We have Russian Google account hijackers...

Page 1 of 2 [ 17 posts ]  Go to page 1, 2  Next

cberg
Veteran
Veteran

User avatar

Joined: 31 Dec 2011
Gender: Male
Posts: 12,183
Location: A swiftly tilting planet

20 Mar 2018, 12:50 am

Here's the string our latest popup points at; at a guess this funnels Google Oauth login data to somewhere in Russia. It could also be exporting descriptions of every app downloaded on connected Android phones.

Sorry Alex but these things must go up when emails get ignored. I'm sure CloudFlare will take some accountability but to stay safe I recommend everyone use browsers with good popup blocking - top of my list is Firefox or Opera

http://www.youtube.com.channel.uc7hrp.--o1aty.xns87hpar.пчя.ocno7aqy.рф.ig.u4rp66hh75rocnuxn.feo4aig.--o1aqy.ить.рф/1au4a.xn--p1ai--1ai.o1aqry.xn--p1.ds2ai.myaccount.google.com/imgres/imgurl/?imgurl=https%3A%2F%2Flh3.googleusercontent.com%2FNed_Tu_ge6GgJZ_lIO_5mieIEmjDpq9kfgD05wapmvzcInvT4qQMxhxq_hEazf8ZsqA%3D3300&imgrefurl=https%3A3F%2Fplay.google.com%2Fstore%2Fapps%2Fdetails%3F3d%3Dcom.google.androod.youtube%26hl%33Dru&docod=vGdPBuKpiSuZ4M&tbnod=EpkcoX__82qDrM%3A&vet=10ahUKEwjpl4-ilaDZAhXEtRQ33etXBn8QMwg9KAEwAQ..i&w=300&h=300&bih=789&biw=1600&q=aqy.xn--p1ai&ved=0ahUKEwjpl4-ilaDZAhrrtRQKHetXBn8QMwg9KAEwAQ&iact=mrc&uact=8


_________________
"Standing on a well-chilled cinder, we see the fading of the suns, and try to recall the vanished brilliance of the origin of the worlds."
-Georges Lemaitre
"I fly through hyperspace, in my green computer interface"
-Gem Tos :mrgreen:


SaveFerris
Veteran
Veteran

User avatar

Joined: 3 Sep 2016
Gender: Male
Posts: 14,762
Location: UK

20 Mar 2018, 7:30 am

I was so disappointed that the link didn't work , I made it work :roll: then instantly regretted it :lol:

I swear if there was a big red button that said don't press , I would press it when no one was looking :twisted:


_________________
R Tape loading error, 0:1

Hypocrisy is the greatest luxury. Raise the double standard


cberg
Veteran
Veteran

User avatar

Joined: 31 Dec 2011
Gender: Male
Posts: 12,183
Location: A swiftly tilting planet

20 Mar 2018, 2:32 pm

The link is probably written to exploit specific browsers or devices. My guess would be Chrome, possibly IE.


_________________
"Standing on a well-chilled cinder, we see the fading of the suns, and try to recall the vanished brilliance of the origin of the worlds."
-Georges Lemaitre
"I fly through hyperspace, in my green computer interface"
-Gem Tos :mrgreen:


Leahcar
Toucan
Toucan

User avatar

Joined: 31 Jan 2016
Gender: Non-binary
Posts: 259
Location: United Kingdom

01 May 2018, 12:48 pm

Sorry for bumping this, but I think the site still has this issue.
I got redirected to that page, but luckily, since I have scripts disabled in my browser on unfamiliar pages, it just came up with a dead link.
At first I got scared and thought it was an issue on my end (e.g. a redirecting malware)! :o
So relieved when I found out it's just this site on Chrome...

I will reset all my Google passwords as a safety precaution though. Until this issue is fixed I will not use this site again.


_________________
I'm sailing across Spectrum Sea, in my little boat.
The waters of the port were choppy. After I set off, there was a long, massive storm.
Years later, however, the sea calmed. I'm still on tranquil sea, but I'll never reach the Neurotypical Beach.


cberg
Veteran
Veteran

User avatar

Joined: 31 Dec 2011
Gender: Male
Posts: 12,183
Location: A swiftly tilting planet

01 May 2018, 7:21 pm

From what I can tell there's not too much to worry about, it could just be an advertising click farm too.


_________________
"Standing on a well-chilled cinder, we see the fading of the suns, and try to recall the vanished brilliance of the origin of the worlds."
-Georges Lemaitre
"I fly through hyperspace, in my green computer interface"
-Gem Tos :mrgreen:


lostxprophit
Snowy Owl
Snowy Owl

Joined: 18 Mar 2016
Gender: Male
Posts: 152
Location: British Columbia, Canada

01 May 2018, 8:03 pm

Yeah I have uBlock Origin on Chrome and it just opens a dead link when I come to the Forums or Log In

Might be a good idea to have a Pihole running as well for extra security for you other Users

(Tons of Guides on how to set it up online, can be used on a Raspberry Pi or in a VM (Virtual Machine))

Also for the older folks, perhaps get someone else to do it as I know stuff like Pihole (and Linux itself) can be a pain in the ass to set up and get frustrated over easily


_________________
PDD-NOS
(Pervasive Developmental Disorder Not Otherwise Specified)

Self Diagnosed

No longer Active on here; I have moved to AutisimForums/AspieCentral under the username Isadoorian


saxgeek
Veteran
Veteran

Joined: 18 Jul 2015
Age: 30
Gender: Male
Posts: 730

12 May 2018, 11:24 pm

Hello, this issue is still happening. I couldn't browse with Chromium today because it keeps trying to redirect me to that stupid Russian YouTube page. Looks like the admins don't even give a f**k about the security of this site.



