View Full Version : XSS vulnerabilities in Revision3 webpages
buddhachu
12-05-2009, 03:12 AM
The Arnold and Mat Damon DiggDialog episode web pages most likely have XSS vulnerabilities in them. The videos won't play in Firefox due to errors and if you copy/paste the URLs to their webplayer pages in Internet Explorer, I get the infamous popup box stating "Your computer is vulnerable to viruses. Click here to scan your computer". (Kill all IE processes to prevent disaster).
Beside the problem listed above, there's no downloads listed so we can get the video that way and these two videos are not listed on the Rev3 channel on my Roku box. Maybe all of that is related...
buddhachu
12-05-2009, 03:19 AM
FWIW, here's what NoScript is not liking and shows up in Firefox's error console:
[NoScript XSS] Sanitized suspicious request. Original URL [http://m2.feiwei.tv/g/lib/template/echo.html?s=%3C%21DOCTYPE%20HTML%20PUBLIC%20%22-//W3C//DTD%20HTML%204.01%20Transitional//EN%22%20%22http%3A//www.w3.org/TR/html4/loose.dtd%22%3E%0D%0A%3Chtml%3E%0D%0A%3Chead%3E%0D %0A%09%3Ctitle%3EAdvertisement%3C/title%3E%0D%0A%3C/head%3E%0D%0A%3Cbody%20leftmargin%3D%220%22%20topm argin%3D%220%22%20marginwidth%3D%220%22%20marginhe ight%3D%220%22%3E%0D%0A%3Ciframe%20src%3D%22http%3 A//northwestbdm.com/%3Ftnt%3Dax531132046176%26tlt%3Dqvr15%26pcz%3D4114 34%26bn_size%3D72890rgh%26_cmm%3D11453111%26pdst%3 D4nx%26id%3D32046176%26zr%3Dsdf2bc6513413403xg%26r cr%3D341130%26ms%3D31c11c%22%20width%3D%22728%22%2 0height%3D%2290%22%20scrolling%3D%22no%22%20hspace %3D%220%22%20frameborder%3D%220%22%3E%3C/iframe%3E%0D%0A%3C/body%3E%0D%0A%3C/html%3E] requested from [http://revision3.com/diggdialogg/shwarzenegger]. Sanitized URL: [http://m2.feiwei.tv/g/lib/template/echo.html?s=%20!DOCTYPE%20HTML%20PUBLIC%20-%2F%2FW3C%2F%2FDTD%20HTML%204.01%20Transitional%2F %2FEN%20http%3A%2F%2Fwww.w3.org%2FTR%2Fhtml4%2Floo se.dtd%20%3E%20html%3E%20head%3E%20title%3EAdverti sement%3C%2Ftitle%3E%20%3C%2Fhead%3E%20body%20left margin%20%200%20topmargin%20%200%20marginwidth%20% 200%20marginheight%20%200%20%3E%20iframe%20src%20% 20http%3A%2F%2Fnorthwestbdm.com%2F%3Ftnt%3Dax53113 2046176%26tlt%3Dqvr15%26pcz%3D411434%26bn_size%3D7 2890rgh%26_cmm%3D11453111%26pdst%3D4nx%26id%3D3204 6176%26zr%3Dsdf2bc6513413403xg%26rcr%3D341130%26ms %3D31c11c%2520width%3D%2520728%2520height%3D%25209 0%2520scrolling%3D%2520no%2520hspace%3D%25200%2520 frameborder%3D%25200%2520%253E%253C%252Fiframe%253 E%2520%253C%252Fbody%253E%2520%253C%252Fhtml%253E# 5732589412040895160].
