Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old October 25th, 2012, 04:14 AM
Ritho Ritho is offline
Infrequent Poster
 
Join Date: Aug 2011
Posts: 3
Default Is this a malware problem or browser bug?

Hi guys,

I was looking at a site for a guy that was complaining that his css was not working when the site was loading in https. I use Sandboxie, and when I checked the site in Google Chrome (with its sandbox disabled using the --no-sandbox perimeter )for a brief moment the black windows run cmd.exe dialogue popped up. (This was on windows XP SP3) I tested it several times and the same thing happened each time.

So I decided to use the browserling.com service to check out what is happening. This is where it got interesting. When testing the site in Internet Explorer 9 it does the same thing, but I end up being directed to the system32 folder on the virtual machine which is not suposed to be able to happen. I closed the session and tried several times, and a each time something else weird seemed to happen.

I tested IE 8 running in sandboxie on my test machine and nothing happened.

Anyway I can't find an infection on the client's machine. I am including the troublesome url, but altering it to keep any one from inadvertently clicking it.

https://www.listenup(dot)com/

P.S. I understand the use of Google Chrome without its sandbox feature enabled is a security risk, I do it for various testing reasons, which is why it was running in Sandboxie.
  #2  
Old October 25th, 2012, 05:40 AM
Get's Avatar
Get Get is offline
Frequent Poster
 
Join Date: Nov 2009
Location: the Netherlands
Posts: 374
Default Re: Is this a malware problem or browser bug?

When I go there with Firefox it opens normal. When I use Chrome (no sandbox) I get a page which tells me not to proceed, because the certificate of the site isn't trusted (translation, text is in dutch). It's not verified by a 3th party, so it could be a hacker which is trying to make you believe it's the real site.
__________________
if I were you I wouldn't bother,
for there are brighter sides to life and I should know,
because I've seen them,
but not very often.
  #3  
Old October 25th, 2012, 05:47 AM
Get's Avatar
Get Get is offline
Frequent Poster
 
Join Date: Nov 2009
Location: the Netherlands
Posts: 374
Default Re: Is this a malware problem or browser bug?

Btw Ritho, wanna cut the reward in half when someone gives you the right answer...?

http://jobs.wordpress.net/2012/10/17...x-this-for-me/

...
__________________
if I were you I wouldn't bother,
for there are brighter sides to life and I should know,
because I've seen them,
but not very often.
  #4  
Old October 25th, 2012, 06:24 AM
Ritho Ritho is offline
Infrequent Poster
 
Join Date: Aug 2011
Posts: 3
Default Re: Is this a malware problem or browser bug?

Quote:
Originally Posted by Get
Btw Ritho, wanna cut the reward in half when someone gives you the right answer...?

http://jobs.wordpress.net/2012/10/17...x-this-for-me/

...

Doing your homework I see. Well I am 99% certain that the two problems are not connected. In fact I don't know if what I mention above is actually a problem. I think the css problem is coming from wordpress itself and has nothing to do with the ssl. I believe there are actually two problems at work with the guys css.

Anyway the certificate that I am getting from the site is perfectly valid and has no dutch or anything like that.
  #5  
Old October 25th, 2012, 06:30 AM
Get's Avatar
Get Get is offline
Frequent Poster
 
Join Date: Nov 2009
Location: the Netherlands
Posts: 374
Default Re: Is this a malware problem or browser bug?

The dutch isn't in the certificate. It's chrome which is in dutch and "tells" me not to proceed.
__________________
if I were you I wouldn't bother,
for there are brighter sides to life and I should know,
because I've seen them,
but not very often.
  #6  
Old October 25th, 2012, 06:49 AM
Ritho Ritho is offline
Infrequent Poster
 
Join Date: Aug 2011
Posts: 3
Default Re: Is this a malware problem or browser bug?

I see I read what you wrote wrong. The warning you are getting is likely because some of the css is not being delivered via https, so there are both secure and non secure elements on the page. Some browsers balk at none secure style sheets while others don't. I have no idea why you are getting a message that the certificate is not verified by a third party, because on my test machines it passes verification just fine from RapidSSL Geotrust
  #7  
Old October 25th, 2012, 02:35 PM
m00nbl00d m00nbl00d is online now
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,439
Default Re: Is this a malware problem or browser bug?

Quote:
Originally Posted by Ritho
I see I read what you wrote wrong. The warning you are getting is likely because some of the css is not being delivered via https, so there are both secure and non secure elements on the page. Some browsers balk at none secure style sheets while others don't. I have no idea why you are getting a message that the certificate is not verified by a third party, because on my test machines it passes verification just fine from RapidSSL Geotrust

I didn't visit the website, but what user Get mentions has nothing to do with insecure content. Whenever a website has both secure and insecure content, Google Chrome will simply block the insecure content, and then the user can choose to allow it (there should be an icon in the address bar... it appears in Chromium builds for quite some time now). The red warning about the certificate is a different matter - Google Chrome simply can't verify the certificate as being a valid one, and will alert the user for that.
  #8  
Old October 25th, 2012, 02:37 PM
AMIGA500's Avatar
AMIGA500 AMIGA500 is online now
Very Frequent Poster
 
Join Date: May 2012
Location: United Kingdom.
Posts: 2,567
Default Re: Is this a malware problem or browser bug?

Comodo dragon does the same also and checks for ssl authentication.
__________________
Avira Free Antivirus.||Comodo Firewall 5.12.||Sandboxie.||MBAM free version.||

For we wrestle not against flesh and blood, but against principalities, against powers, and against the worldly governors, the princes of the darkness of this world...
  #9  
Old October 26th, 2012, 05:01 AM
PJC PJC is offline
Very Frequent Poster
 
Join Date: Feb 2010
Location: Internet
Posts: 2,962
Question Is this a malware problem or browser bug?

Quote:
Originally Posted by Get
When I go there with Firefox it opens normal.
Is it the first time that Firefox opens a webpage without a problem while Chrome cannot?
Is it?
  #10  
Old October 26th, 2012, 09:26 AM
Get's Avatar
Get Get is offline
Frequent Poster
 
Join Date: Nov 2009
Location: the Netherlands
Posts: 374
Default Re: Is this a malware problem or browser bug?

@Mr.PC: I don't use Chrome. I only installed it, because FF and Opera didn't handle ebay well when uploading a picture to a sale and Chrome did, so I can't tell whether it's frequent or not.
__________________
if I were you I wouldn't bother,
for there are brighter sides to life and I should know,
because I've seen them,
but not very often.
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:52 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums