Logo
FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups  ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in
Ads....
Goto page Previous  1, 2
 
Post new topic   Reply to topic    www.fanart-central.net Forum Index -> FAC Site Discussion
View previous topic :: View next topic  
Author Message
Stratadrake
Elder Than Dirt


Joined: 05 May 2004
Posts: 13721
Location: Moo

PostPosted: Sat Apr 28, 2007 1:57 pm    Post subject: Reply with quote

"View Frame Source" is a standard Firefox command, it appears on the context menu when you right-click within a frame.
_________________
Strata here: [url=http://www.nanowrimo.org/eng/user/242293]Nanowrimo[/url] - [url=www.fanart-central.net/user-Stratadrake.php]FAC[/url] - [url=http://stratadrake.deviantart.com]dA[/url] - [url=www.furaffinity.net/user/Stratadrake/]FA[/url]
[size=9]Disclaimer: Posts may contain URLs. Click [url=http://tvtropes.org/pmwiki/pmwiki.php/Main/TVTropesWillRuinYourLife]at your own risk.[/url][/size]
Back to top
View user's profile Send private message
cstdenis
Evil Overlord


Joined: 31 Dec 1969
Posts: 6490
Location: In the tubes.

PostPosted: Sat Apr 28, 2007 2:01 pm    Post subject: Reply with quote

The web developer toolbar lets you do it without clicking in the frame -- which you can't do on flash ad iframes.

Also, it gives you an easy list of frame src info, and acts at least partly on javascript generated code.



Think you can write some javascript to capture that kind of info I can stick in a report ad type link?
Back to top
View user's profile Send private message Visit poster's website
Stratadrake
Elder Than Dirt


Joined: 05 May 2004
Posts: 13721
Location: Moo

PostPosted: Sat Apr 28, 2007 6:33 pm    Post subject: Reply with quote

[quote]Think you can write some javascript to...[/quote]
I know how to script a trick or two, but I'm not THAT good!

It is possible (I think) to use Javascript to iterate through a page's HTML elements, but I'm not up on the details.
_________________
Strata here: [url=http://www.nanowrimo.org/eng/user/242293]Nanowrimo[/url] - [url=www.fanart-central.net/user-Stratadrake.php]FAC[/url] - [url=http://stratadrake.deviantart.com]dA[/url] - [url=www.furaffinity.net/user/Stratadrake/]FA[/url]
[size=9]Disclaimer: Posts may contain URLs. Click [url=http://tvtropes.org/pmwiki/pmwiki.php/Main/TVTropesWillRuinYourLife]at your own risk.[/url][/size]
Back to top
View user's profile Send private message
Sora121
Developer


Joined: 02 Oct 2006
Posts: 2591
Location: I'm here some place

PostPosted: Sat Apr 28, 2007 7:30 pm    Post subject: Reply with quote

Well i'm useless with java at this point, but i can get the html of any pages i come across that have the pop up attacks on them so we can track them down easier.

and Denis, whatever you did worked out okay, i'm not seeing as many popups from clickstor now, i got one just about an hour ago but i could'nt get back to it or even find a similar one after that.
Back to top
View user's profile Send private message MSN Messenger
cstdenis
Evil Overlord


Joined: 31 Dec 1969
Posts: 6490
Location: In the tubes.

PostPosted: Sat Apr 28, 2007 8:39 pm    Post subject: Reply with quote

[quote]but i can get the html of any pages i come across that have the pop up attacks on them[/quote]

Unfortunately, that doesn't help very much due to the complexities of Javascript.
Back to top
View user's profile Send private message Visit poster's website
Sora121
Developer


Joined: 02 Oct 2006
Posts: 2591
Location: I'm here some place

PostPosted: Sat Apr 28, 2007 10:59 pm    Post subject: Reply with quote

yeah i figured as much, it shouldn't be to much longer bfore i start in to some java, after i've gotten CSS down well enough.
Back to top
View user's profile Send private message MSN Messenger
Sora121
Developer