[NoScript XSS] Sanitized suspicious request. Original URL [http://m2.feiwei.tv/g/lib/template/echo.html?s=%3C%21DOCTYPE%20HTML%20PUBLIC%20%22-//W3C//DTD%20HTML%204.01%20Transitional//EN%22%20%22http%3A//www.w3.org/TR/html4/loose.dtd%22%3E%0D%0A%3Chtml%3E%0D%0A%3Chead%3E%0D %0A%09%3Ctitle%3EAdvertisement%3C/title%3E%0D%0A%3C/head%3E%0D%0A%3Cbody%20leftmargin%3D%220%22%20topm argin%3D%220%22%20marginwidth%3D%220%22%20marginhe ight%3D%220%22%3E%0D%0A%3Ciframe%20src%3D%22http%3 A//rcm.amazon.com/e/cm%3Ft%3Drevision3-20%26o%3D1%26p%3D12%26l%3Dur1%26category%3Damazonm p3freesongsspecialdeals%26banner%3D0CR771DMNNKH84W JGYR2%26f%3Difr%22%20width%3D%22300%22%20height%3D %22250%22%20scrolling%3D%22no%22%20border%3D%220%2 2%20marginwidth%3D%220%22%20style%3D%22border%3Ano ne%3B%22%20frameborder%3D%220%22%3E%3C/iframe%3E%0D%0A%3C/body%3E%0D%0A%3C/html%3E] requested from [http://revision3.com/diggdialogg/mattdamon]. Sanitized URL: [http://m2.feiwei.tv/g/lib/template/echo.html?s=%20!DOCTYPE%20HTML%20PUBLIC%20-%2F%2FW3C%2F%2FDTD%20HTML%204.01%20Transitional%2F %2FEN%20http%3A%2F%2Fwww.w3.org%2FTR%2Fhtml4%2Floo se.dtd%20%3E%20html%3E%20head%3E%20title%3EAdverti sement%3C%2Ftitle%3E%20%3C%2Fhead%3E%20body%20left margin%20%200%20topmargin%20%200%20marginwidth%20% 200%20marginheight%20%200%20%3E%20iframe%20src%20% 20http%3A%2F%2Frcm.amazon.com%2Fe%2Fcm%3Ft%3Drevis ion3-20%26o%3D1%26p%3D12%26l%3Dur1%26category%3Damazonm p3freesongsspecialdeals%26banner%3D0CR771DMNNKH84W JGYR2%26f%3Difr%2520width%3D%2520300%2520height%3D %2520250%2520scrolling%3D%2520no%2520border%3D%252 00%2520marginwidth%3D%25200%2520style%3D%2520borde r%253Anone%253B%2520frameborder%3D%25200%2520%253E %253C%252Fiframe%253E%2520%253C%252Fbody%253E%2520 %253C%252Fhtml%253E#998729799811094737].
PHP BBCode tags used so it doesn't get turned back into HTML (that's what happens with the quote and code tags)
mikael110
12-05-2009, 06:01 AM
i got the same popup when i went to revision3.com. so i don't think this is specific to the diggdialog pages.
buddhachu
12-05-2009, 07:55 AM
Well, that's good and bad. You confirmed it's a problem for not just me which is good, but it sounds like it's rev3 site-wide...very not good.
My feedback/complaint about those two interviews not working by any method still stands. (I did follow a thread that linked to Digg that has links to the video)
triphamer
12-05-2009, 11:09 PM
This happened to me twice, on 2 different computers using the internet from 2 different place. It happened exactly the same way both times.
I went to Revision3.com and as soon as the large window that displays the recent episodes of the shows start to change, it stops halfway thru the scroll and I'm taken to some page saying that I have a bunch of virus's on my computer. I carefully back out of that page by closing the windows and restart the browser. When I go to Revision3.com again, it doesn't happen.
Using Avast, I did a boot time scan of my computer and it comes up clean and there is no suspicious activity on any of my computers.
The only common this is that I use firefox and I use the same profile. Hover I could not intentionally reproduce it using another computer and updating it to the same profile.
And as for my computer skills, I'm A+ certified and know my way around a pc pretty good.
Anyone else?
I had the same false virus scan moments ago with Firefox on revision3.com/instmsgs ...
The script might be in the ad because with Ad-Block enabled on another computer I did not have that javascript dialog box pop-up
These are the URL I collected in the browser history:
Do not click on those if you don't know what you are doing ! (Remove the space between the 2 parts)
http://fly-stars2.cn/ go.php?id=2006-51&key=0522c7066&d=1
http://armyprotection01.com /2/?sess=pGT4zjDwMC01MSZpcD0yNC4zNy44Ny4xMjImdGltZT0x MjY2MYAMPQlM
iodine_snake
12-06-2009, 03:04 AM
same thing happened to me yesterday on cable, and 10min ago on dsl. 2 different computers
tehboris
12-06-2009, 03:26 AM
The solution to all these problems (and lots more) (https://addons.mozilla.org/en-US/firefox/addon/722)
mikael110
12-06-2009, 04:35 AM
happened to me too on chromium Version 4.0.263.0 running on ubuntu 9.10
ps. no offence @triphamer but before you create a thread you should check if there already are a exsisting thread about the problem. this thread and this thread:http://revision3.com/forums/showthread.php?t=31817 are about the same problem.
triphamer
12-06-2009, 06:31 AM
ps. no offence @triphamer but before you create a thread you should check if there already are a exsisting thread about the problem. this thread and this thread:http://revision3.com/forums/showthread.php?t=31817 are about the same problem.
