Page 1 of 1 [ 2 posts ] 

Lorn
Hummingbird
Hummingbird

User avatar

Joined: 10 May 2007
Gender: Male
Posts: 22
Location: NE England

22 Jul 2007, 2:52 am

Quatermass wrote:
I didn't attempt to download it, I knew it was bogus, but when I closed it, it attempted to download regardless. Only my antivirus intercepted it in time.

You're using IE, aren't you :p

Hurrah for Firefox!



0_equals_true
Veteran
Veteran

User avatar

Joined: 5 Apr 2007
Age: 44
Gender: Male
Posts: 11,038
Location: London

22 Jul 2007, 5:53 am

Lorn wrote:
alex - It was just like a normal ad in a normal place. Nothing more, except it was for Drivecleaner and it had javascript in it.

I think it was the top ad bit though.

Yes javascript replaces the normal banner with drivecleaner. I've got a special JavaScript debugger which will show attempts to hide the true operation of the code. I have to trall through each of the javasprits that have been called in relation to this site. I found vulnerabilities in sites before including ebay, I'll give it a shot.

Alex it typically happens after clicking new post, when the new post page load after a short timeout.