uBlockOrigin / uAssets

Resources for uBlock Origin, uMatrix: static filter lists, ready-to-use rulesets, etc.
GNU General Public License v3.0
4.13k stars 770 forks source link

hotpornfile.org [NSFW] #5311

Closed bobsage123 closed 5 years ago

bobsage123 commented 5 years ago

URL(s) where the issue occurs

https://www.hotpornfile.org/pornmegaload-19-03-27-chloe-temple-suckin-and-fuckin-nerds-xxx-1080p-mp4-ktr/519863

Describe the issue

When going to a video DL page on this site, ads are now appearing on the left and the bottom.

Screenshot(s)

NSFW: https://i.imgur.com/lU5WDxQ.jpg

Versions

bobsage123 commented 5 years ago

Unfortunately this does not look to have removed the ads. I updated my filters and purged cache, and confirmed the new lines were added to ublock filter. Did a cookie clear on the website and refreshed and they have come back on the left and bottom of the page.

mapx- commented 5 years ago

This should work in chrome too hotpornfile.org##+js(addEventListener-defuser.js, getexoloader)

bobsage123 commented 5 years ago

Ahh, ads are still there after latest commit as well. Are they being removed for you @mapx- ? Maybe it's something on my end.

mapx- commented 5 years ago

yep, working fine in chrome. Do you see the new filter in the logger ?

mapx- commented 5 years ago

if you see the new filter, add and test this 1 too: ||hotpornfile.org/*.php$script,1p

bobsage123 commented 5 years ago

After another refresh of the page it seems to be working now. Thanks for your help!

bobsage123 commented 5 years ago

@mapx- The ads came back, but adding ||hotpornfile.org/*.php$script,1p removed it again. Might want to add this to the filter.

bobsage123 commented 5 years ago

@mapx- Please take a quick look when you have time, looks like ads came back on the bottom again.

https://www.hotpornfile.org/swallowed-19-04-29-alex-blake-ava-parker-and-mackenzie-moss-xxx-1080p-mp4-ktr/527519

bobsage123 commented 5 years ago

@mapx- @okiehsch (unsure if you get notified by default)

Sigh - This site won't give up - Ads are back as well now as redirects to fake virus warning sites - Ads on bottom - https://www.hotpornfile.org/wickedpictures-axel-brauns-dirty-blondes-xxx-1080p-mp4-ktr/336855

Fake virus warning redirect - I clicked the middle video in the search here (first link below) and it redirected to a fake virus warning page (second link below). https://www.hotpornfile.org/?s=WickedPictures+Axel+Brauns+Dirty+Blondes+XXX+1080p+MP4-KTR

Warning page URL (be careful) - https://a3.hotpornfile.org/v2/a/skm/rsl?id=35057f28-7b76-11e9-9139-5f5d5f89b3bf&l=https%3A%2F%2Fpartofmediax.com%2Ffeed%2Fclick%2F%3Ft1%3D128%26tid%3D68%26uid%3D53%26subid%3D9573%26id%3Dc878dabefe1743fb548858e9f0943a1c%3A14dab9d11dba78925c8674829f3d34c5091c58e5d81dffc47eb8d670e7f92b9e3876a7041c41048a2b9bc7802200d237b335cf2afd55b4125958fad48774a5833bda64806858d45ad404fc8241a2083040b05608387e16871dac43f51218081d131b79be4940cd983f3e6b753037f5b83c695dc0b774d912f0362c890e1dba2a9cd4eb436d22479a7cee33028f5de7aaa69e7bef5fbd5292b7efd2fa937de49afcdbb0c0661c7920c01fff7357a9f4d00f1568a3508f20b3b3662f8b62d0506318003c3d2902a39cb3c16275eb5c7459a068a49e7cedf525093a10f1a03cd6fbe485af858be53b6a2165f2dc0d7f114e2c1b42951a6c8920ca6d8b79e63b5a3ba2beb8c364493823add096e59837e3892ac25ff6468e4c59231aa5752fe372785e0a4125fd9b895e886016edf314545de35fa2b51f8782818b4c43036e88b554cb4805df5dc0c20e1d66e9f06ccab02af8b20c097780afd7c4dba6fed6ff129884374ad712048b2f6ce31b7c1388bb78&oz=17859&p=https%3A%2F%2Fwww.hotpornfile.org%2F%3Fs%3DWickedPictures%2BAxel%2BBrauns%2BDirty%2BBlondes%2BXXX%2B1080p%2BMP4-KTR&r=&s=2886

okiehsch commented 5 years ago

unsure if you get notified by default

We are getting notified of every comment in this repo.

bobsage123 commented 5 years ago

unsure if you get notified by default

We are getting notified of every comment in this repo.

Good to know. The ads on the bottom of the DL pages appear to be gone but I still get a redirect when clicking an item in the search results (below link). When clicking a result it will open a new tab with the correct page but the page I just came from will redirect to some ad page or fake virus page. Thanks for your help.

https://www.hotpornfile.org/?s=WickedPictures+Axel+Brauns+Dirty+Blondes+XXX+1080p+MP4-KTR

okiehsch commented 5 years ago

Hm, I have been able to reproduce the redirection but it is fixed on my end by adding the filter hotpornfile.org##+js(addEventListener-defuser.js, DOMContentLoaded, tabUnder)

bobsage123 commented 5 years ago

Hm, I have been able to reproduce the redirection but it is fixed on my end by adding the filter hotpornfile.org##+js(addEventListener-defuser.js, DOMContentLoaded, tabUnder)

That's odd, checked and my ublock filter list has this line. Did a cookie\cache clear on the site as well. Are you on chrome? Maybe browser related?

okiehsch commented 5 years ago

I removed all cookies and I can't reproduce anymore, the only way for me to reproduce now is to disable the mentioned filter. *$popunder,domain=hotpornfile.org should atleast block the popunder on your end.

bobsage123 commented 5 years ago

Thanks - that seems to have done it. One other minor thing, is that sometimes every couple times you go to a DL page, this empty ad box will show up in the bottom right - https://i.imgur.com/2Plt4O2.png

okiehsch commented 5 years ago

What do you mean by "download page"? I am not familiar with the site if I go to https://www.hotpornfile.org/wickedpictures-axel-brauns-dirty-blondes-xxx-1080p-mp4-ktr/336855 and click "download" I don't see any empty box in the bottom right.

bobsage123 commented 5 years ago

The link you provided is the DL page aka where you click Download now. It shows up as soon as you go to the page. But It's random, only every few times it happens. Had to just paste that link in another browser for it to appear. If not able to see that one don't worry about it.

Edit: Sorry to be a pain in the ass, but when going back to the main page of hotpornofile, when clicking some of the videos (but not all), the page will quickly redirect then close. And will open the link I want in a new tab. When this happens, I'm unable to hit back to go back to the main page. It just goes back to "blank". Not sure anything can be done about that.

bobsage123 commented 5 years ago

Not sure what this site is doing, but it somehow keeps getting ads back on the bottom. Example - https://www.hotpornfile.org/babestation-tv-18-10-02-jasmine-marie-red-and-black-xxx-imageset-koczka/533379

Appreciate assistance

dumbusernameidk commented 5 years ago

Site will open a new tab when clicking a link while the first tab redirects to an about:blank page before closing. I think hotpornfile.org##+js(abort-on-property-read.js, open) works for me.

Also occasionally junk ads from garbage sites appear on the right hand side of the screen. Usually from clcknads.pro another two domains to also block would be hapogzu9a19m5fhe56pb.pro and acrmbjkk6qc5utby.pro. I think these junk ads are coming from the script hotpornfile.org/17859.js.

mapx- commented 5 years ago

I added a filter 14 minutes ago, test it https://github.com/uBlockOrigin/uAssets/commit/397b310b12ac8e966e353697b764ee4960dd1f39

bobsage123 commented 5 years ago

I added a filter 14 minutes ago, test it 397b310

Edit: May have encountered an issue. Every few times you type something in the search bar and hit the "Fap" search button, the tab just completely closes. No new tab is even opened.

