Virus loaded ad redirects

Hi.
Had a second redirect from the commuting thread forum on a second device, something is definatley up.
Trying to get the pictures uploaded to share to you.
Its taking over the tab for bike radar.
Both devices reported clean with McAfee av and avast av.
Had a second redirect from the commuting thread forum on a second device, something is definatley up.
Trying to get the pictures uploaded to share to you.
Its taking over the tab for bike radar.
Both devices reported clean with McAfee av and avast av.
Intent on Cycling Commuting on a budget, but keep on breaking/crashing/finding nice stuff to buy.
Bike 1 (Broken) - Bike 2(Borked) - Bike 3(broken spokes) - Bike 4( Needs Work) - Bike 5 (in bits) - Bike 6* ...
Bike 1 (Broken) - Bike 2(Borked) - Bike 3(broken spokes) - Bike 4( Needs Work) - Bike 5 (in bits) - Bike 6* ...
0
Posts
And
Closing page resulted in attempts to get me there my phone.
Bike 1 (Broken) - Bike 2(Borked) - Bike 3(broken spokes) - Bike 4( Needs Work) - Bike 5 (in bits) - Bike 6* ...
Have passed onto the team and we'll get rid of this asap.
No worries. I'll let you know if I have any more.
That last one was particularly nasty redirect, ended up with 14 tabs loaded, all with various junk / "device updates" etc and an APK being downloaded.. :S
Bike 1 (Broken) - Bike 2(Borked) - Bike 3(broken spokes) - Bike 4( Needs Work) - Bike 5 (in bits) - Bike 6* ...
Dev team have created a ticket for this so hopefully resolved asap.
Thanks again.
Bike 1 (Broken) - Bike 2(Borked) - Bike 3(broken spokes) - Bike 4( Needs Work) - Bike 5 (in bits) - Bike 6* ...
This one hit the content warning of my mobile provider, always fun :rolleyes:
Bike 1 (Broken) - Bike 2(Borked) - Bike 3(broken spokes) - Bike 4( Needs Work) - Bike 5 (in bits) - Bike 6* ...
Bike 1 (Broken) - Bike 2(Borked) - Bike 3(broken spokes) - Bike 4( Needs Work) - Bike 5 (in bits) - Bike 6* ...
Would these involve some nasties being put on your device? My av didn't find anything but since it's my phone I'm kind of worried what's been put on it.
I have ad ops investigating whether it is our end or not too.
I always and only get them after visiting a br page, and it kicks in about 6 seconds after the page loads. At the moment don't appear to be virus loading, but I might be catching them in the process of loading,
Bike 1 (Broken) - Bike 2(Borked) - Bike 3(broken spokes) - Bike 4( Needs Work) - Bike 5 (in bits) - Bike 6* ...
Now a data: redirect, had two of them.
Still believe they are from here, use phone all day, only appear after a br visit.
Bike 1 (Broken) - Bike 2(Borked) - Bike 3(broken spokes) - Bike 4( Needs Work) - Bike 5 (in bits) - Bike 6* ...
Bike 1 (Broken) - Bike 2(Borked) - Bike 3(broken spokes) - Bike 4( Needs Work) - Bike 5 (in bits) - Bike 6* ...
1 definatley NSFW.
Bike 1 (Broken) - Bike 2(Borked) - Bike 3(broken spokes) - Bike 4( Needs Work) - Bike 5 (in bits) - Bike 6* ...
Just to confirm im now 36 hours without incident, without changing anything on my phone, so still think it was BR.
Cheers:-)
Bike 1 (Broken) - Bike 2(Borked) - Bike 3(broken spokes) - Bike 4( Needs Work) - Bike 5 (in bits) - Bike 6* ...
It was claiming to be the Google Awards Programme, usual free phone/tablet guff.
Defo something naughty on the site.
Its almost impossible to view the forum now on my android device as every 3 or 4 clicks brings up a bad ad which kills your own site and leaves me just with the rogue ads.
I dwonder if the code was clever enough to detect it running through a proxy and abort. I'll keep watch!
Bike 1 (Broken) - Bike 2(Borked) - Bike 3(broken spokes) - Bike 4( Needs Work) - Bike 5 (in bits) - Bike 6* ...
The best way to get this is to perform a 'man in the middle's attack against it, for which you'll need another PC you can put on the same WiFi network as the phone.
I used fiddler4 software proxy for this (www.fiddler2.com) and set up the WiFi on the phone to proxy through that installation.
If you need help setting it up, holler and I'll try and write a detailed guide.
Bike 1 (Broken) - Bike 2(Borked) - Bike 3(broken spokes) - Bike 4( Needs Work) - Bike 5 (in bits) - Bike 6* ...
I am chasing answers!
Cant go back a page so have to shut off the browser.
It isn't when I click on adds either because I don't bother with them or the clickbait at the bottom of the page. Just standard topic links within the forum.
I'll screenshot it next time and post it up.
Samsung galaxy s6
Ads thought they had resolved the issue but clearly not!
Any screenshots etc is very helpful.
Will go back to running fiddler over the weekend where possible.
Bike 1 (Broken) - Bike 2(Borked) - Bike 3(broken spokes) - Bike 4( Needs Work) - Bike 5 (in bits) - Bike 6* ...
URL incoming
Bike 1 (Broken) - Bike 2(Borked) - Bike 3(broken spokes) - Bike 4( Needs Work) - Bike 5 (in bits) - Bike 6* ...
I thought my phone had a fault with this issue and even got Samsung/ EE tech support involved, but it turns out it was these ads triggering Mediaserver's high usage
Yep had the same with the battery issue. Seriously considering an adblock installation on the mobile just for this site.
Bike 1 (Broken) - Bike 2(Borked) - Bike 3(broken spokes) - Bike 4( Needs Work) - Bike 5 (in bits) - Bike 6* ...
Anwyay - yet another data :base64 again.
Bike 1 (Broken) - Bike 2(Borked) - Bike 3(broken spokes) - Bike 4( Needs Work) - Bike 5 (in bits) - Bike 6* ...