General Question

XOIIO's avatar

Dailyvideorewards scam?

Asked by XOIIO (18328points) October 8th, 2011

How does this scam even work? I get it randomly, no matter what site I go to. Youtube which its themed on, but also kijiji, and sometimes gmail. How do they redirect traffic like that?

Observing members: 0 Composing members: 0

20 Answers

koanhead's avatar

I don’t know the specific thing to which you refer, but is sort of sounds like you are falling victim to a XSS (cross-site scripting) attack which has possibly compromised your browser. Do you use NoScript?
It could also be a function of other malware- did you download anything odd recently?

Can you provide more detail as to what is actually happening?

XOIIO's avatar

I don’t think there’s noscipt installed, just the basic firefox installation that ubuntu 10.4 has

I just go to www.youtube.com and instead it goes to the scam site.

augustlan's avatar

Sounds like you need to run malware bytes or something.

XOIIO's avatar

@augustlan Well I’m on my dual boot linux laptop, which I only use for hacking and it hasnt popped up since, i’ve seen it on lots of pcs though, just a couple times then nothing.

Response moderated (Unhelpful)
Response moderated (Off-Topic)
Lightlyseared's avatar

An easy way for malware to hijack/redierct a browser is for it to edit the HOSTS file. This is a file that functions like a local DNS server. The computer will look at first to turn what you typed into the adress bar into an IP address. If it finds nothing there then it asks a DNS server to resolve it but if there is something there then it goes to where the HOSTS file tells it to.

XOIIO's avatar

@Lightlyseared Ubuntu has a hosts file?

koanhead's avatar

@XOIIO

do ‘sudo cat /etc/hosts’ and post the output, ok?

Lightlyseared's avatar

Yeah anything (well most OS anyway) connected to the net does. Back before there were DNS servers thats how you knew who was where.

XOIIO's avatar

gimme a sec, i got my tablet running with teamviewer, my desktop with the web browser, a virtual machine on the second monitor, and the laptop to start

XOIIO's avatar

It looks normal

::1 localhost ip6-localhost ip6-loopback
fe00::0 ip6-localnet
ff00::0 ip6-mcastprefix
ff02::1 ip6-allnodes
ff02::2 ip6-allrouters
ff02::3 ip6-allhosts

Response moderated (Spam)
jrpowell's avatar

Disable all extensions and see if the problem goes away. It would pretty easy to write one that would redirect you.

koanhead's avatar

Also strongly recommend you use NoScript, which among other things is designed to halt XSS attacks. NoScript basically stops all client-side scripts from executing on any Web page until/unless you explicitly allow them to run.

jrpowell's avatar

Here is the content of /etc/hosts on a fresh install of Ubuntu.

koanhead's avatar

Well, I don’t see anything untoward in @XOIIO‘s hostfile as listed, except for the lack of an entry for IPv4 loopback (127.0.0.1). I’m not sure if that’s suspicious or not.
Perhaps we’d better get a look at hosts.allow and hosts.deny?

That said, I think it’s a great deal more likely that the redirection is taking place in the browser. If you know the urls from which you’re being redirected, you could try pinging it to see if the resolver sends you to the correct IP (check with dig or whois to make sure it’s the right one). If the redirection still happens then you know that the browser is not at fault. If that’s the case you’ll need to file a bug with ubuntu-bug. You might consider filing a bug against the browser in any case.

Response moderated (Spam)
PeterContinu's avatar

you have made a typo error by typing *yotube* .com instead of www.youtube.com. Then you end up at that site.

Grtz,

Peter

buddyperx's avatar

It is. Once you answer their phone text message you are enrolled in their programme to receive text messages about great ways to make money and these will cost you $$ per text mesage. They will charge you SG $14 per week if you don’t terminate the service.

Answer this question

Login

or

Join

to answer.

This question is in the General Section. Responses must be helpful and on-topic.

Your answer will be saved while you login or join.

Have a question? Ask Fluther!

What do you know more about?
or
Knowledge Networking @ Fluther