Bitcoin Forum
November 09, 2024, 08:19:41 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [SOLVED] what did my browser eat?  (Read 837 times)
groggin (OP)
Legendary
*
Offline Offline

Activity: 1894
Merit: 1001



View Profile
January 26, 2014, 09:13:29 PM
Last edit: February 04, 2014, 05:14:29 PM by groggin
 #1

 something not very good, i fear - where did that stupid cop come from anyway?  (scroll down please)


      

 he used to have a stupid button underneath him that said "I understand the risks" and you could click it and proceed, but that option seems to have vanished, wtf..

 is it a b.h.o.? malware? idk but its gotta go, it's in firefox and chrome on my tower pc running win7 (multi-boot w/linuxmint and win xp, the problem only exists in win 7)
 recently, i've just been uninstalling and re-installing browsers, gets me around for a day or two, but it creeps back in somehow, can anyone help? thanks!



loose the sword that is your pen or tongue [or bittorrent enabled computer] and help fight the so-called new world order   it is the enemy of humanity[/b][/url]  |  Sign-up @ Aurovine to get FREE HD music ... and coins!| |
tanalith
Newbie
*
Offline Offline

Activity: 36
Merit: 0


View Profile
January 26, 2014, 09:58:27 PM
 #2

I think there maybe some cache poisoning going around, try to use the google dns servers and see if you still get a certificate for an unregistered domain...
Kenshin
Sr. Member
****
Offline Offline

Activity: 280
Merit: 250


View Profile
January 26, 2014, 10:01:21 PM
 #3

I think there maybe some cache poisoning going around, try to use the google dns servers and see if you still get a certificate for an unregistered domain...

BTW, that is 8.8.8.8 and 8.8.4.4
msc
Sr. Member
****
Offline Offline

Activity: 284
Merit: 250



View Profile
January 26, 2014, 10:05:43 PM
 #4

he used to have a stupid button underneath him that said "I understand the risks" and you could click it and proceed, but that option seems to have vanished, wtf..
I noticed that on Firefox a while back, but you don't want to proceed in this case.  You've got a DNS problem or malware.
bitpop
Legendary
*
Offline Offline

Activity: 2912
Merit: 1060



View Profile WWW
January 27, 2014, 08:03:21 AM
 #5

Wipe hdd immediately

U1TRA_L0RD
Full Member
***
Offline Offline

Activity: 126
Merit: 100

CAUTION: Angry Man with Attitude.


View Profile
January 27, 2014, 03:16:20 PM
 #6

Wipe hdd immediately
lol, Without backing up bitcoin wallets?  Cheesy

What is it anyway, I sometimes get those too.  Shocked
OnkelPaul
Legendary
*
Offline Offline

Activity: 1039
Merit: 1005



View Profile
January 27, 2014, 03:23:45 PM
 #7

You should certainly not enter your bitcointalk password on that site. It's a man-in-the-middle attack, and any passwords you enter there will be used by hackers.

One can only guess what's been compromised on your win7 installation - probably the hosts file or some DNS settings. In any case, you should not use this windows system for anything moderately valuable before you've found and removed all compromised files.
(which probably means it's safest to do a complete reinstall)

Onkel Paul

bitpop
Legendary
*
Offline Offline

Activity: 2912
Merit: 1060



View Profile WWW
January 27, 2014, 03:25:02 PM
 #8

Lol look at the domain in the page

groggin (OP)
Legendary
*
Offline Offline

Activity: 1894
Merit: 1001



View Profile
January 27, 2014, 03:56:38 PM
 #9


 thanks for the responses, i'm glad to say i use mostly linuxmint! i'll try changing the dns server next reboot, (it'll prolly not stay changed tho, i think) then maybe scan from win xp ...

tho most likely i'll end up reformatting, then repairing grub. glad i keep my OS partitions small, and data elsewhere  Smiley     thanks again!

loose the sword that is your pen or tongue [or bittorrent enabled computer] and help fight the so-called new world order   it is the enemy of humanity[/b][/url]  |  Sign-up @ Aurovine to get FREE HD music ... and coins!| |
rme
Hero Member
*****
Offline Offline

Activity: 756
Merit: 504



View Profile
January 27, 2014, 03:58:49 PM
 #10


 he used to have a stupid button underneath him that said "I understand the risks" and you could click it and proceed, but that option seems to have vanished, wtf..


Thanks to my suggestion, they implemented HSTS.
That tells the browser that a secure connection is required always.

That is why there is no button, you must have a secure connection.

groggin (OP)
Legendary
*
Offline Offline

Activity: 1894
Merit: 1001



View Profile
January 27, 2014, 04:34:37 PM
 #11


 he used to have a stupid button underneath him that said "I understand the risks" and you could click it and proceed, but that option seems to have vanished, wtf..


Thanks to my suggestion, they implemented HSTS.
That tells the browser that a secure connection is required always.

That is why there is no button, you must have a secure connection.



thanks to you good sir 

loose the sword that is your pen or tongue [or bittorrent enabled computer] and help fight the so-called new world order   it is the enemy of humanity[/b][/url]  |  Sign-up @ Aurovine to get FREE HD music ... and coins!| |
drakoin
Hero Member
*****
Offline Offline

Activity: 826
Merit: 1000

see my profile


View Profile
January 27, 2014, 08:18:51 PM
 #12

the same sometimes happens with google results.

searching for something here on bitcointalk with google
(because there I am allowed to search more often per time)

I sometimes get results with an IP address instead of btct

... [some trying] ...


yes, here's an example:
https://duckduckgo.com/?q=ann+altcoin+giveaway+g!

scroll down 7 hits to "flushcoin"

and click.



same procedure.

That is not an infected OS.
Is that an infected search engine?





no sign of a signature
msc
Sr. Member
****
Offline Offline

Activity: 284
Merit: 250



View Profile
January 27, 2014, 08:36:30 PM
 #13

That is not an infected OS.
Is that an infected search engine?
Well no, that's not an attack, it's just that the search engine has indexed a URL using the IP address instead of the domain name.  If you click that link, then on the error page change https to http, it'll redirect you to the real forum.

But, without knowing the domain name, the browser can't tell if it's legit or not.  

It's actually an error on the forum's part, I think.  If you access the IP address using http, it redirects you to the domain name.  But using https, it doesn't.  Not that the forum must do a redirect, but it's nice when possible.
groggin (OP)
Legendary
*
Offline Offline

Activity: 1894
Merit: 1001



View Profile
February 04, 2014, 05:12:23 PM
 #14


  Well, thanks OnkelPaul for mentioning the hosts file! had a look at it and sho'nuff bitcointalk was there. a simple # and it's working fine again. (so far  Roll Eyes)
i use hostsman, and use all the available update sources, so i guess someone has our forum listed in there, incase staff wants to do something about it.
changing the dns server was not helpful
thanks again all

loose the sword that is your pen or tongue [or bittorrent enabled computer] and help fight the so-called new world order   it is the enemy of humanity[/b][/url]  |  Sign-up @ Aurovine to get FREE HD music ... and coins!| |
bitpop
Legendary
*
Offline Offline

Activity: 2912
Merit: 1060



View Profile WWW
February 04, 2014, 05:26:52 PM
 #15


  Well, thanks OnkelPaul for mentioning the hosts file! had a look at it and sho'nuff bitcointalk was there. a simple # and it's working fine again. (so far  Roll Eyes)
i use hostsman, and use all the available update sources, so i guess someone has our forum listed in there, incase staff wants to do something about it.
changing the dns server was not helpful
thanks again all

Why do you use that?

OnkelPaul
Legendary
*
Offline Offline

Activity: 1039
Merit: 1005



View Profile
February 04, 2014, 07:18:42 PM
 #16


  Well, thanks OnkelPaul for mentioning the hosts file! had a look at it and sho'nuff bitcointalk was there.

You're welcome! What address was in the host file? Although it was probably a compromised host, it might give a hint about the source of this attack.
Regarding hostsman: Don't let such tools mess around with your networking setup! A computer being used with bitcoins or other crypto stuff should have as few modifications relative to a secure baseline as possible.

Onkel Paul

groggin (OP)
Legendary
*
Offline Offline

Activity: 1894
Merit: 1001



View Profile
February 04, 2014, 07:45:27 PM
 #17

Quote from: OnkelPaul
What address was in the host file?

here's a copy-paste from it

bitcoinmegastore.com
bitcoinsgenerator.net
bitcointalk.org
bitcointipbot.com
bitcointips.net
bitdoctor.ru
bitdoctors.ru
bitdownload.biz
bitenova.nl


Quote from: bitpop
Why do you use that?

  i like the way it blocks many ads + unfriendly sites - another layer of protection Smiley

loose the sword that is your pen or tongue [or bittorrent enabled computer] and help fight the so-called new world order   it is the enemy of humanity[/b][/url]  |  Sign-up @ Aurovine to get FREE HD music ... and coins!| |
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!