Joined: 02 Oct 2006
Posts: 2591
Location: I'm here some place

PostPosted: Sun Apr 29, 2007 7:39 pm    Post subject: Reply with quote

Okay i think i know just where the ad is coming from. while i was building my forum with the PHPBB editor, i was testing around on it and found a few popup/unders from our good friends at clickstor, that originated from the forums, i'm begining to think that these popups we're seeing are coming from this forum, or the many Google ads we have here on the site. I'm not sure if that really helps you but thats what i've noticed the ads from clickstor originating from.

if it is not infact comeing from the forums coding in some way, then it must be from the Google ads.
Back to top
View user's profile Send private message MSN Messenger
Stratadrake
Elder Than Dirt


Joined: 05 May 2004
Posts: 13721
Location: Moo

PostPosted: Sun Apr 29, 2007 8:28 pm    Post subject: Reply with quote

I just received a popup while browsing FAC. This wasn't a popup ad, but a Javascript aler() popup.

Gathering relevant information now.

Popup:
[quote][img]http://i67.photobucket.com/albums/h316/Stratelier/popup_bad.jpg[/img][/quote]

The popup is clearly bogus. DriveCleaner is known scareware (and possibly trojan).

Banner ad shown on the page where it occured:
- [url]http://i67.photobucket.com/albums/h316/Stratelier/popup_bad2.jpg[/url]

HTML source:
[list]<!-- BEGIN RAW TAG - 728 x 90 - ARTS - DO NOT MODIFY -->
<iframe marginwidth="0" marginheight="0" src="http://ipoint.targetpoint.com/tag.php?uid=240312&wd=728&hg=90&cid=1000" frameborder="0" height="90" scrolling="no" width="728"></iframe>
<!-- END TAG -->[/list:u]

Iframe source of that banner:
[quote]<html><body style="margin-left: 0%; margin-right: 0%; margin-top: 0%; margin-bottom: 0%"><script type="text/javascript">if (window.rm_crex_data) {rm_crex_data.push(331174);}
</script><A HREF="http://ad.adserverplus.com/click,gxcAAKyLAACmDQUAD94BAAABXAAAAA4AAgABFQAABgIwCwIAyAADAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAFtnNUYAAAAA
,,http%3A%2F%2Fwww%2Efanart%2Dcentral%2Enet%2Fpic%2D577938%2Ehtml,http://ad.de.doubleclick.net/jump/N4179.oridian_netzwerk/B2195261.23;sz=728x90;ord=1177904987?" target="_blank">
<IMG SRC="http://ad.de.doubleclick.net/ad/N4179.oridian_netzwerk/B2195261.23;sz=728x90;ord=1177904987?" BORDER=0 WIDTH=728 HEIGHT=90 ALT="Hier

klicken"></A></body></html>[/quote]

But I don't know if that's enough information to track down the alert box which originally popped up.
_________________
Strata here: [url=http://www.nanowrimo.org/eng/user/242293]Nanowrimo[/url] - [url=www.fanart-central.net/user-Stratadrake.php]FAC[/url] - [url=http://stratadrake.deviantart.com]dA[/url] - [url=www.furaffinity.net/user/Stratadrake/]FA[/url]
[size=9]Disclaimer: Posts may contain URLs. Click [url=http://tvtropes.org/pmwiki/pmwiki.php/Main/TVTropesWillRuinYourLife]at your own risk.[/url][/size]


Last edited by Stratadrake on Mon Apr 30, 2007 4:01 am; edited 1 time in total
Back to top
View user's profile Send private message
Falconlobo
Forum Stalker


Joined: 18 Apr 2006
Posts: 1570
Location: Home

PostPosted: Sun Apr 29, 2007 8:59 pm    Post subject: Reply with quote

that poped up on me too and i don't have javascript

that was a weird one that poped up

or ones like that saying something about secearety exchange on the net pop up once in a while

and sorry for my bad spelling
Back to top
View user's profile Send private message
Stratadrake
Elder Than Dirt


Joined: 05 May 2004
Posts: 13721
Location: Moo

PostPosted: Mon Apr 30, 2007 3:33 am    Post subject: Reply with quote

[quote]...and i don't have javascript[/quote]
Are you sure?

