Badmovies.org Forum

Trouble Tickets => Trouble Tickets => Topic started by: Ash on September 10, 2009, 10:57:24 PM



Title: Download File?
Post by: Ash on September 10, 2009, 10:57:24 PM

I was surfing around on this forum and got one of those yellow bars that pop down from the top of my browser.
It wanted me to download a file but my security settings blocked it. 
It wouldn't say what the file was.

I know Andrew would never have anything like that here on the site so I figured I'd report it.
Anyone else get this file download prompt?



Title: Re: Download File?
Post by: Andrew on September 11, 2009, 06:57:14 AM
Probably a rogue advertisement.  This site should never automatically prompt you to download anything.  I did some weeding of advertisements last night, so I might have already killed the offending banner.  However, please let me know if you run into it again - and any information it tells you about the download or banners on the page when it happens.


Title: Re: Download File?
Post by: Ash on September 12, 2009, 09:28:29 PM
I did some weeding of advertisements last night, so I might have already killed the offending banner.  However, please let me know if you run into it again - and any information it tells you about the download or banners on the page when it happens.

It just did it again.
Unfortunately, it doesn't say what the file is.
I wish I could give you more info, but I can't without actually downloading it, and I don't want to do that.

It's not a banner or ad of any kind that I can see.
It's simply prompting me to download a file and my security settings are blocking it.



Title: Re: Download File?
Post by: Ash on September 13, 2009, 03:20:00 AM
Here's a picture:

(http://img147.imageshack.us/img147/1662/09132009031310.jpg) (http://img147.imageshack.us/i/09132009031310.jpg/)

See the yellow bar at the top of my browser?
It says, "To help protect your security..."


Title: Re: Download File?
Post by: Andrew on September 13, 2009, 11:09:32 AM
Ash,

I've been unable to replicate this, nor have I seen the forum pages doing anything they shouldn't be doing as far as code.  I do not know why you are seeing this.  If it is an actual threat, a rogue ad is the probable cause - and I'd think that I would have encountered it as well.  Perhaps it is a false positive?  The site has Quantcast and Google analytics code, but if that was causing it you should see the warning every time.

Has anyone else seen this warning?


Title: Re: Download File?
Post by: Psycho Circus on September 13, 2009, 01:10:43 PM
I kept getting it last week. But I ignored it and it seems to have gone away. I haven't changed any IE settings or anything, so I'm guessing like Andrew said, it's some sort of rogue ad or pop-up jahbooey.


Title: Re: Download File?
Post by: Ash on September 15, 2009, 01:27:25 AM
Andrew,

It is now doing it almost every time I visit the forum.
I thought it might've been something on my computer so I ran several spyware scans and a full virus scan and neither of them found anything.

 :question:



Title: Re: Download File?
Post by: Andrew on September 15, 2009, 06:52:10 AM
If this is happening nearly every time, it makes it less likely to be an advertisement, but I still cannot replicate this - so tracking it down has been a guessing game.  Clicking on the information bar is supposed to give you more information about what was blocked.  Is it not doing this?

I completely removed the ads from the forum, to see if doing that changed anything.  Please let me know.

Some research showed that this error does arise at times for forums, and can be something to do with the forum itself (the theme file).  I've also seen it mentioned as a result of a javascript ad downloading images that are part of the ad, and even as a result of security certificates being deleted or missing.


Title: Re: Download File?
Post by: venomx on September 15, 2009, 01:51:33 PM
I get it too. (alot) Next time I see it I'll snap it and give you the details boss.


Title: Re: Download File?
Post by: Ash on September 18, 2009, 08:52:22 PM
Clicking on the information bar is supposed to give you more information about what was blocked.  Is it not doing this?

No it's not.

When I click on it, it says:
"Download File"
"What's the Risk?", and
"Information Bar Help"

It does not give any info at all as to what the file is.



Title: Re: Download File?
Post by: Andrew on September 18, 2009, 08:54:08 PM
Was it doing this for the two days that all of the ads were removed?


Title: Re: Download File?
Post by: Ash on September 18, 2009, 09:04:18 PM
I think it did.
Which days were the ads off?
It did it yesterday several times and once already tonight.


Title: Re: Download File?
Post by: venomx on September 18, 2009, 10:11:50 PM
My Maxthon browser shows me every security risk. It's a javascript file, but I wonder why it prompts?

Here it is again, I took a snap for you this time ... 3 mins ago. (I have no clue why it happens, sorry)

(http://img89.imageshack.us/img89/1632/popupj.png) (http://img89.imageshack.us/i/popupj.png/)

Is this what everyone else is getting?

edit* no, for the last 2 days I didn't get this.


Title: Re: Download File?
Post by: Andrew on September 19, 2009, 09:41:45 AM
Thank you, that helps a lot.  At least it might.  What I did is block the domains img.mediaplex.com and mediaplex.com via every advertiser interface.  However, the original ad that tries to pull the javascript from img.mediaplex.com might not be from that domain.  If that is the case, what I did will not work. 

Give this about two hours (say 12:30 pm EST) and let me know if it is still coming up.  If what I did does not work, I will start deactivating advertisers to try to find the offending network.


Title: Re: Download File?
Post by: Ash on September 19, 2009, 01:54:33 PM
Give this about two hours (say 12:30 pm EST) and let me know if it is still coming up.  If what I did does not work, I will start deactivating advertisers to try to find the offending network.

It just prompted me to download it again at 1:52 pm Central time.



Title: Re: Download File?
Post by: Andrew on September 19, 2009, 06:10:00 PM
There are two possible networks that it could be coming from.  I just turned off 1 of them.  If it appears again after 9 pm EST, either I picked the wrong one, or both networks have this rogue banner.

Sorry this is taking so long.  I'd like to hurt the people who do stuff like this.