Nexus PDF wtf?

Post » Fri Jun 18, 2010 8:50 pm

Anyone else getting a random piece of crap pdf trying to save to your machine when simply going onto the FalloutNexus site?

I know I don't have a virus or anything, I think its one of the ad's from the site as it only comes up when the the ad loads. Its extremely irritating even though it only happened like twice in the past several days.

PS- I didn't allow it to download obviously.
User avatar
Matt Gammond
 
Posts: 3410
Joined: Mon Jul 02, 2007 2:38 pm

Post » Fri Jun 18, 2010 10:58 pm

Yup, thats happened to me. I thought it was just me, so I didn't speak up or anything. :P

Glad to know its not a virus, though.
User avatar
Hairul Hafis
 
Posts: 3516
Joined: Mon Oct 29, 2007 12:22 am

Post » Sat Jun 19, 2010 5:31 am

Perhaps a better place to ask would be the forums on the site you're talking about?

Cipscis
User avatar
Julia Schwalbe
 
Posts: 3557
Joined: Wed Apr 11, 2007 3:02 pm

Post » Fri Jun 18, 2010 7:08 pm

Well I don't THINK it is a virus at least. More over since many of us go to that site, I thought I'd ask around here. Besides, I feel a little safer hanging around here asking than there waiting for it to screw something up.

Anyone else getting this strange crap? I'm sure its an ad, but It shouldn't be doing what its doing regardless. =/
User avatar
Heather beauchamp
 
Posts: 3456
Joined: Mon Aug 13, 2007 6:05 pm

Post » Sat Jun 19, 2010 4:45 am

been getting this thing as well was going to dl it and run it in a sandbox to see what the hell it is next time it pops up
User avatar
Dark Mogul
 
Posts: 3438
Joined: Tue Feb 20, 2007 11:51 am

Post » Fri Jun 18, 2010 8:21 pm

Feel free, but I can't stress enough to be wary. Give us some insight if you wouldn't mind assuming you do. Oh and pdf's can easily launch viral websites and such so...yeah, be careful.
User avatar
Red Sauce
 
Posts: 3431
Joined: Fri Aug 04, 2006 1:35 pm

Post » Sat Jun 19, 2010 6:55 am

Feel free, but I can't stress enough to be wary. Give us some insight if you wouldn't mind assuming you do. Oh and pdf's can easily launch viral websites and such so...yeah, be careful.

yeah i know, but ive got a backup from last week so can easily reinstall if something goes horribly horribly wrong 0_o
User avatar
REVLUTIN
 
Posts: 3498
Joined: Tue Dec 26, 2006 8:44 pm

Post » Fri Jun 18, 2010 10:28 pm

Much thanks, we're here if you could keep us posted what you find out. =)
User avatar
Etta Hargrave
 
Posts: 3452
Joined: Fri Sep 01, 2006 1:27 am

Post » Sat Jun 19, 2010 7:58 am

Much thanks, we're here if you could keep us posted what you find out. =)

ok so still havent been able to get the pdf to pop back up but i found this

http://thenexusforums.com/index.php?showtopic=179568&hl=pdf

do not friggin download it, it is a virus, looks like its been around since last month and the mods have not been able to get rid of it.
User avatar
Taylor Tifany
 
Posts: 3555
Joined: Sun Jun 25, 2006 7:22 am

Post » Fri Jun 18, 2010 9:23 pm

Get some http://www.google.de/chrome and https://chrome.google.com/extensions/detail/gighmmpiobklfepjocnamgkkbiglidom geez...
User avatar
Taylor Thompson
 
Posts: 3350
Joined: Fri Nov 16, 2007 5:19 am

Post » Sat Jun 19, 2010 3:40 am

Get some http://www.google.de/chrome and https://chrome.google.com/extensions/detail/gighmmpiobklfepjocnamgkkbiglidom geez...

abp dosent block every single advertisemant known to man, i have firefox and abp + all the necessary subscriptions and this little bastard has still popped up
User avatar
Oyuki Manson Lavey
 
Posts: 3438
Joined: Mon Aug 28, 2006 2:47 am

Post » Sat Jun 19, 2010 5:31 am

Cripes, just when you thought it was safe to go into the water =/

Thanks for the heads up. Well I won't be going to nexus till that's cleared up now, friggin piece of [censored] firefox auto downloads before you tell it too =/

So anyone using firefox IMMEDIATELY kill/stop and close the browser and all its tabs in as fast as you can if you see that on the nexus. Firefox will automatically download the damn thing even if you just sit there at the "save to" option.