The confirm() popup is especially annoying, as DriveCleaner is known rogue software:
- http://en.wikipedia.org/wiki/WinFixer
- http://en.wikipedia.org/wiki/SysProtect

And it [i]only occurs when browsing FAC[/i]. Note, however, that the popup message box originates from the DriveCleaner.com domain.
_________________
Strata here: [url=http://www.nanowrimo.org/eng/user/242293]Nanowrimo[/url] - [url=www.fanart-central.net/user-Stratadrake.php]FAC[/url] - [url=http://stratadrake.deviantart.com]dA[/url] - [url=www.furaffinity.net/user/Stratadrake/]FA[/url]
[size=9]Disclaimer: Posts may contain URLs. Click [url=http://tvtropes.org/pmwiki/pmwiki.php/Main/TVTropesWillRuinYourLife]at your own risk.[/url][/size]
Back to top
View user's profile Send private message
Benk
Elder In Training


Joined: 28 Jul 2006
Posts: 3733

PostPosted: Mon Apr 30, 2007 6:17 am    Post subject: Reply with quote

Ahh!! Winfixer!

For anyone who does not know winfixer; its pops up an ad for virus detecting softwear and opens up another iwndow no matter what you click. The only two ways to get rid of it are to wipe your harddrive or buy a product by the company who makes winfixer. But those might be outdated, that was like that when it was on my computer
Back to top
View user's profile Send private message AIM Address Yahoo Messenger
Falconlobo
Forum Stalker


Joined: 18 Apr 2006
Posts: 1570
Location: Home

PostPosted: Mon Apr 30, 2007 10:26 am    Post subject: Reply with quote

yes i'm sure i never purchached a javascript program not that i know of

i have adobe flash 9 unless that contians a javascript then i don't know
Back to top
View user's profile Send private message
unfocused
Moderator


Joined: 17 Jul 2004
Posts: 6983
Location: Texas

PostPosted: Tue May 01, 2007 12:36 am    Post subject: Reply with quote

[img]http://i4.photobucket.com/albums/y112/unfocused/untitled.png[/img]
_________________
"edit : i luv james" - Layzcarter
Back to top
View user's profile Send private message Yahoo Messenger MSN Messenger
cstdenis
Evil Overlord


Joined: 31 Dec 1969
Posts: 6490
Location: In the tubes.

PostPosted: Tue May 01, 2007 12:45 pm    Post subject: Reply with quote

I've disabled targetpoint.
Back to top
View user's profile Send private message Visit poster's website
Stratadrake
Elder Than Dirt


Joined: 05 May 2004
Posts: 13721
Location: Moo

PostPosted: Tue May 01, 2007 4:03 pm    Post subject: Reply with quote

[quote]For anyone who does not know winfixer; its pops up an ad for virus detecting softwear and opens up another iwndow no matter what you click.[/quote]
There's an easier method to avoid Winfixer infections: If the box occurs, unplug your internet connection before dismissing it.

Fortunately, far as I've seen the SysProtect popup boxes are honest enough to take "no" for an answer.
_________________
Strata here: [url=http://www.nanowrimo.org/eng/user/242293]Nanowrimo[/url] - [url=www.fanart-central.net/user-Stratadrake.php]FAC[/url] - [url=http://stratadrake.deviantart.com]dA[/url] - [url=www.furaffinity.net/user/Stratadrake/]FA[/url]
[size=9]Disclaimer: Posts may contain URLs. Click [url=http://tvtropes.org/pmwiki/pmwiki.php/Main/TVTropesWillRuinYourLife]at your own risk.[/url][/size]
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    www.fanart-central.net Forum Index -> FAC Site Discussion All times are GMT - 8 Hours
Goto page Previous  1, 2
Page 2 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum