Page 1 of 2 12 LastLast
Results 1 to 25 of 37

Thread: anandtech ad server got compromised beware

  1. #1
    Banned
    Join Date
    May 2009
    Posts
    676

    anandtech ad server got compromised beware





    seems some ad server has got maleware in it delivering it to the site, asking for a plug-in install containing trojans.
    it's not the first time AT has had issues since they moved into VB,
    yet they're aware of it and working to solve it,
    good luck over there guys.
    Last edited by onex; 03-27-2010 at 02:53 PM.

  2. #2
    I am Xtreme
    Join Date
    Dec 2008
    Location
    France
    Posts
    9,060
    Ow...
    I'm sure it will be sorted ASAP, though.
    Just glad I've read their Fermi review earlier today, just in time before the crisis!
    Donate to XS forums
    Quote Originally Posted by jayhall0315 View Post
    If you are really extreme, you never let informed facts or the scientific method hold you back from your journey to the wrong answer.

  3. #3
    Xtreme Member
    Join Date
    Jun 2009
    Posts
    145
    I love coincidental timing. This was the first place I went to the moment I also received a warning that Anand might upload a trojan to me to get my Fermi review fix

  4. #4
    Xtreme Cruncher
    Join Date
    Feb 2003
    Location
    Estonia
    Posts
    1,097
    Went to anand via chrome and got message that its not safe, had the little WTF?! moment, then entered.


    Figures
    Member of XS WCG since 2006-11-25




  5. #5
    I am Xtreme
    Join Date
    Dec 2008
    Location
    France
    Posts
    9,060
    Quote Originally Posted by anubis View Post
    Went to anand via chrome and got message that its not safe, had the little WTF?! moment, then entered.


    Figures
    So its your computer that sent me 250 viagra spam emails today?!

    Just kidding.
    Donate to XS forums
    Quote Originally Posted by jayhall0315 View Post
    If you are really extreme, you never let informed facts or the scientific method hold you back from your journey to the wrong answer.

  6. #6
    Xtreme Cruncher
    Join Date
    Dec 2008
    Location
    The Netherlands
    Posts
    896
    Lol, had an unsafe warning as well, but I just entered regardless. I'm not that stupid to randomly install addons/plugins

  7. #7
    Xtreme Cruncher
    Join Date
    Feb 2003
    Location
    Estonia
    Posts
    1,097
    Quote Originally Posted by zalbard View Post
    So its your computer that sent me 250 viagra spam emails today?!

    Just kidding.
    Only 250? have to give the little critters access to bit more BW i guess
    Member of XS WCG since 2006-11-25




  8. #8
    Xtreme Enthusiast
    Join Date
    Feb 2009
    Location
    Montreal
    Posts
    791
    Quote Originally Posted by Musho View Post
    Lol, had an unsafe warning as well, but I just entered regardless. I'm not that stupid to randomly install addons/plugins
    Except that you don't even need to accept anything to get infected through certain types of vulnerabilities. Do you run noscript? If not, or if you have it whitelisted for that site, chances are you can get hit by an attack without even realizing it. It doesn't matter what IQ you have or how many AV softwares you run, it can and will still happen.

    Welcome to the internet.

  9. #9
    Xtreme Enthusiast
    Join Date
    Apr 2005
    Location
    Windsor, Canada
    Posts
    858
    Yeah I got the same message while trying to see the Fermi review again this morning. Good thing I had already read it last night.
    Quote Originally Posted by jimmyz View Post
    A DFI board is like a divorce, expensive, but well worth it.
    Quote Originally Posted by virtualrain View Post
    I dunno... I think a DFI board is more like marriage... demanding, time consuming, and a PITA but rewarding in it's own twisted way.

  10. #10
    Xtreme Enthusiast
    Join Date
    May 2005
    Location
    Edmonton, Alberta, Canada
    Posts
    714
    3rd party ads got hacked actually, not Anandtech per say.

    Anand speaketh.
    http://forums.anandtech.com/showpost...4&postcount=51
    Gigabyte X58A-UD3R | i7 930 @ 4 GHz | Corsair H50
    G.Skill RipJaws 4x2 GB @ DDR3-1600 7-7-6-24-1N | HIS Radeon HD 5870
    3x Intel X25-M 80 GB RAID-0; OCZ Agility 120 GB | Samsung SH-S243D
    Corsair HX1000 | Dell 3007WFP & Samsung 204T | 7 Ultimate x64

  11. #11
    Xtreme Cruncher
    Join Date
    Dec 2008
    Location
    The Netherlands
    Posts
    896
    Quote Originally Posted by antiacid View Post
    Except that you don't even need to accept anything to get infected through certain types of vulnerabilities. Do you run noscript? If not, or if you have it whitelisted for that site, chances are you can get hit by an attack without even realizing it. It doesn't matter what IQ you have or how many AV softwares you run, it can and will still happen.