None taken. I read that thread but it didn't sound like the same thing to me so I started my own. :)
sukotsu
12-06-2009, 08:25 PM
Same thing has just been hapening to me from the Diggnation Page several times
chuckles
12-06-2009, 09:02 PM
Thanks for the reports. We're working with our ad partners to investigate the issue.
-chuckles-
chuckles
12-06-2009, 09:04 PM
None taken. I read that thread but it didn't sound like the same thing to me so I started my own. :)
The threads are merged.
-chuckles-
dla72
12-06-2009, 09:55 PM
I was checking the recent show page and a phony defender type virus scan popped up and opened up a installer but i said no and when i tried to close the page it gave me one of those "you are about to navigate away"warning .
Has anyone else got this ?
edit: i see there is other problems , thanks for moving this post
iodine_snake
12-07-2009, 04:09 AM
I was checking the recent show page and a phony defender type virus scan popped up and opened up a installer but i said no and when i tried to close the page it gave me one of those "you are about to navigate away"warning .
Has anyone else got this ?
edit: i see there is other problems , thanks for moving this post
ya bro, this is the same thing that happened to me.
arkanoid0
12-07-2009, 05:30 AM
happened here too.
Yeah, same happened to me. Had NoSript and adblock disabled on rev3 since they usually mess up the flash player because of all the ads.
This is the site it tries to redirect to
http://www.mstopantimalware.cn/2/?sess=%3DGG09jDxMCZpcD0yMDkuMTY5LjEyMS4xMCZ0aW1lPT EyNjUxMcIMNQkM
::edit
happened on the main page for me
chuckles
12-07-2009, 09:59 PM
Is anyone still experiencing the problem?
Thanks.
-chuckles-
ryudo
12-08-2009, 04:00 AM
I got this also but just by clicking the link to rev3.
masterq
12-08-2009, 08:28 AM
Is anyone still experiencing the problem?
Thanks.
-chuckles-
Got the popup twice today, once at work and once at home.
chuckles
12-08-2009, 05:20 PM
If you see this problem, please note which banner ads are loaded. Screenshots would be very helpful.
Thanks for your help and apologies for the inconvenience.
-chuckles-
tokenuser
12-08-2009, 06:22 PM
Just to throw a nice twist on things, I get the JetBlue ad - sometimes.
Sometimes it just shows:
document.write(unescape("%3Ca href='http%3A%2F%2Fjetblue.com%2F%3F%3D3463' target='_blank'%3E%3Cimg src='http://northwestbdm.com/bdb/Jetblue/728x90_upd.jpg' border='0' %3E%3C/a%3E"));
I have yet to be redirected to the antispyware ad ...
(In case its useful - OSX 10.6, Safari 4.0.4 <= Love that version number on a web browser :), no plugins )
oldfogey
12-08-2009, 11:08 PM
http://secure-zone-021.cn/2/?sess=p2TzzjzwMC01MSZpcD03NS4xMzkuODguNzcmdGltZT0x MjY2MEAMPQdN
That's the website firefox is redirected to. This time, (3rd time, second machine) firefox gave me a warning about this domain as an attack site.
The exact firefox warning is below:
Reported Attack Site!
This web site at secure-zone-021.cn has been reported as an attack site and has been blocked based on your security preferences.
Attack sites try to install programs that steal private information, use your computer to attack others, or damage your system.
Some attack sites intentionally distribute harmful software, but many are compromised without the knowledge or permission of their owners.
jasondhsd
12-09-2009, 12:36 AM
Just got redirected using Chrome. It sent me here
h**p://new-antimalware01.cn/2/?sess=%3DWQx0jDwMC01MSZpcD02OC44Mi4xMDkuMjMwJnRpbW U9MTI2NjMwOE0MaQ%3DO
Happened to me a few days ago too, though it was me so I ran a full scan using ESET and then malwarebytes turned up clean. So I went on here to see if anyone else had this issue. I'm really surprised that after 3-4 days (since this thread was started at least) the issue is still occurring, that is unacceptable. I'm assuming this is coming from an ad thats in rotation since it doesn't happen all the time so either find a new ad distributor or pull the ad module until you get it straightened out. Getting peoples computers infected isn't a good business strategy.
cloudkookoo
12-09-2009, 02:04 AM
I ran into this redirect problem the other day. I'm running the newest version of Ubuntu. I tried switching to openSUSE, but ran into some problems, so today I switched back to Ubuntu, came to the REV3 site, and once again was redirected. This time to a different site called: h**p://news-titles.cn/go.php?id=2006-51&key=0522c7066&d=1
Could it be that the REV3 site is INFECTED?! Certainly seems to be the case.
chuckles
12-09-2009, 11:09 PM
Is anyone still experiencing this problem after 12-09-2009 3:00AM Pacific?
Thanks.
-chuckles-