09 WedNov 17 2004 )

Board URL: http://emerald.bbboy.net/nickdisk

Not sure if this is the correct forum for this but anyhow had this info passed on to me by another user. Thought I'd let you all look at at and see what you think. Sure doesnt seem like something that should be happening. Here it is:

For the last couple of weeks or so I have been receiving a popup window with apparently no contents nor window title when I enter some of Nickdisk's forums, in particular the Rocket Power one. This popup appears randomly, which means that not everytime I go to the forum I receive it.

This kind of popup window seems to work on machines running Windows XP / Internet Explorer 6. I have seen it in three different machines, all of which have that configuration.

When that popup appears, it stays in top of the screen, but it doesn't get a new icon in the program bar, so, in order to minimize or close it, you have to click on the X icon on the top right corner of the popup.

THIS WINDOW STARTS A MALICIOUS CODE

If you click on this popup window, it will open a new browser window and link to a site called "NTSEARCH". Although this site seems quite innocent, it sends lots of cookies with malicious scripts to your computer, and if your equipment is not protected, those codes will start doing anything from harvesting data (the so-called "spyware" to instal plug-ins in your computer, modifiying your Internet Explorer program by adding a search bar (with spyware and pornography included) and setting your default home page to NTSEARCH.

To moderators: although I understand that this kind of popup windows are out of your control, most likely due to the fact that the site is hosted on a free account and thus can have commercial propaganda windows, it might be a good idea to report this window to the host administrator, since it could be a misuse of his infrastructure by the people at NTSearch.

To Windows XP users: So far, it seems this operating system is the only one with the vulnerability needed for this spyware to work. You can protect your computer by following these steps:

1) Upgrade your Windows OS to Service Pack 2. That SP includes many fixes to security breaches in Windows XP. If you use Internet extensively, this is definitely recommended.

2) Install a pop-up blocker plugin on your browser. Google and Yahoo! offer for download a search bar that plugs into Internet Explorer which, among other features, includes a very useful popup blocking tool.

3) Increase the security settings of your browser. Go to Tools - Internet options - Security and turn security level to high. This might cause some special features to stop working, but then again, you will be protected from malicious code.

4) Install a personal firewall. Windows XP has a built-in personal firewall that should be turned on, but it would be great to get an extra firewall.

5) Keep your antivirus updated. No need to explain why, uh?

6) Finally (if you are as paranoid as I am right now), download a spyware control program like Lavasoft's AdAware, and delete all the Internet temporary files (in Internet Explorer, Tools, Internet options. In the "general" tab, there's a section called "internet files" with a button labeled "delete all temporary files"). After deleting the temp files, run AdAware and make sure to quarantine all the spiders it finds.

Hope this works for you all. Like I said, this has happened to me only with machines running Windows XP, but if anyone has had a similar experience with other operating systems, please post. I think this is something we should definitely be aware of.

  
Nickdisk
Unavailable
3274 posts
~BbMod~


BbTheme Winner



Mood Now: Sleeping
Post Mood: Optimistic

Reply
Re: Malicious code in a popup window. ( 23:35:11 WedNov 17 2004 )

The only way we are going to be able to find the source of this if it is indeed coming from one of our ad networks is to have the source code from a board page that was loaded when this happens. Right click on the board page you are on when this happened, go to 'View Source' and then send it to us by posting it in this thread. If someone can do copy the source of a page from the board that was loading when the problem pop up loaded that gives us what we need to stop allowing whatever network is sending that out to us and in turn sending it to you. :smile:

Please do NOT use pop up blockers on our network as you are stealing revenue from us and that is a big reason of why we are NOT taking any new boards OR allowing free boards to remain. If you use a pop up blocker you're violating BbBoards TOU and abusing BbBoards service :smile:

Also, those who get pop ups that are triggered when you close one, please right click and view source and follow the above instructions so that we can track the ad network that is sending those because we definitely do NOT want people to have more then the two pop ups per IP per 12 hours on fixed boards. We appreciate your help in this matter so that we can find and remove this from our network so that noone is bombarded with things that are NOT supposed to be happening. :smile:




  

Pages: [ 1 ]

[ Watch ] [ < ] [ LOCKED ] [ > ]

8 people online in the last 15 minutes - 0 members, 0 anon and 8 guests. (Most ever was 129 at 22:49:41 Fri Oct 4 2002)

 Total Members: 3242, Newest Member: catford.

  • Can't start a new thread. (Everyone Registered)
  • Can't start a new poll. (Admins Only)
  • Can't add a reply. (Everyone Registered)
  • Can't edit your posts. (Mods & Admins)
  • Register :: Log In :: In Power

    The time is now 09:17:46 Thu May 23 2013

    Powered By BbBoard V1.4.2
    © 2001-2007 BbBoy.net