    Welcome to the internet.
    Already ran a scan. Didn't get infected

    Adblock plus blocked the infected ads. I love that addon
    Last edited by Musho; 03-27-2010 at 11:04 AM.

  12. #12
    Xtreme Cruncher
    Join Date
    Feb 2003
    Location
    Estonia
    Posts
    1,097
    Im clean, seems like adblock saved me aswell.
    Member of XS WCG since 2006-11-25




  13. #13
    Xtreme Addict
    Join Date
    Apr 2006
    Location
    City of Lights, The Netherlands
    Posts
    2,381
    This thread title is slightly misleading. I wouldn't really say that AnandTech got hacked, they were unknowingly serving evil ads. They're working to fix it though, if they haven't already fixed it.
    "When in doubt, C-4!" -- Jamie Hyneman

    Silverstone TJ-09 Case | Seasonic X-750 PSU | Intel Core i5 750 CPU | ASUS P7P55D PRO Mobo | OCZ 4GB DDR3 RAM | ATI Radeon 5850 GPU | Intel X-25M 80GB SSD | WD 2TB HDD | Windows 7 x64 | NEC EA23WMi 23" Monitor |Auzentech X-Fi Forte Soundcard | Creative T3 2.1 Speakers | AudioTechnica AD900 Headphone |

  14. #14
    Xtreme X.I.P.
    Join Date
    Nov 2001
    Location
    Daytona Beach
    Posts
    2,126
    Quote Originally Posted by anubis View Post
    Went to anand via chrome and got message that its not safe, had the little WTF?! moment, then entered.


    Figures
    wow same here. last night reading fermi review clicked on 2nd page and got "not safe message". I didn't think anything about it at the time.


    check out "XS REVIEWS"

    Want me to believe your hardware review? Show me a receipt

  15. #15
    Banned
    Join Date
    May 2009
    Posts
    676
    3rd party ads got hacked actually, not Anandtech per say.

    Anand speaketh.
    http://forums.anandtech.com/showpost...4&postcount=51
    yeah seen it,
    This thread title is slightly misleading. I wouldn't really say that AnandTech got hacked, they were unknowingly serving evil ads. They're working to fix it though, if they haven't already fixed it.
    title would be changed.
    it sounds a bit like yellow gossip, it isn't the meaning.

  16. #16
    Nerdy Powerlifter
    Join Date
    Jul 2007
    Location
    Down in the Bayou
    Posts
    4,553
    So what exactly is the malware we have? I trusted the site & ads, although nothing popped up to install.

    avg won't scan... hmmm... lol
    You must [not] advance.


    Current Rig: i7 4790k @ stock (**** TIM!) , Zotac GTX 1080 WC'd 2214mhz core / 5528mhz Mem, Asus z-97 Deluxe

    Heatware

  17. #17
    Xtreme Addict
    Join Date
    Jan 2008
    Posts
    1,463
    Quote Originally Posted by [XC] Synthetickiller View Post
    So what exactly is the malware we have? I trusted the site & ads, although nothing popped up to install.

    avg won't scan... hmmm... lol
    It attempts to install a spoof antivirus program called "antivirus soft" which is a trojan rehash of "antivirus live" auto installer. It blocks most run32dll executions with an error message and trys to get you to buy the software via pop-ups. It also will attempt a fake virus scan. If you really got something a "antivirus soft" virus scanner would pop up, and you would be unable to use most programs. IE would take you to their purchase page
    Bring... bring the amber lamps.
    [SIGPIC][/SIGPIC]

  18. #18
    NooB MOD
    Join Date
    Jan 2006
    Location
    South Africa
    Posts
    5,799
    I didn't see a thing when I visited them about two hours ago I'm using Opera 9.64 and ESET Smart Security 4, not so much as a warning and judging by the above post I'm not infected either.
    Xtreme SUPERCOMPUTER
    Nov 1 - Nov 8 Join Now!


    Quote Originally Posted by Jowy Atreides View Post
    Intel is about to get athlon'd
    Athlon64 3700+ KACAE 0605APAW @ 3455MHz 314x11 1.92v/Vapochill || Core 2 Duo E8500 Q807 @ 6060MHz 638x9.5 1.95v LN2 @ -120'c || Athlon64 FX-55 CABCE 0516WPMW @ 3916MHz 261x15 1.802v/LN2 @ -40c || DFI LP UT CFX3200-DR || DFI LP UT NF4 SLI-DR || DFI LP UT NF4 Ultra D || Sapphire X1950XT || 2x256MB Kingston HyperX BH-5 @ 290MHz 2-2-2-5 3.94v || 2x256MB G.Skill TCCD @ 350MHz 3-4-4-8 3.1v || 2x256MB Kingston HyperX BH-5 @ 294MHz 2-2-2-5 3.94v

  19. #19
    Xtreme Member
    Join Date
    Apr 2008
    Location
    Stockholm, Sweden
    Posts
    324
    So how does Google fit in this picture? You get the message even if you don't go through their search engine. How can Google control other sites?