I have been trying to find a way to kill that feature.
User avatar
Shelby Huffman
 
Posts: 3454
Joined: Wed Aug 08, 2007 11:06 am

Post » Sat Jun 19, 2010 6:31 am

Cripes, just when you thought it was safe to go into the water =/

Thanks for the heads up. Well I won't be going to nexus till that's cleared up now, friggin piece of sh!t firefox auto downloads before you tell it too =/

So anyone using firefox IMMEDIATELY kill/stop and close the browser and all its tabs in as fast as you can if you see that on the nexus. Firefox will automatically download the damn thing even if you just sit there at the "save to" option.

I have been trying to find a way to kill that feature.

go to tools options applications look for pdf and set to always ask, i do this will all downlodable files, though if you dont know exactly what each option in there does id only mess with the pdf one.
User avatar
Nicole Mark
 
Posts: 3384
Joined: Wed Apr 25, 2007 7:33 pm

Post » Sat Jun 19, 2010 2:02 am

I thank you for the tip. But alas the option is really not good enough. Even when the user is just sitting there looking at the "where to save file" option, firefox has already begun downloading it to the temporary file section hidden on your hard drive. Its very very bad that the browser does this as it can be dangerous. =/
User avatar
Emily Jones
 
Posts: 3425
Joined: Mon Jul 17, 2006 3:33 pm

Post » Fri Jun 18, 2010 7:41 pm

Get some http://www.google.de/chrome and https://chrome.google.com/extensions/detail/gighmmpiobklfepjocnamgkkbiglidom geez...

http://my.opera.com/desktopteam/blog/2010/02/17/no-rest-for-the-wicked. :P
User avatar
Kayla Bee
 
Posts: 3349
Joined: Fri Aug 24, 2007 5:34 pm

Post » Fri Jun 18, 2010 11:27 pm

Except neither Chrome nor Opera have any sort of protection against this kind of attack. In fact, lacking a virtualized protected mode (that IE has), they're even weaker against it.

The attack is against Adobe Reader, which may or may not automatically load into your browser when it encounters a PDF. If it does load into your browser, and your browser is anything other than IE7/8 in protected mode, you are infected.

The solution is to replace Adobe Reader (by removing it) or to turn off Javascript within Reader.
User avatar
Nichola Haynes
 
Posts: 3457
Joined: Tue Aug 01, 2006 4:54 pm

Post » Sat Jun 19, 2010 12:20 am

Thanks for the tips Hat. =)

Surprising the nexus is not screening their ad's a little better. But I hope that problem will be fixed soon.

Hope people read this here first before allowing their machines damaged.
User avatar
lucy chadwick
 
Posts: 3412
Joined: Mon Jul 10, 2006 2:43 am

Post » Sat Jun 19, 2010 10:16 am

I use Firefox with AdblockPlus and have never seen any ads at Nexus but thanks to this thread and the advice from Hattix, I no longer have Adobe Reader on my computer. I installed http://blog.kowalczyk.info/software/sumatrapdf/index.html instead after seeing it recommended by other forum members and on howtogeek.com.
User avatar
Jonathan Braz
 
Posts: 3459
Joined: Wed Aug 22, 2007 10:29 pm

Post » Fri Jun 18, 2010 11:37 pm

Glad to bring it to even a handful of people. I hate to be paranoid but Sometimes a little caution is good. Stay safe folks =)
User avatar
Dan Endacott
 
Posts: 3419
Joined: Fri Jul 06, 2007 9:12 am

Post » Fri Jun 18, 2010 9:00 pm

Thanks for the tips Hat. =)

Surprising the nexus is not screening their ad's a little better. But I hope that problem will be fixed soon.

