republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Malware on grandcanyonskywalk.com or FP?
Search Topic:
Uniqs:
993
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Obama's internet monitoring plan moves forward »
« Cybersecurity Plan to Involve NSA, Telecoms (again)  
page: 1 · 2
AuthorAll Replies
-


Dude111
An Awesome Dude
Premium
join:2003-08-04
USA

1 edit
reply to Its a Secret
Re: Malware on grandcanyonskywalk.com or FP?

Do you get the alert if you goto the FLASH file directly?

»www.grandcanyonskywalk.com/main.swf


amysheehan
Premium,VIP,MVM
join:1999-12-21
Huntington Beach, CA
·RoadRunner Cable

reply to CajunTek
said by CajunTek See Profile :

Interesting stuff here.. Tried at home with KAV and IE 8.. get similar results.. At work with Norton... site opens right up in IE 6.. hmmm
With IE8 and NIS I get the ''cannot initialize site'' page.

What Norton are you using with IE6 ?


--
Proud Member of ASAP
DSLR Phishtracker


Grail Knight
Who Dares Wins
Premium
join:2003-05-31
reply to Mele20
Noscript does the same thing in Fx.
--
"Facts not FUD!"


NetFixer
Freedom is NOT Free
Premium
join:2004-06-24
Murfreesboro, TN
·AT&T Southeast
·Vonage
·Cingular Wireless
·AT&T CallVantage


1 edit
reply to Its a Secret
said by Its a Secret See Profile :

I got the same thing:
*** Can't find address for server webaliser.net: Server failed

Interesting. Why would replying to your post trigger this?
Because I posted the iframe url link, and apparently just seeing that code (even though it is only text in the DSLR [code]...[/code] posting) is enough to trigger the Avast! warning alarm (just as it is sufficient to trigger the same alarm on the grandcanyonskywalk.com site even though the webaliser.net is not actually reachable),
--
A well-regulated militia, being necessary to the security of a free State, the right of the people to keep and bear arms shall not be infringed.
»portscan.dcs-net.net
»nature-pics.com


Its a Secret
Whatever
Premium
join:2008-02-23
U B Funny

1 edit
reply to NetFixer
I got the same thing:
*** Can't find address for server webaliser.net: Server failed

Interesting. Why would replying to your post trigger this?


NetFixer
Freedom is NOT Free
Premium
join:2004-06-24
Murfreesboro, TN
·AT&T Southeast
·Vonage
·Cingular Wireless
·AT&T CallVantage


1 edit
reply to GuruGuy
said by GuruGuy See Profile :

Still getting the av alert after clicking the english flag after the flash page loads..................still an issue.
Interesting, I don't see an english flag even after I allow the flash file to load and also allow the webaliser.net iframe code.




Just out of curiosity, what do you get if you do a nslookup webaliser.net?


Oops, nevermind. I just reread all of your posts in this thread, and you were not using the OP's url to get to the site. Clicking on the flag image from your url however, takes you to the OP's page.
--
A well-regulated militia, being necessary to the security of a free State, the right of the people to keep and bear arms shall not be infringed.
»portscan.dcs-net.net
»nature-pics.com


NetFixer
Freedom is NOT Free
Premium
join:2004-06-24
Murfreesboro, TN
·AT&T Southeast
·Vonage
·Cingular Wireless
·AT&T CallVantage

reply to Its a Secret
said by Its a Secret See Profile :

said by NetFixer See Profile :

Try flushing your browser and/or DNS cache, and see if you still get the alert message.
Have done that. Intersting though, I went to reply to you and got the Avast! virus alert!
Perhaps Avast! is simply triggering on the webaliser.net iframe link code based on an assumption that anything at webaliser.net is bogus. Just out of curiosity, what do you get if you do a nslookup webaliser.net?
--
A well-regulated militia, being necessary to the security of a free State, the right of the people to keep and bear arms shall not be infringed.
»portscan.dcs-net.net
»nature-pics.com


Its a Secret
Whatever
Premium
join:2008-02-23
U B Funny
·Shaw


1 edit
reply to NetFixer
Click for full size
said by NetFixer See Profile :

Try flushing your browser and/or DNS cache, and see if you still get the alert message.
Have done that. Intersting though, I went to reply to you and got the Avast! virus alert!
--
"In the future, that which is not mandatory will be illegal"
"Nobody knows the age of the human race, but everybody agrees that it is old enough to know better" - Anonymous

GuruGuy

join:2002-12-16
Atlanta, GA

reply to CajunTek
said by CajunTek See Profile :

Interesting stuff here.. Tried at home with KAV and IE 8.. get similar results.. At work with Norton... site opens right up in IE 6.. hmmm
That's norton for you
--
GuruGuy

GuruGuy

join:2002-12-16
Atlanta, GA

reply to NetFixer
said by NetFixer See Profile :

said by Its a Secret See Profile :

No, it's still there.
The code on the grandcanyonskywalk.com web site may still be there, but webaliser.net is no longer to be found (at least with the DNS servers I use/tried).




webhost:/ # nslookup webaliser.net
Server: 192.168.10.1
Address: 192.168.10.1#53

** server can't find webaliser.net: SERVFAIL

webhost:/ # nslookup webaliser.net 68.94.156.1
Server: 68.94.156.1
Address: 68.94.156.1#53

** server can't find webaliser.net: SERVFAIL

webhost:/ # nslookup webaliser.net 208.67.222.222
Server: 208.67.222.222
Address: 208.67.222.222#53

** server can't find webaliser.net: SERVFAIL

webhost:/ # ping webaliser.net
ping: unknown host webaliser.net



Try flushing your browser and/or DNS cache, and see if you still get the alert message.
Still getting the av alert after clicking the english flag after the flash page loads..................still an issue.
--
GuruGuy


CajunTek
Insane Cajun
Premium,MVM
join:2003-08-08
Arlington, TX
reply to Grail Knight
Interesting stuff here.. Tried at home with KAV and IE 8.. get similar results.. At work with Norton... site opens right up in IE 6.. hmmm
--
da Cajun Darn I hate Malware


NetFixer
Freedom is NOT Free
Premium
join:2004-06-24
Murfreesboro, TN
·AT&T Southeast
·Vonage
·Cingular Wireless
·AT&T CallVantage


2 edits
reply to Its a Secret
said by Its a Secret See Profile :

No, it's still there.
The code on the grandcanyonskywalk.com web site may still be there, but webaliser.net is no longer to be found (at least with the DNS servers I use/tried).




webhost:/ # nslookup webaliser.net
Server: 192.168.10.1
Address: 192.168.10.1#53

** server can't find webaliser.net: SERVFAIL

webhost:/ # nslookup webaliser.net 68.94.156.1
Server: 68.94.156.1
Address: 68.94.156.1#53

** server can't find webaliser.net: SERVFAIL

webhost:/ # nslookup webaliser.net 208.67.222.222
Server: 208.67.222.222
Address: 208.67.222.222#53

** server can't find webaliser.net: SERVFAIL

webhost:/ # ping webaliser.net
ping: unknown host webaliser.net



Try flushing your browser and/or DNS cache, and see if you still get the alert message.
--
A well-regulated militia, being necessary to the security of a free State, the right of the people to keep and bear arms shall not be infringed.
»portscan.dcs-net.net
»nature-pics.com


Its a Secret
Whatever
Premium
join:2008-02-23
U B Funny
reply to munky99999
No, it's still there.

munky99999
Munky

join:2004-04-10
canada
clubs:
reply to Its a Secret
Has been fixed or something. I cant seem to find any problems.


Its a Secret
Whatever
Premium
join:2008-02-23
U B Funny
reply to GuruGuy
Yes, I did fire off an email referencing this thread to them.


Grail Knight
Who Dares Wins
Premium
join:2003-05-31
reply to GuruGuy
I see I will check it out later then with the manual input.
Thanks.
--
"Facts not FUD!"


Woody79_00

join:2004-07-08
united state

reply to GuruGuy
I am also running Avira but

when i loaded that page, the HAVP(Http Antivirus proxy) running ClamAV on my pfsense box(which scans all traffic passing though my pfsense box with clamav) threw up this warning before Avira even got a chance to do anything

"This page was blocked because it contained the following virus: PUA JS.Obfus-2

So I would say its infected...

GuruGuy

join:2002-12-16
Atlanta, GA

reply to Grail Knight
said by Grail Knight See Profile :

Fx v3.5.1 says it "Can not initialize."
Mine did too at first, then I typed it in as

www.grandcanyonskywalk.com

And it worked. After I clicked the little English button below I got the Avira warning.
--
GuruGuy


Grail Knight
Who Dares Wins
Premium
join:2003-05-31
reply to Its a Secret
Fx v3.5.1 says it "Can not initialize."
--
"Facts not FUD!"

GuruGuy

join:2002-12-16
Atlanta, GA

1 edit
reply to Its a Secret
I get this from avira:

Requested URL: www.grandcanyonskywalk.com/mainmenu.html
Information Contains recognition pattern of the HTML/Infected.WebPage.Gen HTML script virus
--
GuruGuy
Forums » Up and Running » Security » SecurityObama's internet monitoring plan moves forward »
« Cybersecurity Plan to Involve NSA, Telecoms (again)  
page: 1 · 2


Wednesday, 25-Nov 22:02:30 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [105] New AT&T Ad Campaign Hits Back At Verizon
· [94] Apple Joins AT&T Verizon Snark Fest
· [85] New Bill Takes Aim At Higher Verizon ETFs
· [79] Time Warner Cable Fires Broadside At Broadcasters
· [55] TiVo Sees Record Customer Losses
· [48] In-Flight Internet Headed For Bumpy Landing?
· [32] Senators Want ACTA Made Public
· [30] Earthlink Suffers From Major E-mail Outage
· [30] AT&T Offers New Prepaid Wireless plans
· [28] Frontier Increases Modem Rental Fee
Most people now reading
· Shutting of Electricity Temporarily (up to 1 yr) to Save $$$ [Home Repair & Improvement]
· Came from FIOS to Comcast and.....I'm glad I did! [Comcast HSI]
· Telemarketing Hell: Heather's back [Spam, Scam and Phishbusters]
· ToC 4th boss - Preliminary Strategy for Twin Valkyr [World of Warcraft]
· I'll Just Unplug That... [No, I Will Not Fix Your #@$!! Computer]
· Slow speeds in the evenings [TekSavvy]
· Windows 7 boot manager editing questions [Microsoft Help]
· No Newegg connection [General Questions]
· [video] The Muppets: Bohemian Rhapsody [56k Lookout (Broadband Heavy)]
· Sometimes PC is better??? [All Things Macintosh]