  20. #20
    Xtreme Enthusiast
    Join Date
    Dec 2008
    Posts
    640
    Saw the warning earlier today, too. Hacked ad server really screwing with AT over there.


    Quote Originally Posted by -n7- View Post
    3rd party ads got hacked actually, not Anandtech per say.
    If you're going to use per se, spell it correctly at least.

  21. #21
    Xtreme Addict
    Join Date
    Jun 2007
    Location
    Thessaloniki, Greece
    Posts
    1,307
    Quote Originally Posted by Eson View Post
    So how does Google fit in this picture? You get the message even if you don't go through their search engine. How can Google control other sites?
    It can't. Chrome actually always searches google, even if you enter the http address of the site.
    Seems we made our greatest error when we named it at the start
    for though we called it "Human Nature" - it was cancer of the heart
    CPU: AMD X3 720BE@ 3,4Ghz
    Cooler: Xigmatek S1283(Terrible mounting system for AM2/3)
    Motherboard: Gigabyte 790FXT-UD5P(F4) RAM: 2x 2GB OCZ DDR3 1600Mhz Gold 8-8-8-24
    GPU:HD5850 1GB
    PSU: Seasonic M12D 750W Case: Coolermaster HAF932(aka Dusty )

  22. #22
    Xtreme Mentor
    Join Date
    Jan 2009
    Location
    Oslo - Norway
    Posts
    2,879
    Quote Originally Posted by jaredpace View Post
    It attempts to install a spoof antivirus program called "antivirus soft" which is a trojan rehash of "antivirus live" auto installer. It blocks most run32dll executions with an error message and trys to get you to buy the software via pop-ups. It also will attempt a fake virus scan. If you really got something a "antivirus soft" virus scanner would pop up, and you would be unable to use most programs. IE would take you to their purchase page
    I have seen the exact same fake virus scan attempt while using IE on a couple of other sites, including trustedreviews.com and photographyblog.com. It is not there all the time, but pops up sometimes. I guess one of the tech ad-servers is infected.
    It stops by ALF F4 if you are really fast, but one time I didn't see it and it could deliver a virus that MS security essential could catch and clean.
    I'm not sure if anandtechis is compromised by the same virus, (and I don't want to go there to find out ) , but it sounds similar.
    Last edited by Sam_oslo; 03-27-2010 at 04:44 PM.

    ASUS P8P67 Deluxe (BIOS 1305)
    2600K @4.5GHz 1.27v , 1 hour Prime
    Silver Arrow , push/pull
    2x2GB Crucial 1066MHz CL7 ECC @1600MHz CL9 1.51v
    GTX560 GB OC @910/2400 0.987v
    Crucial C300 v006 64GB OS-disk + F3 1TB + 400MB RAMDisk
    CM Storm Scout + Corsair HX 1000W
    +
    EVGA SR-2 , A50
    2 x Xeon X5650 @3.86GHz(203x19) 1.20v
    Megahalem + Silver Arrow , push/pull
    3x2GB Corsair XMS3 1600 CL7 + 3x4GB G.SKILL Trident 1600 CL7 = 18GB @1624 7-8-7-20 1.65v
    XFX GTX 295 @650/1200/1402
    Crucial C300 v006 64GB OS-disk + F3 1TB + 2GB RAMDisk
    SilverStone Fortress FT01 + Corsair AX 1200W

  23. #23
    Banned
    Join Date
    May 2009
    Posts
    676
    So how does Google fit in this picture? You get the message even if you don't go through their search engine. How can Google control other sites?
    it's going through G servers when there is a request for the site.
    Of the 1101 pages we tested on the site over the past 90 days, 86 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2010-03-27, and the last time suspicious content was found on this site was on 2010-03-27.
    now have a look at what has happened during the last few hours.
    after receiving suspicious information from the site, G analysis apparently emulate a series of test on different pages to get a view of the site's malicious behavior.
    it probably goes over pages with background daemon searching for destructive code

    E: sorry, missed earlier posts.
    Last edited by onex; 03-27-2010 at 04:50 PM.

  24. #24
    Xtreme Member
    Join Date
    Apr 2008
    Location
    Stockholm, Sweden
    Posts
    324
    Quote Originally Posted by BrowncoatGR View Post
    It can't. Chrome actually always searches google, even if you enter the http address of the site.
    I use Firefox, but Ive seen screens like this when i follow links from a site.

  25. #25
    Xtreme Member
    Join Date
    Sep 2006
    Posts
    319
    Right click on Sanboxie -> Chrome -> Delete Contents.
    I still don't know why everyone isn't using Sandboxie

Page 1 of 2 12 LastLast

Bookmarks

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •