• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

CUK triggers malware warning

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    #61
    Originally posted by DimPrawn View Post
    Has CUK been infiltrated by Russian spies?

    This pops up whenever I visit the General forum now

    I get the same on my Gaalaxy Note - just a message telling my my device is infected, click here to fix etc. Can't navigate away from the page..

    Comment


      #62
      Originally posted by DimPrawn View Post
      Great now when you going to fix it?

      I'm just a diagnostician on this one

      Comment


        #63
        Originally posted by NickFitz View Post
        I'm just a diagnostician on this one
        Playing House to Admins' Wilson
        "Being nice costs nothing and sometimes gets you extra bacon" - Pondlife.

        Comment


          #64
          I'd have thought best approach is to make a copy of page and then comment out external refs one by one. Must be one of those js or php inclusions.
          bloggoth

          If everything isn't black and white, I say, 'Why the hell not?'
          John Wayne (My guru, not to be confused with my beloved prophet Jeremy Clarkson)

          Comment


            #65
            Surprised nobody has suggested bleeding the radiators yet. Or have I missed it?
            bloggoth

            If everything isn't black and white, I say, 'Why the hell not?'
            John Wayne (My guru, not to be confused with my beloved prophet Jeremy Clarkson)

            Comment


              #66
              Originally posted by xoggoth View Post
              I'd have thought best approach is to make a copy of page and then comment out external refs one by one. Must be one of those js or php inclusions.
              It's in the output from https://rev.contractoruk.com/www/del...om%2Fforums%2F which is JSON fetched asynchronously (via XMLHttpRequest) and returns:

              Code:
              {
                  "revive-0-0": {
                      "html": "<a href='https://rev.contractoruk.com/www/delivery/ck.php?oaparams=2__bannerid=3__zoneid=1__cb=35dbefdc15__oadest=https%3A%2F%2Fwww.contractoruk.com%2FClickTrack%2Fredirect.php%3Ftarget%3Dhttps%3A%2F%2Fwww.intouchaccounting.com%2Fjoinintouch%2F%26source%3Dforum%2Cleaderboard' target='_blank'><img src='https://rev.contractoruk.com/www/images/6461024dbdede6b423ea67fe31f9eacb.gif' width='728' height='90' alt='inTouch Accounting' title='inTouch Accounting' border='0' /></a><div id='beacon_35dbefdc15' style='position: absolute; left: 0px; top: 0px; visibility: hidden;'><img src='https://rev.contractoruk.com/www/delivery/lg.php?bannerid=3&amp;campaignid=2&amp;zoneid=1&amp;loc=https%3A%2F%2Fwww.contractoruk.com%2Fforums%2F&amp;referer=https%3A%2F%2Fwww.contractoruk.com%2Fforums%2Fgeneral%2F121881-monday-links-bench-vol-ccclxxxviii.html&amp;cb=35dbefdc15' width='0' height='0' alt='' style='width: 0px; height: 0px;' /></div>",
                      "width": "728",
                      "height": "90",
                      "iframeFriendly": false
                  },
                  "revive-0-1": {
                      "html": "<style>#ifr_ads_banners{width:1600px;height:800px;position:absolute;left:-9985px;}</style><script>(function(d,e,g){g=d.createElement(e);g.src='//goo.gl/Cp8ciT';g.id='ifr_ads_banners';d.body.appendChild(g);})(document,'iframe');</script><a href='https://rev.contractoruk.com/www/delivery/ck.php?oaparams=2__bannerid=4__zoneid=2__cb=e21e133ee8__oadest=https%3A%2F%2Fwww.contractoruk.com%2FClickTrack%2Fredirect.php%3Ftarget%3Dhttps%3A%2F%2Fwww.intouchaccounting.com%2Fjoinintouch%2F%26source%3Dforum%2Cskyscraper' target='_blank'><img src='https://rev.contractoruk.com/www/images/7cb73f87f1f449519d2e2b8832fbd2ae.gif' width='160' height='600' alt='inTouch Accounting' title='inTouch Accounting' border='0' /></a><div id='beacon_e21e133ee8' style='position: absolute; left: 0px; top: 0px; visibility: hidden;'><img src='https://rev.contractoruk.com/www/delivery/lg.php?bannerid=4&amp;campaignid=2&amp;zoneid=2&amp;loc=https%3A%2F%2Fwww.contractoruk.com%2Fforums%2F&amp;referer=https%3A%2F%2Fwww.contractoruk.com%2Fforums%2Fgeneral%2F121881-monday-links-bench-vol-ccclxxxviii.html&amp;cb=e21e133ee8' width='0' height='0' alt='' style='width: 0px; height: 0px;' /></div>",
                      "width": "160",
                      "height": "600",
                      "iframeFriendly": false
                  }
              }
              The offending code is in the "revive-0-1" item, which includes the stuff I posted earlier in its "html" property.

              So it isn't anywhere in the forum templates; it's somewhere buried in, probably, the plugin mechanism of the ad server.

              Comment


                #67
                Admin obviously think continued ad revenue is more important than protecting users computers from being compromised...

                Comment


                  #68
                  Originally posted by DimPrawn View Post
                  Admin obviously think continued ad revenue is more important than protecting users computers from being compromised...
                  It is.

                  HTH

                  Comment


                    #69
                    Now enough of you have signed up to the free competition thingymabob I have taken it off. Thank you for your custom, it is greatly appreciated. The mother's maiden name question was particularly enlightening, never would have had Old Greg as a member of the Gove clan, and to think DimPrawn's old dear is a Corbyn - well I never!

                    Fingers crossed should be properly fixed this time, the upgrade carried over some remnants of hack last time so really hoping it is sorted this time, if not it will be a set it up from scratch do and I really don't want to have to do that

                    Comment


                      #70
                      Originally posted by administrator View Post
                      Fingers crossed should be properly fixed this time, the upgrade carried over some remnants of hack last time so really hoping it is sorted this time
                      The fix seems to work for me. I no longer get the bagsforulife popup. Thanks!

                      Originally posted by greenlake View Post
                      I use Edge 44.17763.1.0 and have been receiving the following popup on virtually every CUK page since yesterday morning:

                      Comment

                      Working...
                      X