Hope people read this here first before allowing their machines damaged.



Hard part is it's due to nexus iirc using an ad service and not handpicking ads.

Much like digg and facebook does, they don't choose the ads. They just let a third party put them up for them

It is way too easy for a service based ad to be compromised.
User avatar
Mike Plumley
 
Posts: 3392
Joined: Wed Sep 05, 2007 10:45 pm

Post » Sat Jun 19, 2010 6:06 am

Was not aware of that fact. But that makes more sense. Ultimately though its us the end users who suffer. Sure the files do not seem compromised as of yet that I'm aware of. But neither do you want to casually forget and skip on over to the nexus and "oh fiddlestix, it ruins your machine".

Kinda just keeping this thread up because obviously people here go there a lot and it makes sense for people to be aware of this.
User avatar
christelle047
 
Posts: 3407
Joined: Mon Apr 09, 2007 12:50 pm

Post » Sat Jun 19, 2010 5:28 am

Thank you for letting us know. I don't go to the Nexus often, but I hope this situation can be resolved soon.

Fortunately, I don't have PDFs autoloading at all, so even if Firefox attempts to download it, it won't automatically launch.

And Firefox is a really good browser, although it fails on some webpages...
User avatar
Shannon Lockwood
 
Posts: 3373
Joined: Wed Aug 08, 2007 12:38 pm

Post » Fri Jun 18, 2010 10:49 pm

If you want an adblocker that simultaneously works for every browser, you can use an updated HOSTS file: http://www.mvps.org/winhelp2002/hosts.htm
Direct download: http://www.mvps.org/winhelp2002/hosts.zip
User avatar
Juanita Hernandez
 
Posts: 3269
Joined: Sat Jan 06, 2007 10:36 am

Post » Fri Jun 18, 2010 10:10 pm

Hi folks,

This problem is related to a bad advertiser somewhere down the chain. Most small/independent sites will make use of third-parties to sell their advertising inventory as they have no time or social capital to strike deals with individual companies themselves. You actually deal with 2 or more third-parties that works in a chaining system; the first company will be your exclusive company that you give all your ad inventory to. They utilise it the best they can but some of the inventory they won't be able to show ads for either because they have none, they've reached their cap or the user isn't from a geographic location they're interested in, so that ad inventory gets passed on to a second company. Rinse and repeat as much as you want down a chain in format: Exclusive (first) ad company -> company #2 -> company #3 -> company #4 ... End.

Ideally you chain your companies in order of how good/effective/profitable they are, but in turn some of these companies might send some of your inventory to chains of their own, and this is where problems start. If they outsource some of your inventory to a company that isn't as reputable or stringent on their safety standards as the ones you've picked then you run in to problems. This will be what has happened here.

If you would actually like to help troubleshoot this problem then providing me with as much information as possible will be a great help. A screenshot of the ad in question and any URLs related to it would also be super helpful. I've already been on the phone to my ad agent(s) and spoken to them about it and we're all investigating it now.

You can use an adblocker if you want but obviously becoming a premium member (who see no ads on the site) would be preferable. Advertising income and premium membership are absolutely paramount to keeping the site(s) a float and people using adblockers are essentially leeching off the site. What with the sites making use of 8 different dedicated servers and serving 70TB of bandwidth at a constant 450mbit the bills are up to about $4000/month right now :)

Remember to keep your anti-virus and firewall up-to-date as well.
User avatar
Suzy Santana
 
Posts: 3572
Joined: Fri Aug 10, 2007 12:02 am

Post » Sat Jun 19, 2010 7:07 am

It needs to be added that by no stretch of the imagination is this the fault of Nexus.

Ads are bought from an agency, in this case, it's organised crime using stolen identities to buy the ads, which then include malicious PDFs. The agency doesn't know anything and the first thing site owners know is when their users are lambasting them for distributing malware.

Nexus isn't the only site that's been affected, some extremely high profile sites such as Fark and Washington Post also were affected.
User avatar
Lauren Denman
 
Posts: 3382
Joined: Fri Jun 16, 2006 10:29 am

Next

Return to Fallout 3