hagezi / dns-blocklists

DNS-Blocklists: For a better internet - keep the internet clean!
GNU General Public License v3.0
5.83k stars 200 forks source link

Blocked payment method on lampgallerian.se #323

Closed BourbonCrow closed 1 year ago

BourbonCrow commented 1 year ago

What adblocker/DNS cloud service are you using?

Which blocklists are used?

HaGeZi - Multi PRO

Which domain(s) should be unblocked?

secure.adnxs.com

Why should the domain(s) be unblocked? If necessary, please describe the steps to reproduce.

The website https://www.lampgallerian.se/ is using the domain above as a secure payment service or whatever you wanted to call it my mom tried to order a lamp but didnt work to pay so i checked the logs and this was the domain that blocked the payment and i can imagine other swedish sites could use it as well

BourbonCrow commented 1 year ago

i did whitelist it my self to confirm and it solved the payment issue, so she can have her lamp now :3

BourbonCrow commented 1 year ago

https://imgur.com/a/vD4FqEm

here is a image of the 2 domains that was blocked during the attempt to pay but i only unblocked the adnxs and it worked, after googling for that domain tho i dont find anything positive about it really so im a lil confused, cause all i can find is that it seems ad related but i didnt see any ads on her iphone there even after unblocking

the website uses https://www.qliro.com/sv-se/ as a payment service and as well a common tool "BankID" for identification its common in sweden and the payment broke after verifying her identity on BankID

but im not tech savey guy so i leave rest of the investigation to you, in worst case i just allow it temporarly then block it again Lol

i event sent a email to the website asking them why thats a thing cause that domain seems toxic after ive done some reading around

nezlobnyj commented 1 year ago

More specifically - https://secure.adnxs.com/seg?add={INTEGER}&t={INTEGER}

This request isn't being sent neither from this website on mobile platform (i.e., iOS 16 and Android 13) nor from country-specific website versions (e.g., https://www.lightshop.com/pl) on desktop.

Also quick lazy search suggests it's used for tracking/fingerprinting as it deploys tracking pixel. VT and alienvault suggest it's clean though.

Not that anyone asked, but I'd keep it blocked globally and leave whitelisting to user.

hagezi commented 1 year ago

https://slayterdev.github.io/tracker-radar-wiki/domains/adnxs.com.html

Very wild to use a popular ad motivated tracker as an obligation for a payment process. A bit cheeky. I'm curious to see what the company says when you ask.

Until then, it's definitely something for the personal whitelist. If there are any other restrictions in the payment area, I'll have to bite the bullet and whitelist it for the masses.

hagezi commented 1 year ago

Thanks @nezlobnyj I agree with you completely. Let's see what the company responds to the request.

BourbonCrow commented 1 year ago

If they reply to me I will post it here gonna be interesting

hagezi commented 1 year ago

@BourbonCrow Have you received any feedback?

BourbonCrow commented 1 year ago

@BourbonCrow Have you received any feedback?

oh i wish.. im gonna wait until friday since it was like weekend when i emailed em and most ppl dont work on weekends and if nothing they can .... off :D cause its kinda unacceptable to force a ad network to be active to be able to go through with a payment, espeically that one as well they seem kinda toxic based on my googling

hagezi commented 1 year ago

Since no one has contacted me, I will close here. If you get any more info, please let me know.