Black Demon Posted April 26, 2015 Report Posted April 26, 2015 When I click at any random thread in the forum, it will automatically redirect me to a fishy wiki-like website called http://wpkg.org/ (obviously, it's best not to go there) after 1-2 seconds. Does anyone else have this problem?It's probably not my account, computer or network because I've tried clearing all cookies, switched to my phone and even faked my IP but the problem still persisted. Adblocker is also on. It's really obnoxious because I don't get to post or even read anything in the forum.EDIT: Disabling JavaScript seems to work, but that is quite inconvenient.EDIT 2: I've found out that when I browse threads on some (but not all) other forums that are also using IP Board as the forum software, this problem will also occur, and they'd all lead to the exact same site.Examples, but not limited to:http://www.neowin.net/forum/http://serenesforest.net/forums/http://www.worldofraids.com/http://revillution.cometc.So it's probably a forum software problem, the strange thing is nobody else seems to encounter this issue.
User 4869 Posted April 26, 2015 Report Posted April 26, 2015 Not happening to me. From the symptom I suspect malwares but you said you already look into it...
Black Demon Posted April 26, 2015 Author Report Posted April 26, 2015 Hmm, looks like this will only happen if I use Chrome (both for Windows and iOS). Other browsers like IE, Firefox, Safari are fine. Weird... Actually, it's happening with other browsers as well, albeit the target website is different. The only way for me to avoid this is to either disable JavaScript or enter mobile mode.
User 4869 Posted April 26, 2015 Report Posted April 26, 2015 I believe Chrome in each devices link together through Google account. I search on my tablet and the same word show up in my search box in my PC. I had similar problem (a whole page of ad show up on top of page I'm browsing). My solution is disable/uninstall extension. try chrome-customize (top right) extension and look if something unusual are there. Edit: Doesn't explain why it only happen to DCW though 1
Black Demon Posted April 27, 2015 Author Report Posted April 27, 2015 I think I've figured out my problem: http://www.reddit.com/r/China/comments/33wpk3/anyone_else_almost_all_websites_in_both_chrome I've just black-listed these websites in my ad-blocker and it's working for now, without having to disable JavaScript (blocking the .js files doesn't seem to work, so I just blocked the whole domain). Currently scanning my computer to check for additional threats. Thanks for the replies, anyway! 2
Chekhov MacGuffin Posted April 27, 2015 Report Posted April 27, 2015 This appears to be a-someone-probably-China-related-is-breaking-the-internet-infrastructure that has nothing to do with DCW or with infections on people's computers. While there is plenty of room for uncertainty at this stage, I wouldn't be surprised if it turns out to be the Chinese government again since WPKG appears to be an open source software deployment and distribution tool, not unlike Github which was attacked recently. If it is the CCP again, I pity the poor Chinese people who are going to get caught up in the internet tangle between the CCP and the rest of the internet organization constituents who wants to stop them from doing this sort of thing. 2
Metantei Kiddo Posted April 29, 2015 Report Posted April 29, 2015 Agree with Mod Chek. Seems platform independent. http://www.thebeijinger.com/blog/2015/04/28/what-heck-wpkgorg-and-why-are-we-being-redirected-it 1
Chekhov MacGuffin Posted April 29, 2015 Report Posted April 29, 2015 There appears to be a continuation of the attack, although not as large as the previous. http://www.reddit.com/r/China/comments/346a5e/warning_new_firewall_dns_spoof_redirecting_to/ Get a javascript blocker (noscript for FF), download something to enforce https protocol on as many sites as possible like https everywhere, and switch your DNS to something like OpenDNS if you were affected before. It's pretty awful that a whole country's internet got hijacked like this. I hope all of the affected don't get something nasty on their computers. Whatever thing is replacing javascript with custom script could definitely serve up malware instead of just redirecting.
Chekhov MacGuffin Posted May 1, 2015 Report Posted May 1, 2015 Here is the final rundown of the situation: http://krebsonsecurity.com/2015/04/china-censors-facebook-net-blocks-sites-with-like-buttons/#more-30782 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now