uBlockOrigin / uBlock-issues

This is the community-maintained issue tracker for uBlock Origin
https://github.com/gorhill/uBlock
919 stars 78 forks source link

malware/virus faking as a Firefox upgrade #139

Closed kevomac12 closed 6 years ago

kevomac12 commented 6 years ago

Prerequisites

Description

I did not have a filter or white list in place for this behavior, that malware/virus would attempt via my browser to install an "upgrade", when the browser had already been upgraded to the current level as defined by the kid who created Waterfox! [Description of the bug or feature]

A specific URL where the issue occurs

[A specific URL is MANDATORY for issue happening on a web page, even if it happens "everywhere"]

Steps to Reproduce

  1. open: https://vidtodo.me/zfaxxlrvinba
  2. then this happens: https://wfyqdhypgmscy.com/MO.aspx?z=5613669&g=1836653426&y=1532211240&h=1225685996&s=493&r=%21t6vYpDVhd2BXZnOwNtb78OFhIpOOkdjvyp323djwTNA7bQudRf3f8maeNjIw%2B9G9dNCa9iPaU2yK25t6crqpjWynoIFD9eVyr3ro1e4IC9cRmJJmKHeoO51DMlggHgHQjRl7kxizsYQPIa0x63xNDK8DQOJ72ZVYcSjVY%2B%2Ft8%2FYBdJPo43Vw5EG45hnae8M6h3p0bwBcalnefUCaPZanxLHQUoTsUfeJPpT3IH0Pt6AirDZDmNngJkjW1UCxIXex0SOIDGU5%2B%2BbQ4c0agrPqv%2F1B%2FfZ9YB%2B38tGO2Fo7vF6JGFG3nO2FkZuV7nidI57sW2Iy%2FXg9BfYHItwA2tu7S2U0WU4ph6enCuvWBZIq04gs9sG3ZPSn%2BPHYPRFOQh6sKUnSJlR4Rht%2BY%2FWenvj8WAB%2BzkiZ%2Bw34l0DQpX%2Ffa13T%2F9TTn6IIcHPlRMspWuXPxSqL91PF8gfYtXcVMHMlInR%2FzbsfF%2FBED8oxLyoYv%2F8%3D&s=1366,768,1,1366,768&v=nt.v&m=651,373,45,127,9,562,290,5,42,-1,-8,-8,1366,643,1382,784
  3. and: https://accessa.club/aE94ODgJLRVM
  4. https://us.shein.com/user/auth/login?url_from=popads-US-Dress-20180312-Y-D7-vc-61294.html
  5. http://www.pc.error6655553402ausmsauthcombof0807.com.s3-website.us-east-2.amazonaws.com/?mid=0807&number=1-855-897-0807&cid=4cvI52MftcE&pid=106583_627368&bid=0.00994&ip=73.14.123.236&city=Colorado+Springs&url=vidtodo.me_crossing&network=ausmsauthcombof5870
  6. http://35.193.89.147/OTAxNDExOTMwNDUzLzkwMTQxMzc3NzU2MC8wcGZqenJicDRn
  7. https://c44.download/lp11/

Expected behavior:

To stream my show [What you expected to happen]

Actual behavior:

Changed my watchseries.to tabs to a so called firefox installation, it changed four (4) open tabs, I had to close and then reopen from the 'History' function all my desired pages [What actually happened]

Your environment

http://35.193.89.147/OTAxNDExOTMwNDUzLzkwMTQxMzc3NzU2MC8wcGZqenJicDRn - this is trying to get me to install new upgrade for Waterfox, which has already been up graded to 56.2.2, it over writes tabs already opened, all tabs in an attempt to trick an installation!

kevomac12 commented 6 years ago

I used the 'history' tab to reveal the URI' involved. If there's a better way to do a 'tracking' of malicious sites do tell.