Go Back  Bike Forums > News & Suggestions > Forum Suggestions & User Assistance
Reload this Page >

malicious pop ups coming from bf advertising

Search
Notices
Forum Suggestions & User Assistance Have a suggestion for the forums? Need help with the Forums? Post here.

malicious pop ups coming from bf advertising

Thread Tools
 
Search this Thread
 
Old 12-28-16, 10:19 PM
  #1  
nycphotography
NYC
Thread Starter
 
nycphotography's Avatar
 
Join Date: Sep 2006
Posts: 3,714
Mentioned: 18 Post(s)
Tagged: 0 Thread(s)
Quoted: 1169 Post(s)
Liked 107 Times in 62 Posts
malicious pop ups coming from bf advertising

One of your advertisers has started serving malicious / phishing type ads. Every so often I'll get a full screen log in box, or "infection" warning, or some other kind of malicious crap that most reputable sites have long since exterminated.

I'd suggest having someone who knows how to track down such things take a look.

It happens once or twice a day for the last couple weeks. Took me a while to figure out it was your site... I wasted a few hours figuring out how to get an run malware bytes for my macbook before realizing, through googling about it, that it was probably a malicious ad insertion, and then it took me a while to isolate that it is indeed (definitely) coming from bikeforums and not from some other site.
nycphotography is offline  
Old 12-29-16, 12:07 AM
  #2  
Rollfast
What happened?
 
Rollfast's Avatar
 
Join Date: Jun 2007
Location: Around here somewhere
Posts: 7,927

Bikes: 3 Rollfasts, 3 Schwinns, a Shelby and a Higgins Flightliner in a pear tree!

Mentioned: 57 Post(s)
Tagged: 1 Thread(s)
Quoted: 1835 Post(s)
Liked 292 Times in 255 Posts
Again, if you could try and tell them what it was for or some other information the staff and IB techs could probably tell you if it actually came from here etc and they can have those sources blocked.


It really does help. We all have to help each other.


Also, there is a misconception of many that these things are easily traced and correctable...some exploits and bad advertisements are somewhat random and since the ads may be different than what others see (because the ad server may personalize them based on the browsing patterns they know of for you) others might not be seeing the same things.


HOWEVER...with your help they can see if that ad was served to BF and ultimately you (No, we DON'T all get the same ads) and they can tell the ad vendor that the ad is inappropriate and have it removed from being served to the site.


The internet is stranger than the Oompah-Loompahs.
__________________
I don't know nothing, and I memorized it in school and got this here paper I'm proud of to show it.

Last edited by Rollfast; 12-29-16 at 12:18 AM.
Rollfast is offline  
Old 12-29-16, 10:51 AM
  #3  
nycphotography
NYC
Thread Starter
 
nycphotography's Avatar
 
Join Date: Sep 2006
Posts: 3,714
Mentioned: 18 Post(s)
Tagged: 0 Thread(s)
Quoted: 1169 Post(s)
Liked 107 Times in 62 Posts
ah yes, thanks to micro targeting you can no longer police your own back yard. OK, I'll watch for more details and see if helps.

I know these things are hard (near impossible) to track down. I basically killed several of my web sites because it was impossible to maintain both revenue and integrity.
nycphotography is offline  
Old 12-29-16, 08:12 PM
  #4  
Rollfast
What happened?
 
Rollfast's Avatar
 
Join Date: Jun 2007
Location: Around here somewhere
Posts: 7,927

Bikes: 3 Rollfasts, 3 Schwinns, a Shelby and a Higgins Flightliner in a pear tree!

Mentioned: 57 Post(s)
Tagged: 1 Thread(s)
Quoted: 1835 Post(s)
Liked 292 Times in 255 Posts
Sure it's easy. You get your ad buys ahead of time, as sponsors and stop letting Google etc ruin your day.


Run the ads as pictures with URLs but not clickable. Tell the users to paste them.