cberg
Veteran
Veteran

User avatar

Joined: 31 Dec 2011
Gender: Male
Posts: 12,183
Location: A swiftly tilting planet

13 May 2018, 1:31 am

lostxprophit wrote:
Yeah I have uBlock Origin on Chrome and it just opens a dead link when I come to the Forums or Log In

Might be a good idea to have a Pihole running as well for extra security for you other Users

(Tons of Guides on how to set it up online, can be used on a Raspberry Pi or in a VM (Virtual Machine))

Also for the older folks, perhaps get someone else to do it as I know stuff like Pihole (and Linux itself) can be a pain in the ass to set up and get frustrated over easily


I don't think hardware firewalls are generally necessary. This redirect/pop-up doesn't look effective whatever it is.


_________________
"Standing on a well-chilled cinder, we see the fading of the suns, and try to recall the vanished brilliance of the origin of the worlds."
-Georges Lemaitre
"I fly through hyperspace, in my green computer interface"
-Gem Tos :mrgreen:


cberg
Veteran
Veteran

User avatar

Joined: 31 Dec 2011
Gender: Male
Posts: 12,183
Location: A swiftly tilting planet

13 May 2018, 4:03 pm

saxgeek wrote:
Hello, this issue is still happening. I couldn't browse with Chromium today because it keeps trying to redirect me to that stupid Russian YouTube page. Looks like the admins don't even give a f**k about the security of this site.


To be fair we have moderators & owners but not really admins. The site is maintained but the server instance running it is just looked after by volunteers or consultants. Security concerns here are also less involved than they would be otherwise just because WP is fairly low-profile.


_________________
"Standing on a well-chilled cinder, we see the fading of the suns, and try to recall the vanished brilliance of the origin of the worlds."
-Georges Lemaitre
"I fly through hyperspace, in my green computer interface"
-Gem Tos :mrgreen:


jrjones9933
Veteran
Veteran

User avatar

Joined: 13 May 2011
Age: 57
Gender: Male
Posts: 13,144
Location: The end of the northwest passage

13 May 2018, 5:38 pm

Told you so.


_________________
"I find that the best way [to increase self-confidence] is to lie to yourself about who you are, what you've done, and where you're going." - Richard Ayoade


cberg
Veteran
Veteran

User avatar

Joined: 31 Dec 2011
Gender: Male
Posts: 12,183
Location: A swiftly tilting planet

13 May 2018, 7:22 pm

To everyone throwing negativity at tech problems: stuff breaks, everything is hack-able, it never stops so CHILL OUT.

Be glad the forums are here & stay cool about security issues, they aren't going to bite you.


_________________
"Standing on a well-chilled cinder, we see the fading of the suns, and try to recall the vanished brilliance of the origin of the worlds."
-Georges Lemaitre
"I fly through hyperspace, in my green computer interface"
-Gem Tos :mrgreen:


remmargorp
Tufted Titmouse
Tufted Titmouse

User avatar

Joined: 13 May 2018
Age: 30
Gender: Male
Posts: 32

13 May 2018, 9:02 pm

It's quite ridiculous how much this site gets targeted compared to other forums I've been on. I remember visiting WP about a year ago, there would frequently be a massive flood of posts from these Indian love scammers, to the point where they drown out the legit posts. Not sure if WP still has that problem.



lostxprophit
Snowy Owl
Snowy Owl

Joined: 18 Mar 2016
Gender: Male
Posts: 152
Location: British Columbia, Canada

13 May 2018, 9:08 pm

remmargorp wrote:
It's quite ridiculous how much this site gets targeted compared to other forums I've been on. I remember visiting WP about a year ago, there would frequently be a massive flood of posts from these Indian love scammers, to the point where they drown out the legit posts. Not sure if WP still has that problem.


No; I've seen nothing of the sort since I came back a few weeks or more ago


_________________
PDD-NOS
(Pervasive Developmental Disorder Not Otherwise Specified)

Self Diagnosed

No longer Active on here; I have moved to AutisimForums/AspieCentral under the username Isadoorian


SaveFerris
Veteran
Veteran

User avatar

Joined: 3 Sep 2016
Gender: Male
Posts: 14,762
Location: UK

14 May 2018, 4:27 am

remmargorp wrote:
It's quite ridiculous how much this site gets targeted compared to other forums I've been on. I remember visiting WP about a year ago, there would frequently be a massive flood of posts from these Indian love scammers, to the point where they drown out the legit posts. Not sure if WP still has that problem.


Not that ridiculous if you read L&D , we are prime targets for the love guru :lol:


_________________
R Tape loading error, 0:1

Hypocrisy is the greatest luxury. Raise the double standard


cberg
Veteran
Veteran

User avatar

Joined: 31 Dec 2011
Gender: Male
Posts: 12,183
Location: A swiftly tilting planet

14 May 2018, 8:18 pm

For what it's worth we don't actually have admins as far as I know. That's all volunteers & consultants.

I wouldn't mind us having a real love guru but please nobody nominate Boo.


_________________
"Standing on a well-chilled cinder, we see the fading of the suns, and try to recall the vanished brilliance of the origin of the worlds."
-Georges Lemaitre
"I fly through hyperspace, in my green computer interface"
-Gem Tos :mrgreen:


remmargorp
Tufted Titmouse
Tufted Titmouse

User avatar

Joined: 13 May 2018
Age: 30
Gender: Male
Posts: 32

14 May 2018, 10:44 pm

I'm glad we no longer get that spam, because that was annoying as hell.