Cruisers Forum
 


Join CruisersForum Today

Reply
 
Thread Tools Rate Thread Display Modes
Old 05-04-2011, 14:17   #1
Registered User
 
S/V_Surya's Avatar

Join Date: Mar 2009
Location: Sasafra river,MD
Boat: gulfstar ketch 41 Surya
Posts: 658
Driving Revenue JavaScript

I have a trendmicro watch on my PC. Everytime I open a page on this web site I get an alert about a site called http.cndlayer.com trying to run a jave script called driving revenue. It has been there for a couple days. Please get rid of this or I will I will have to move on.
__________________

__________________
S/V_Surya is offline   Reply With Quote
Old 05-04-2011, 14:20   #2
mrm
Registered User

Join Date: Feb 2011
Location: Poland, EU
Boat: crew on Bavaria 38 Cruiser
Posts: 651
Re: Malware java script

Hmm... I have most scripts blocked, but since I joined CF my email address started to be spammed mercilessly by some bizbooster folks, so some checking might be in order.
__________________

__________________
mrm is offline   Reply With Quote
Old 05-04-2011, 14:28   #3
Registered User

Join Date: Aug 2010
Posts: 611
Re: Malware java script

I would suggest doing a little research on the subject. Just because Trendmicro is flagging an unknown java script doesn't mean that all java scripts are bad. I work for a company that is heavily based in computer security and I don't have any issues with any scripts on this site while I'm at work and have no issues with virus', malware and the like.

Spammers sending mail to a mailbox would be completely unrelated. A mailicious pirce of code could be deleivered via E-mail, but wouldn't necessarily promote spam beign sent to a mailbox on an unrelated mail server.
__________________
Shrew is offline   Reply With Quote
Old 05-04-2011, 14:28   #4
Registered User
 
S/V_Surya's Avatar

Join Date: Mar 2009
Location: Sasafra river,MD
Boat: gulfstar ketch 41 Surya
Posts: 658
Re: Malware java script

If you google the web site you will find other people that have been alerted to a trojan trying to get on your PC. All user of CF should scan the PCs' to make sure they are not infected.
__________________
S/V_Surya is offline   Reply With Quote
Old 05-04-2011, 14:30   #5
cruiser

Join Date: May 2010
Location: SF Bay Area; Former Annapolis and MA Liveaboard.
Boat: Looking and saving for my next...mid-atlantic coast
Posts: 6,197
Re: Malware java script

I see embedded at end of page this:

<!-- Start Driving Revenue tag -->
<script language="JavaScript" type="text/javascript"> var DR_id = "1302";</script>
<script language="JavaScript" type="text/javascript" src="http://http.cdnlayer.com/drivingrevenue/DR_v4.js"></script>
<!-- End Driving Revenue tag -->



i also see really lousy CSS inline specs. and I do get ERRORS in the console for some of the js modules. The site is also not bug free.
__________________
SaltyMonkey is offline   Reply With Quote
Old 05-04-2011, 14:32   #6
Moderator
 
Janet H's Avatar

Cruisers Forum Supporter

Join Date: Jan 2007
Location: Pacific NW, USA
Boat: Cape Dory 27
Posts: 6,081
Images: 5
Re: Malware java script

Quote:
Originally Posted by S/V_Surya View Post
I have a trendmicro watch on my PC. Everytime I open a page on this web site I get an alert about a site called http.cndlayer.com trying to run a jave script called driving revenue. It has been there for a couple days. Please get rid of this or I will I will have to move on.
Hi - this is not malware. We use CDN to load the images that you see on the forum as well as some ads (which help keep the doors open). The images include avatars, images in posts and even some of the little icons you see. It allows us to keep the site running faster as well.

Quote:
Originally Posted by mrm View Post
Hmm... I have most scripts blocked, but since I joined CF my email address started to be spammed mercilessly by some bizbooster folks, so some checking might be in order.
We don't sell, share, loan or rent your e-mail or account information but if you post your e-mail address anywhere on the internet that is visible it's likely that you will be spammed. There are bots that search for e-mail addresses and you can be their new best friend...
__________________
Janet H is offline   Reply With Quote
Old 05-04-2011, 14:32   #7
cruiser

Join Date: May 2010
Location: SF Bay Area; Former Annapolis and MA Liveaboard.
Boat: Looking and saving for my next...mid-atlantic coast
Posts: 6,197
Re: Malware java script

Downloading the code, they appear at least to be owned by

Affiliate Every Link on the Web with VigLink

The code is compressed, so I need to beautify it to understand what it does
__________________
SaltyMonkey is offline   Reply With Quote
Old 05-04-2011, 14:33   #8
Registered User
 
S/V_Surya's Avatar

Join Date: Mar 2009
Location: Sasafra river,MD
Boat: gulfstar ketch 41 Surya
Posts: 658
Re: Malware java script

Yes thats the script not cdnlayer not cndlayer as noted in my earlier post.
__________________
S/V_Surya is offline   Reply With Quote
Old 05-04-2011, 14:34   #9
cruiser

Join Date: May 2010
Location: SF Bay Area; Former Annapolis and MA Liveaboard.
Boat: Looking and saving for my next...mid-atlantic coast
Posts: 6,197
Re: Malware java script

This has nothing to do with using CDN for serving resources. This is a tracking link and performing additional processing work unrelated to offloading cache images and the like
__________________
SaltyMonkey is offline   Reply With Quote
Old 05-04-2011, 14:36   #10
Registered User
 
S/V_Surya's Avatar

Join Date: Mar 2009
Location: Sasafra river,MD
Boat: gulfstar ketch 41 Surya
Posts: 658
Re: Malware java script

Quote:
Originally Posted by Janet H View Post
Hi - this is not malware. We use CDN to load the images that you see on the forum as well as some ads (which help keep the doors open). The images include avatars, images in posts and even some of the little icons you see. It allows us to keep the site running faster as well.



We don't sell, share, loan or rent your e-mail or account information but if you post your e-mail address anywhere on the internet that is visible it's likely that you will be spammed. There are bots that search for e-mail addresses and you can be their new best friend...
Why am I seeing this within the last cople of days?
__________________
S/V_Surya is offline   Reply With Quote
Old 05-04-2011, 14:36   #11
Moderator
 
Janet H's Avatar

Cruisers Forum Supporter

Join Date: Jan 2007
Location: Pacific NW, USA
Boat: Cape Dory 27
Posts: 6,081
Images: 5
Re: Malware java script

Quote:
Originally Posted by SaltyMonkey View Post
This has nothing to do with using CDN for serving resources. This is a tracking link and performing additional processing work unrelated to offloading cache images and the like
Yes - it's related to site advertising. It is not malware.
__________________
Janet H is offline   Reply With Quote
Old 05-04-2011, 14:39   #12
mrm
Registered User

Join Date: Feb 2011
Location: Poland, EU
Boat: crew on Bavaria 38 Cruiser
Posts: 651
Re: Malware java script

Quote:
Originally Posted by Janet H View Post
We don't sell, share, loan or rent your e-mail or account information but if you post your e-mail address anywhere on the internet that is visible it's likely that you will be spammed. There are bots that search for e-mail addresses and you can be their new best friend...
Janet, I never suggested you did, nor was my intention to do so. I just mentioned a suspicious correlation I noticed.
__________________
mrm is offline   Reply With Quote
Old 05-04-2011, 14:42   #13
cruiser

Join Date: May 2010
Location: SF Bay Area; Former Annapolis and MA Liveaboard.
Boat: Looking and saving for my next...mid-atlantic coast
Posts: 6,197
Re: Malware java script

Looking at the code, it appears to WRAP resources in the page with behavior tracking functionality. What it exactly does, can't tell since its not pretty named. Could be tracking user interaction on the site and logging it. For example, hovering over an ad image may generate a log entry that it was hovered. If it was clicked, another entry. It modifies to DOM for events and such.

However, this has nothing to do with using a CDN or not. It has to do with tracking activity on resource usage and navigation.
__________________
SaltyMonkey is offline   Reply With Quote
Old 05-04-2011, 14:59   #14
Captain
 
Andy R's Avatar

Cruisers Forum Supporter

Join Date: Nov 2005
Location: Forianopolis, Brasil
Posts: 1,574
Send a message via MSN to Andy R Send a message via Skype™ to Andy R
Re: Driving Revenue JavaScript

Quote:
Originally Posted by S/V_Surya View Post
I have a trendmicro watch on my PC. Everytime I open a page on this web site I get an alert about a site called http.cndlayer.com trying to run a jave script called driving revenue. It has been there for a couple days. Please get rid of this or I will I will have to move on.
This is NOT malware. Driving Revenue is a company that is used by thousands of websites as an affiliate marketing solution. If someone links to an eCommerce site that offers and affiliate program then they add an affiliate ID.

I will pass on your report of TrendMicro to the owners of DrivingRevenue as they take these alerts seriously. I'll let you know what I hear but in the mean time I can assure you it's not malware.
Quote:
Originally Posted by mrm View Post
Hmm... I have most scripts blocked, but since I joined CF my email address started to be spammed mercilessly by some bizbooster folks, so some checking might be in order.
I can assure you we do not sell, share or in any other way dispense any of our member's data including emails. Maybe it was a coincidence but I can assure you we have not shared your data with anyone.
Andy R is offline   Reply With Quote
Old 05-04-2011, 15:07   #15
cruiser

Join Date: May 2010
Location: SF Bay Area; Former Annapolis and MA Liveaboard.
Boat: Looking and saving for my next...mid-atlantic coast
Posts: 6,197
Re: Driving Revenue JavaScript

Hard to tell what they are pushing down that pipe outside their vendor id:
var DR_id = "1302"

I mean, can they track using my uid if i am signed in?

And they also have a number of trackers:
<!-- Social Knowledge Quantcast tag -->
<!-- Google Analytics tag -->

Start Martini Network 1x1 Pixel
Adify tag for "AudiencePixel" Ad Space

who know what else?
__________________

__________________
SaltyMonkey is offline   Reply With Quote
Reply

Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Trim - I'm 2" Off and It's Driving Me Crazy! rebel heart Monohull Sailboats 9 30-10-2009 17:31
DRIVING THE BOAT DWT Off Topic Forum 13 13-02-2009 05:19



Copyright 2002- Social Knowledge, LLC All Rights Reserved.

All times are GMT -7. The time now is 04:06.


Google+
Powered by vBulletin® Version 3.8.8 Beta 1
Copyright ©2000 - 2017, vBulletin Solutions, Inc.
Social Knowledge Networks
Powered by vBulletin® Version 3.8.8 Beta 1
Copyright ©2000 - 2017, vBulletin Solutions, Inc.

ShowCase vBulletin Plugins by Drive Thru Online, Inc.