If you explain nicely it should be fine for all but the fussbudgets you don't want.
__________________
I don't know nothing, and I memorized it in school and got this here paper I'm proud of to show it.
Rollfast is offline  
Old 12-29-16, 10:58 PM
  #5  
nycphotography
NYC
Thread Starter
 
nycphotography's Avatar
 
Join Date: Sep 2006
Posts: 3,714
Mentioned: 18 Post(s)
Tagged: 0 Thread(s)
Quoted: 1169 Post(s)
Liked 107 Times in 62 Posts
got one on the mac (none on the win 10 box so far)

Dear Verizon User,
Congratulations! You've been selected to participate in an anonymous survey about your experiences with Verizon.
In consideration for your time, at the end of this short survey you will be presented with several exclusive reward offers (worth at least $70).

url https://www.mellowsurvey.com/?sid=isp.opt.3a6x&ow=us.ao96ho9gbr467d49.nojs.c&isp=Mci%20Communications%20Services%20inc.%20Dba%20V erizon%20Business&browser=Firefox&os=OS%20X&region=New%20York&city=xxxx&ip=xxx.xx.xxx.xxx&countryname=United%20States&device=DESKTOP&brand=Desktop&model=Desktop&country=US&track=www.trunkssurvey.com&tid=0ba6f51c-279d-4a68-82c0-dc5e8b9e9e67&caid=3fc624b7-4074-4b7f-aa2a-a68cbc6a0c97&head=ret.ss.asp.ncxw9c&did=5269&voluumdata=BASE64xxxREDACTEDxxx&c1=5269&c2=13031&c3=454 14&c4=US&c5=xxxx&c6=Firefox

lots of shady here, especially the 2k of base64 payload


Attached Images
nycphotography is offline  
Old 12-30-16, 08:31 AM
  #6  
nycphotography
NYC
Thread Starter
 
nycphotography's Avatar
 
Join Date: Sep 2006
Posts: 3,714
Mentioned: 18 Post(s)
Tagged: 0 Thread(s)
Quoted: 1169 Post(s)
Liked 107 Times in 62 Posts
Another one: NFL Picks 2016: 5 Best Bets Against The Spread For Week 17

NFL Picks 2016: 5 Best Bets Against The Spread For Week 17


this one navigated away from a half typed reply to a message causing me to lose my work in progress!!!
nycphotography is offline  
Old 12-30-16, 05:12 PM
  #7  
Rollfast
What happened?
 
Rollfast's Avatar
 
Join Date: Jun 2007
Location: Around here somewhere
Posts: 7,927

Bikes: 3 Rollfasts, 3 Schwinns, a Shelby and a Higgins Flightliner in a pear tree!

Mentioned: 57 Post(s)
Tagged: 1 Thread(s)
Quoted: 1835 Post(s)
Liked 292 Times in 255 Posts
Okay...let's go from this angle.


Check some of the sites/apps you use for 'safety' in search.


Some people have downloaded games or apps that look innocent enough but are known for malware/exploits...you may not notice unless you visited un the same timeframe or before coming here...it does happen.
__________________
I don't know nothing, and I memorized it in school and got this here paper I'm proud of to show it.
Rollfast is offline  
Old 12-30-16, 05:46 PM
  #8  
nycphotography
NYC
Thread Starter
 
nycphotography's Avatar
 
Join Date: Sep 2006
Posts: 3,714
Mentioned: 18 Post(s)
Tagged: 0 Thread(s)
Quoted: 1169 Post(s)
Liked 107 Times in 62 Posts
Originally Posted by Rollfast
Okay...let's go from this angle.


Check some of the sites/apps you use for 'safety' in search.


Some people have downloaded games or apps that look innocent enough but are known for malware/exploits...you may not notice unless you visited un the same timeframe or before coming here...it does happen.
FWIW the mac has almost nothing installed on it. I used to run windows in a VM but eventually killed that and the mac has like... nothing installed. malwarebytes says squeaky clean.

finally, they ONLY happen when on bikeforums in firefox, often taking over the active tab.

is anyone from BF/IB going to weigh in on this or am I just jerking myself off?
nycphotography is offline  
Old 01-01-17, 08:11 PM
  #9  
Rollfast
What happened?
 
Rollfast's Avatar
 
Join Date: Jun 2007
Location: Around here somewhere
Posts: 7,927

Bikes: 3 Rollfasts, 3 Schwinns, a Shelby and a Higgins Flightliner in a pear tree!

Mentioned: 57 Post(s)
Tagged: 1 Thread(s)
Quoted: 1835 Post(s)
Liked 292 Times in 255 Posts
I think this site isn't all that conducive, not even the bike porn...