Thanks mapx-, this seems to have fixed it. As a person still learning to make filters, how did you determine that you had to block the "onload" property read js function? I sometimes come across other similar sites and would like to block myself.

mapx- commented 5 years ago

Examining the external scripts, I got hotpornfile.org/17859.js one (which obviously - obfuscated code) was at the origin of that bahaviour.

Then in the html page I saw hotpornfile.org/17859.js launched by this code:

window.onload = function() {
        if (Cookies.get('hpf_fv')) {
            postscribe('#dummy', '<script src="https://www.hotpornfile.org/17859.js"><\/script>', {
                        done: function() {
                            setTimeout(function() {
                                if (typeof UmDWe9Dn8Fr2nKAs === 'object') {
                                    UmDWe9Dn8Fr2nKAs.config({coverScrollbar: false, noOpenerHijacking: true, coverTags: [], perpage: 1, tabUnderIgnoreTargetBlank: false});
                                    UmDWe9Dn8Fr2nKAs.bindTo(['button', 'img', 'a']);
                                    UmDWe9Dn8Fr2nKAs.ignoreTo(['.slick-arrow', '.vjs-wrapper', '.fluid_video_wrapper', '.fluid_player_layout_default', '.fluidPlayer', '.vast_video_loading', '.fluid_controls_container', '.fade_out', '.fluid_controls_left', '.fluid_button', '.fluid_button_play', '.fluid_controls_progress_container', '.fluid_slider', '.fluid_controls_progress', '.fluid_controls_currentprogress', '.fluid_controls_currentpos', '.fluid_controls_buffered', '.fluid_controls_ad_markers_holder', '.fluid_timeline_preview', '.fluid_controls_right', '.fluid_button_fullscreen', '.fluid_button_theatre', '.fluid_button_video_source', '.fluid_button_playback_rate', '.fluid_video_playback_rates', '.fluid_video_playback_rates_item', '.fluid_button_download', '.fluid_control_volume_container', '.fluid_control_volume', '.fluid_control_currentvolume', '.fluid_control_volume_currentpos', '.fluid_button_volume', '.fluid_fluid_control_duration', '.fluid_context_menu', '.fluid_pseudo_poster', '.fluid_html_on_pause', '.fluid_initial_play', '.fluid_initial_play_button', 'video', 'article a', '.external', '.button.showCaptcha', '.tab-bar a', '.left-off-canvas-menu a', '.top-bar a', '#sidebar iframe']);
                                    UmDWe9Dn8Fr2nKAs.add('https://hotpornfile.org/m995e/5cdr3cfuzvv6.php', {under: true,
                  newTab: true, cookieExpires: 600});
                                }
                            }, 250);
                        }
                    });
        } else {
            Cookies.set('hpf_fv', '1', { expires: 1 });
        }
    };
bobsage123 commented 5 years ago

Thanks @mapx- , please see my above edit, I may have found an issue.

mapx- commented 5 years ago

I cannot reproduce that search behaviour. I guess you are using the last filters.

bobsage123 commented 5 years ago

I cannot reproduce that search behaviour. I guess you are using the last filters.

That's correct.

