Dailyvideorewards scam?
Asked by
XOIIO (
18328)
October 8th, 2011
How does this scam even work? I get it randomly, no matter what site I go to. Youtube which its themed on, but also kijiji, and sometimes gmail. How do they redirect traffic like that?
Observing members:
0
Composing members:
0
20 Answers
I don’t know the specific thing to which you refer, but is sort of sounds like you are falling victim to a XSS (cross-site scripting) attack which has possibly compromised your browser. Do you use NoScript?
It could also be a function of other malware- did you download anything odd recently?
Can you provide more detail as to what is actually happening?
I don’t think there’s noscipt installed, just the basic firefox installation that ubuntu 10.4 has
I just go to www.youtube.com and instead it goes to the scam site.
Sounds like you need to run malware bytes or something.
@augustlan Well I’m on my dual boot linux laptop, which I only use for hacking and it hasnt popped up since, i’ve seen it on lots of pcs though, just a couple times then nothing.
Response moderated (Unhelpful)
Response moderated (Off-Topic)
An easy way for malware to hijack/redierct a browser is for it to edit the HOSTS file. This is a file that functions like a local DNS server. The computer will look at first to turn what you typed into the adress bar into an IP address. If it finds nothing there then it asks a DNS server to resolve it but if there is something there then it goes to where the HOSTS file tells it to.
@XOIIO
do ‘sudo cat /etc/hosts’ and post the output, ok?
Yeah anything (well most OS anyway) connected to the net does. Back before there were DNS servers thats how you knew who was where.
gimme a sec, i got my tablet running with teamviewer, my desktop with the web browser, a virtual machine on the second monitor, and the laptop to start
It looks normal
::1 localhost ip6-localhost ip6-loopback
fe00::0 ip6-localnet
ff00::0 ip6-mcastprefix
ff02::1 ip6-allnodes
ff02::2 ip6-allrouters
ff02::3 ip6-allhosts
Response moderated (Spam)
Disable all extensions and see if the problem goes away. It would pretty easy to write one that would redirect you.
Also strongly recommend you use NoScript, which among other things is designed to halt XSS attacks. NoScript basically stops all client-side scripts from executing on any Web page until/unless you explicitly allow them to run.
Here is the content of /etc/hosts on a fresh install of Ubuntu.
Well, I don’t see anything untoward in @XOIIO‘s hostfile as listed, except for the lack of an entry for IPv4 loopback (127.0.0.1). I’m not sure if that’s suspicious or not.
Perhaps we’d better get a look at hosts.allow and hosts.deny?
That said, I think it’s a great deal more likely that the redirection is taking place in the browser. If you know the urls from which you’re being redirected, you could try pinging it to see if the resolver sends you to the correct IP (check with dig or whois to make sure it’s the right one). If the redirection still happens then you know that the browser is not at fault. If that’s the case you’ll need to file a bug with ubuntu-bug. You might consider filing a bug against the browser in any case.
Response moderated (Spam)
you have made a typo error by typing *yotube* .com instead of www.youtube.com. Then you end up at that site.
Grtz,
Peter
It is. Once you answer their phone text message you are enrolled in their programme to receive text messages about great ways to make money and these will cost you $$ per text mesage. They will charge you SG $14 per week if you don’t terminate the service.
Answer this question
This question is in the General Section. Responses must be helpful and on-topic.