Real PCs can be found dirt cheap, I build mine from donations and stripped chassis.
__________________
I don't know nothing, and I memorized it in school and got this here paper I'm proud of to show it.
Rollfast is offline  
Old 01-01-17, 08:34 PM
  #10  
Johnny Mullet
That Huffy Guy
 
Johnny Mullet's Avatar
 
Join Date: Jun 2014
Location: Ashtabula, Ohio
Posts: 1,438

Bikes: Old School Huffy Bikes

Mentioned: 6 Post(s)
Tagged: 0 Thread(s)
Quoted: 79 Post(s)
Likes: 0
Liked 6 Times in 6 Posts
I'm running Linux Mint Mate 18.1 with Firefox and have never had any issues with this or any other site. I don't even have any anti-virus software on this rig.
Johnny Mullet is offline  
Old 01-03-17, 06:49 PM
  #11  
ibtyen
Senior Member
 
Join Date: Feb 2014
Posts: 208
Mentioned: 3 Post(s)
Tagged: 0 Thread(s)
Quoted: 70 Post(s)
Likes: 0
Liked 0 Times in 0 Posts
As Rollfast has mentioned, tracking these things down is a difficult task. Could you email the screenshots you posted full size directly to me?

tyson.yen@internetbrands.com


Originally Posted by nycphotography
FWIW the mac has almost nothing installed on it. I used to run windows in a VM but eventually killed that and the mac has like... nothing installed. malwarebytes says squeaky clean.

finally, they ONLY happen when on bikeforums in firefox, often taking over the active tab.

is anyone from BF/IB going to weigh in on this or am I just jerking myself off?
ibtyen is offline  
Old 01-03-17, 07:04 PM
  #12  
nycphotography
NYC
Thread Starter
 
nycphotography's Avatar
 
Join Date: Sep 2006
Posts: 3,714
Mentioned: 18 Post(s)
Tagged: 0 Thread(s)
Quoted: 1169 Post(s)
Liked 107 Times in 62 Posts
absolutely. i'll send the one I have later tonight and start watching for new ones.
nycphotography is offline  
Old 01-07-17, 04:54 PM
  #13  
smarkinson
Senior Member
 
Join Date: May 2015
Posts: 1,003
Mentioned: 1 Post(s)
Tagged: 0 Thread(s)
Quoted: 332 Post(s)
Liked 13 Times in 7 Posts
Started getting a spam/phishing ad that takes over the browser after about 10 seconds of the page loading and redirects away from BF to a different site. This has started happening in the last couple of days.

It doesn't happen on every BF page but it seems to happen consistently on this thread https://www.bikeforums.net/general-cy...rformance.html .

The ad pretends to be a facebook page with Membership Rewards as the title. "Congratulations, you could be selected to receive a reward!"

The address that I get redirected too is ucns.online/newipau/index.php?s1=lam_au&pubid=www.bikeforums.net_son&bid=aeb9b921ac651693f39e4d420981043f

It appears to be rather harmless (at least on android, I'd hate to try it on a PC).

This is happening on both my Android tablet (Google browser) and my Android phone (again a google browser) but not on my Apple Ipod. In both cases the redirected address is the same (including the hex characters at the end). The other difference is on my Android devices I am logged in as a user of BF while on the ipod I am not logged in.

I couldn't tell if it happens on my PC as this is the reason I have adblockers on my PC.
smarkinson is offline  
Old 01-07-17, 06:25 PM
  #14  
nycphotography
NYC
Thread Starter
 
nycphotography's Avatar
 
Join Date: Sep 2006
Posts: 3,714
Mentioned: 18 Post(s)
Tagged: 0 Thread(s)
Quoted: 1169 Post(s)
Liked 107 Times in 62 Posts
all of these contest and gift card sites are blind phishing for credentials which then be further exploited. definitely NOT harmless.
nycphotography is offline  
Old 01-07-17, 11:46 PM
  #15  
Deal4Fuji
minimalist cyclist
 
Deal4Fuji's Avatar
 
Join Date: Mar 2014
Location: North Carolina
Posts: 1,745

Bikes: yes please

Mentioned: 26 Post(s)
Tagged: 0 Thread(s)
Quoted: 1119 Post(s)
Liked 1,641 Times in 944 Posts
I had this same problem get progressively worse this week. This Malware or Adware pop-up would appear when on Bike Forums and I'd have to exit out completely and get back on BF, then in about 5 minutes or less it would happen again. I looked National Consumer Center up on the web and found out that's how these things operate. The removal steps looked like more than I wanted to tackle, and since I'm a Norton subscriber I contacted their Cust Service dept and they took control of my PC via a live chat type session and it's gone. Here's a screenshot of what I was getting:
Deal4Fuji is offline  
Old 01-08-17, 04:23 PM
  #16  
nycphotography
NYC
Thread Starter
 
nycphotography's Avatar
 
Join Date: Sep 2006
Posts: 3,714
Mentioned: 18 Post(s)
Tagged: 0 Thread(s)
Quoted: 1169 Post(s)
Liked 107 Times in 62 Posts
looks like bf definitely needs to police their advertisers.

on my part this has not (yet) happened when I have been on any other web site
nycphotography is offline  
Old 01-08-17, 06:43 PM
  #17  
Rollfast
What happened?
 
Rollfast's Avatar
 
Join Date: Jun 2007
Location: Around here somewhere
Posts: 7,927

Bikes: 3 Rollfasts, 3 Schwinns, a Shelby and a Higgins Flightliner in a pear tree!

Mentioned: 57 Post(s)
Tagged: 1 Thread(s)
Quoted: 1835 Post(s)
Liked 292 Times in 255 Posts
See the eagle icon and yellow jersey with my name? WORKS!
__________________
I don't know nothing, and I memorized it in school and got this here paper I'm proud of to show it.
Rollfast is offline  
Old 01-08-17, 07:46 PM
  #18  
nycphotography
NYC
Thread Starter
 
nycphotography's Avatar
 
Join Date: Sep 2006
Posts: 3,714
Mentioned: 18 Post(s)
Tagged: 0 Thread(s)
Quoted: 1169 Post(s)
Liked 107 Times in 62 Posts
so you're saying it's a shady shakedown?
I suspect not.
nycphotography is offline  
Old 01-09-17, 12:59 AM
  #19  
Rollfast
What happened?
 
Rollfast's Avatar
 
Join Date: Jun 2007
Location: Around here somewhere
Posts: 7,927

Bikes: 3 Rollfasts, 3 Schwinns, a Shelby and a Higgins Flightliner in a pear tree!

Mentioned: 57 Post(s)
Tagged: 1 Thread(s)
Quoted: 1835 Post(s)
Liked 292 Times in 255 Posts
What I am saying is one or all of this:


Stop using the mobile browser.


Turn ON the popup blocking for your browser.


Do work with them. I'm not God or mama and I don't have popup ads.


Do tie the spam we now block with preemptive actions and these together in some fashion, it's probably related.


But DON'T blame it on the incompetence of the owners by saying "nobody else has this problem". You do not know the circumstances nor are you aware of what is being worked on right now. The version of vB we are currently using was designed for IB sites with forums in the realization that other versions of vB had problems that were hard to fix. This is actually BETTER than the 4.2.x running on Non-IB sites in a number of ways. Pobody's Nerfect tho.


You don't even use the same browser I do IF I understand. Why aren't you looking into that?


I can see from you signature what some of the problem is. You don't take any responsibility to help fix the problem. It is all of our problem, and all of us help to try and solve all of our problems. We have had other problems far longer and still worked to solve them.


IB will NOT be using something else, they own VBS and that is that.


I'm not giving you a lecture. I'm trying to help if I can, but I'm still not God or your mama. I suspect it's that hand held toy because with Windows 7 and IE 11 I'm not having these problems and especially because I have a premium membership status there are no ads in my page when I am logged in...remember, logged in.
__________________
I don't know nothing, and I memorized it in school and got this here paper I'm proud of to show it.
Rollfast is offline  
Old 01-09-17, 02:26 PM
  #20  
ibtyen
Senior Member
 
Join Date: Feb 2014
Posts: 208
Mentioned: 3 Post(s)
Tagged: 0 Thread(s)
Quoted: 70 Post(s)
Likes: 0
Liked 0 Times in 0 Posts
Thanks for the info guys. I'm updating the tech ticket I have with this new info/images.
ibtyen is offline  
Old 01-10-17, 11:32 PM
  #21  
f4rrest
Farmer tan
 
f4rrest's Avatar
 
Join Date: May 2008
Location: Burbank, CA
Posts: 7,986

Bikes: Allez, SuperSix Evo

Mentioned: 38 Post(s)
Tagged: 1 Thread(s)
Quoted: 2870 Post(s)
Liked 28 Times in 23 Posts
These popups are driving new visitors away. I guarantee you.

