Ghacks website delivering malware

Discussion in 'other software & services' started by stapp, Sep 22, 2023.

  1. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    27,623
    Location:
    UK
  2. nicolaasjan

    nicolaasjan Registered Member

    Joined:
    Sep 23, 2018
    Posts:
    989
    Location:
    The Netherlands
    I think it's fixed.
    The redirect to the malicious domain ~ Domain Mention Removed ~ is no longer in the source.
     
  3. nicolaasjan

    nicolaasjan Registered Member

    Joined:
    Sep 23, 2018
    Posts:
    989
    Location:
    The Netherlands
  4. plat

    plat Registered Member

    Joined:
    Dec 19, 2018
    Posts:
    2,233
    Location:
    Brooklyn, NY
  5. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    6,313
    the major problem is that CSS and also 3rd-party is not blocked by default. users need to adjust their content filters! means, see, what adblocker can do for you, uBlock can do.

    *$stylesheet,3p

    ofc this means to set exclusions
     
  6. Bertazzoni

    Bertazzoni Registered Member

    Joined:
    Apr 13, 2018
    Posts:
    751
    Location:
    Milan, Italia
    Or µBO Hard Mode! :thumb::cool:
     
  7. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    6,313
    Is hard mode a recommended usage?
    https://github.com/gorhill/uBlock/wiki/Blocking-mode:-hard-mode

    Except "3rd-party" ("Ressourcen aus Drittquellen") which is set to noop the other 3rd-party is blocked here too by default. But that results in some exclusions, and i have in mind that someone recommended noop might better in general.

    ofc my personal blocklist in ublock=umatrix is growing over time (180 entries that far)
    (although uM is not supported it does a good job in blocking sites where uBo is disabled for trialing)
     
  8. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,259
    Yes, much easier.
     
  9. B-boy/StyLe/

    B-boy/StyLe/ Registered Member

    Joined:
    Sep 19, 2012
    Posts:
    520
    Location:
    Bulgaria
    Hard mode didn't really work on the test page here for me:

    https://www.mike-gualtieri.com/css-exfil-vulnerability-tester

    But adding the * * 1p-script block rule along with the other two used by the Medium Mode worked.

    * * 3p-frame block
    * * 3p-script block

    Indeed, some website will require exceptions, but it is what is it. :)
     
  10. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,259
    Hard mode only protects against cross-domain CSS, of course. And blocking 1st-party scripts doesn't show any results on that site as it requires javascript.

    So cross-domain CSS is blocked by Hard Mode. And if it comes to same-origin CSS, I can only confirm what arkenfox writes:

     
  11. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,867
    Location:
    Italy
    The problem would have been avoided even with uBlock Origin in Hard Mode + TLD's.
    Or with Adguard MV3 in Hard Mode + TLD.

    Personally, I would have avoided the problem even with just the TLDs I set up in Next DNS.
     
  12. B-boy/StyLe/

    B-boy/StyLe/ Registered Member

    Joined:
    Sep 19, 2012
    Posts:
    520
    Location:
    Bulgaria
    But it didn't block the JS script on the test page, or you will see that JS is needed. This is not how you perform the test. I tried that with NoScript and the test failed with a warning that JS is needed. When selected Custom and unchecked script and noscript then JS was active, but the test was successful (no images loaded). The same was achieved with the 1st-party rules in the uBlock settings. That was I meant.
     
  13. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    I see a long discussion about uBlock in this thread, but against this kind of stuff it can't protect right? I mean if the website is hacked it will of course show you the fake browser update or whatever, I sometimes see it on other sites too.
     
  14. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    6,313
    you have uncounted problems with ublock and vivaldi. your point of interest should be elsewhere but not here.
     
  15. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    For the third time:

    Think before you speak/write, because now it's just jibberish. This hasn't got anything to do with Vivaldi, I'm just saying we can't expect uBlock to block everything. But I see people talking about uBlock's hard mode, so I wonder what this is all about.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice