thewayne: (Default)
[personal profile] thewayne
I've noticed that I've had slightly odd behavior for a couple of weeks: I'd type in the url for a site that I've visited before, and I'd get a message saying that access to that site had been blocked by an add-in!

Very odd.

Tonight, I was looking for some Grateful Dead midi files. Open up Google, type in 'Grateful Dead midi file' and hit enter. And I happened to notice that the tab bar said MaxAsk.com! Now, the interesting thing is that the results looked fairly reasonable, and had the Google logo, but that's easy enough to impersonate.

Doing a little digging in a different, very rarely used browser, revealed that MaxAsk is a browser hijacker! This could explain trouble accessing web sites. I checked the add-ins that I had which were rather few: an ad blocker, and one that I didn't remember loading. I removed it, and Google seemed to be responding normally.

Very weird. And, of course, the big question is: how did it get installed!

I'm going to have to do some cleaning and see if there are any traces of any other problems lurking on this box.

Date: 2024-10-30 08:09 am (UTC)
darkoshi: (Default)
From: [personal profile] darkoshi
If you have your browser history being saved, you could check for the first instance of MaxAsk.com in the history, and check what pages you opened before that which might have installed it. Maybe you installed something else around that time which included it.

Firefox's history view only lists the most recent time each page was opened. I use this Nirsoft tool to list my full browsing history including multiple visits to the same pages in the actual order I visited them, from all my browsers (it works for many besides Firefox):
https://www.nirsoft.net/utils/browsing_history_view.html

Date: 2024-10-30 10:22 am (UTC)
moonhare: (Eisbär)
From: [personal profile] moonhare
Well, that’s just worrisome. I know you are savvy on all things security, so one of these sneaking in needs to be looked into.

I’m relentless with dumping cookies and website data from my browsers, hoping it will remove any such residue. Still, the internet of ‘things’ posts ads in Facebook for items I’ve asked about in Google….

Date: 2024-10-30 01:53 pm (UTC)
disneydream06: (Disney Surprised)
From: [personal profile] disneydream06
Thank goodness you found that. :o
Hugs, Jon

Date: 2024-10-30 08:58 pm (UTC)
silveradept: A kodama with a trombone. The trombone is playing music, even though it is held in a rest position (Default)
From: [personal profile] silveradept
Always fun to try and figure out who succeeded at the drive-by download. It was probably an ad that did it, but the other usual candidate is a software installation that didn't disclose that it was also including a browser plug-in or similar.

These kinds of things are why adblock is not a nicety, but a necessity when it comes to browsing the web.
Edited Date: 2024-10-30 08:58 pm (UTC)

Date: 2024-10-31 12:15 am (UTC)
pondhopper: (Default)
From: [personal profile] pondhopper
That's nasty. I hope you managed to eliminate it but yeah, a good check-up would not be a bad thing. I've had that sort of thing take up residence and they can be a real mess. Good luck.

Date: 2024-11-01 01:12 am (UTC)
moonhare: (thumper)
From: [personal profile] moonhare
At least some of the stuff I view doesn’t generate ads… ;o)

Date: 2024-11-02 12:11 am (UTC)
kaishin108: waves by hwm (Default)
From: [personal profile] kaishin108
That's awful.

Date: 2024-11-12 03:50 am (UTC)
halfshellvenus: (Default)
From: [personal profile] halfshellvenus
Yikes! That's the kind of thing we all fear.

To quote Cybersecurity, "Don't click that link!"

June 2025

S M T W T F S
123456 7
8910 11121314
15 1617 18 1920 21
22232425262728
2930     

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jun. 30th, 2025 12:25 pm
Powered by Dreamwidth Studios