Steps taken:

  1. Purged ublock cache, reupaded filters
  2. Cleared cookies\cache on hotpornfile on chrome
  3. Type anything into search box and hit enter. Every 3rd or so time (may take a few more but usually under 10) you do a search the tab will just close (I assume this is the page trying to do that redirect which happened about every 3rd time as well)

Edit: may have found another script that appeared in the logger when the tab closed that may have caused this: https://a3.hotpornfile.org/v2/a/push/js/34721

Also noticed this sometimes running, but I don't think after I do a search. https://a3.hotpornfile.org/v1/pixel.js

mapx- commented 5 years ago

add & test (and see if breaks something) hotpornfile.org##+js(abort-on-property-read.js, open)

bobsage123 commented 5 years ago

Unfortunately didn't work. Here's the log when the tab closes. Seems the tab closes then https://a3.hotpornfile.org/v2/a/push/js/34721 runs so not sure if it's related. Unless there is a problem with "​*$popunder,domain=hotpornfile.org" in ublock filters causing this that's the issue?

1

mapx- commented 5 years ago

test hotpornfile.org##+js(abort-current-inline-script.js, postscribe, setTimeout)

bobsage123 commented 5 years ago

Happened again after trying a few times - did cache\cookie clear on site

Nothing else appearing on this logger except this popunder filter line. I think there may be a conflict.

$popunder,domain=hotpornfile.org

2

dumbusernameidk commented 5 years ago

I think it would be best to just block all first party scripts on the site.

mapx- commented 5 years ago

@dumbusernameidk are you able to reproduce the same issue ?

okiehsch commented 5 years ago

That would break all videos, for example go to

https://www.hotpornfile.org/monstercurves-19-05-28-luna-star-driver-meets-dom-xxx-1080p-mp4-ktr/534652

block all 1st-party scripts and load the site bypassing the cache.

I can't reproduce the issue.

mapx- commented 5 years ago

@bobsage123 you could try refreshing uBo ("reset to default settings"), update the lists and test again

bobsage123 commented 5 years ago

I think it would be best to just block all first party scripts on the site.

Looks like doing that removes the "Download / Stream now!" button on the bottom of the video pages which lets you run the captcha, then get to the dl links.

dumbusernameidk commented 5 years ago

I can't produce any popunders but sometimes I get an iframe video ad on the side of the page.

Alright the ads still appear if I block both. But that's the only issue on my end.

mapx- commented 5 years ago

for 34721 add the filter above hotpornfile.org##+js(abort-current-inline-script.js, postscribe, setTimeout)

bobsage123 commented 5 years ago

@bobsage123 you could try refreshing uBo ("reset to default settings"), update the lists and test again

What just worked for me was the below. The other day I believe this line was added to ufilter because I was still getting a redirect. Even though @okiehsch was not getting redirects without it enabled. With all the other lines, we added looks like it's no longer needed for me and was the cause of my tabs closing.

@@*$popunder,domain=hotpornfile.org

dumbusernameidk commented 5 years ago

Seems that filter gets rid of the iframe ads.

mapx- commented 5 years ago

ok, I added 2 filters and disabled popunder one, let's see what happens (update your lists in 5 minutes and test again)

okiehsch commented 5 years ago

Well, I have to say I can't see how blocking all popunders can cause the search function to break that would mean the site shows the search results in a popunder tab which it certainly does not on my end. And how blocking all popunders on a site can possibly cause iframe-ads to appear beats me.

bobsage123 commented 5 years ago

ok, I added 2 filters and disabled popunder one, let's see what happens (update your lists in 5 minutes and test again)

Seem to be all good now. Thanks for your help.

bobsage123 commented 5 years ago

Aw crud...was working fine now the download now button is not working. Was working fine the other day.

https://www.hotpornfile.org/povmaniaxxx-19-02-02-nickey-huntsman-pov-blowjob-xxx-1080p-mp4-ktr/504414

bobsage123 commented 5 years ago

@okiehsch Looks like the button works now but it's doing that crap again where it redirects the page and opens a new tab when clicking an item in the search results. May need to try clicking search result 2-4 times before it happens.