I experienced the same on my Android and am very experienced with web servers and internet security.

So, it is IB's problem if they want to maintain a healthy number of website visitors. Don't put the blame on the website visitors or their choice of technology.
f4rrest is offline  
Old 01-10-17, 11:54 PM
  #22  
Rollfast
What happened?
 
Rollfast's Avatar
 
Join Date: Jun 2007
Location: Around here somewhere
Posts: 7,927

Bikes: 3 Rollfasts, 3 Schwinns, a Shelby and a Higgins Flightliner in a pear tree!

Mentioned: 57 Post(s)
Tagged: 1 Thread(s)
Quoted: 1835 Post(s)
Liked 292 Times in 255 Posts
Why not? You can't read BF on a cellphone, all the people said so earlier.


Is anybody having a trip on a Dell? I've got a few...
__________________
I don't know nothing, and I memorized it in school and got this here paper I'm proud of to show it.
Rollfast is offline  
Old 01-10-17, 11:55 PM
  #23  
Rollfast
What happened?
 
Rollfast's Avatar
 
Join Date: Jun 2007
Location: Around here somewhere
Posts: 7,927

Bikes: 3 Rollfasts, 3 Schwinns, a Shelby and a Higgins Flightliner in a pear tree!

Mentioned: 57 Post(s)
Tagged: 1 Thread(s)
Quoted: 1835 Post(s)
Liked 292 Times in 255 Posts
PS Don't bother tripping on a Dell, she's getting married now.
__________________
I don't know nothing, and I memorized it in school and got this here paper I'm proud of to show it.
Rollfast is offline  
Old 01-12-17, 01:39 PM
  #24  
JeremyLC
Senior Member
 
JeremyLC's Avatar
 
Join Date: Nov 2005
Location: Arlington, TX
Posts: 1,414

Bikes: 2008 Surly Cross Check, 2010 Fuji Track Comp

Mentioned: 7 Post(s)
Tagged: 0 Thread(s)
Quoted: 255 Post(s)
Likes: 0
Liked 2 Times in 2 Posts
Originally Posted by smarkinson
Started getting a spam/phishing ad that takes over the browser after about 10 seconds of the page loading and redirects away from BF to a different site. This has started happening in the last couple of days.

It doesn't happen on every BF page but it seems to happen consistently on this thread https://www.bikeforums.net/general-cy...rformance.html .

The ad pretends to be a facebook page with Membership Rewards as the title. "Congratulations, you could be selected to receive a reward!"

The address that I get redirected too is ucns.online/newipau/index.php?s1=lam_au&pubid=www.bikeforums.net_son&bid=aeb9b921ac651693f39e4d420981043f

It appears to be rather harmless (at least on android, I'd hate to try it on a PC).

This is happening on both my Android tablet (Google browser) and my Android phone (again a google browser) but not on my Apple Ipod. In both cases the redirected address is the same (including the hex characters at the end). The other difference is on my Android devices I am logged in as a user of BF while on the ipod I am not logged in.

I couldn't tell if it happens on my PC as this is the reason I have adblockers on my PC.

I'm experiencing the Facebook phishing redirect on Chrome (55) on Android(7.1.1) on my Pixel XL. I'll try to grab a screenshot when it happens again. It's usually accompanied by a JavaScript pop-up dialog of some kind.
JeremyLC is offline  
Old 01-12-17, 02:14 PM
  #25  
ibtyen
Senior Member
 
Join Date: Feb 2014
Posts: 208
Mentioned: 3 Post(s)
Tagged: 0 Thread(s)
Quoted: 70 Post(s)
Likes: 0
Liked 0 Times in 0 Posts
We have adjusted a few ad networks last night. Please let us know if you guys are still experiencing problems.
ibtyen is offline  


Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.