Search results - https://www.hotpornfile.org/?s=POVManiaXXX+16+06+10+Stassi+Sinclair+Gives+A+Blowjob+XXX+1080p+MP4-KTR

Here's two of the links it redirects to when clicking, one after another- https://a3.hotpornfile.org/v2/a/skm/rsl?id=a7757786-84f3-11e9-bb6e-4757bae89bf9&l=http%3A%2F%2Fwww.tubepixs.com%2F%3Fsource%3Dwww.hotpornfile.org&oz=17859&p=https%3A%2F%2Fwww.hotpornfile.org%2F%3Fs%3DPOVManiaXXX%2B16%2B06%2B10%2BStassi%2BSinclair%2BGives%2BA%2BBlowjob%2BXXX%2B1080p%2BMP4-KTR&r=&s=3200

https://a3.hotpornfile.org/v2/a/skm/rsl?id=a7757786-84f3-11e9-bb6e-4757bae89bf9&l=http%3A%2F%2Fwww.tubepixs.com%2F%3Fsource%3Dwww.hotpornfile.org&oz=17859&p=https%3A%2F%2Fwww.hotpornfile.org%2F%3Fs%3DPOVManiaXXX%2B16%2B06%2B10%2BStassi%2BSinclair%2BGives%2BA%2BBlowjob%2BXXX%2B1080p%2BMP4-KTR&r=&s=3200&jsr=1&wgl=1&abl=1&_=

dumbusernameidk commented 5 years ago

the previous fix for the iframe ads doesn't work for me. i just went with blocking this script ||hotpornfile.org/v2/a/push/js/$script and that worked fine.

bobsage123 commented 5 years ago

the previous fix for the iframe ads doesn't work for me. i just went with blocking this script ||hotpornfile.org/v2/a/push/js/$script and that worked fine.

I think that might have done the trick, thanks!

bobsage123 commented 5 years ago

the previous fix for the iframe ads doesn't work for me. i just went with blocking this script ||hotpornfile.org/v2/a/push/js/$script and that worked fine.

@dumbusernameidk are you experiencing the redirect issue again? I am. Pretty clear now the site owner is watching this page and then just making tweaks. Might need to take this convo offline.

dumbusernameidk commented 5 years ago

yeah unfortunately i don't have any quick fixes. I'm wondering if a csp filter is doable but i'm gonna assume no cause i'd imagine it would've been added by now.

Also i don't know if it's much but there's some script that's encoded with base64 in an <src> header. i'm under the assumption this is where the iframe ads are loaded in/switched given the functions. but the iframe ads aren't the problem so i didn't bother with it.

at this point i think it's best to just abandon the site as it's clearly using malicious redirects. or just use the previous hotpornfile.org##+js(abort-on-property-read.js, open) filter and live with broken buttons. sounds a lot better than malicious redirects if you ask me.

bobsage123 commented 5 years ago

yeah unfortunately i don't have any quick fixes. I'm wondering if a csp filter is doable but i'm gonna assume no cause i'd imagine it would've been added by now.

Also i don't know if it's much but there's some script that's encoded with base64 in an <src> header. i'm under the assumption this is where the iframe ads are loaded in/switched given the functions. but the iframe ads aren't the problem so i didn't bother with it.

at this point i think it's best to just abandon the site as it's clearly using malicious redirects. or just use the previous hotpornfile.org##+js(abort-on-property-read.js, open) filter and live with broken buttons. sounds a lot better than malicious redirects if you ask me.

Unfortunately only downside to using that is the download now button does not work which kinda makes the site useless lol. Wish there was a PM feature on here. Then we could at least manually get help and enter into our filter lists.

dumbusernameidk commented 5 years ago

I suppose if it's no worry for you then you can just add ||hotpornfile.org/v2/a/skm/rsl?id=*$document as this is the page serving the redirects.

okiehsch commented 5 years ago

Use *$popunder,domain=hotpornfile.org for the redirection. You said the breakage caused by that filter is "Type anything into search box and hit enter. Every 3rd or so time (may take a few more but usually under 10) you do a search the tab will just close" You can still use the page with that kind of breakage.