Skip to main content
this nasty g00 adware insertion in popular newspaper sites..

 

https://github.com/uBlockOrigin/uAssets/issues/227

 

when i go to newspaper site,it just head to g00 adware referrer and consumes lot of bandwidth....

can webroot foil this attempt by prebenting g00 crap....potentially a malicious code is inserted by instart logic code....

you can see no of cookies set by this g00 crap

following is list of sites affected

 

'baltimoresun.com',

'boston.com',

'capitalgazette.com',

'carrollcountytimes.com',

'celebuzz.com',

'chicagotribune.com',

'courant.com',

'dailypress.com',

'deathandtaxesmag.com',

'gamerevolution.com',

'gofugyourself.com',

'hearthhead.com',

'infinitiev.com',

'mcall.com',

'nasdaq.com',

'orlandosentinel.com',

'ranker.com',

'sandiegouniontribune.com',

'saveur.com',

'sherdog.com',

'spin.com',

'sporcle.com',

'stereogum.com',

'sun-sentinel.com',

'thefrisky.com',

'thesuperficial.com',

'timeanddate.com',

'tmn.today',

'vancouversun.com',

'vibe.com',

'weather.com',

'wowhead.com',

'calgaryherald.com',

'edmontonjournal.com',

'edmunds.com',

'financialpost.com',

'leaderpost.com',

'montrealgazette.com',

'nationalpost.com',

'ottawacitizen.com',

'theprovince.com',

'thestarphoenix.com',

'windsorstar.com',
I would assume that it can given the nature of the threat but for the definitive answer we need to ask for the input of the Webroot Threat Researcher such as @...any chace that you could assist re. this one? ;)

 

Regards, Baldrick
Only affecting Chromium-based browsers?

 
yep only chromium
I can pass this along to our Web Analysts, but this looks like something that would be best handled by ad-blockers. 

 

-Dan
Hi Dan

 

Many thanks for the response...much appreciated.

 

Hi samual914

 

Further to Dan's recommendation please see below for some ada blockers for Chromium that a number of members use/recommend:

 

uBlock: https://chrome.google.com/webstore/detail/ublock-origin/cjpalhdlnbpafiamejdnhcphjbkeiagm?hl=en or

Privacy Badger: https://chrome.google.com/webstore/detail/privacy-badger/pkehgijcmpdhfbdbbnkijodmdjhbjlgp

 

Regards, Baldrick
If you visit the link in the initial post there is a link to an extension that takes care of this issue...

 

-Dan
Cheers, Dan. :D
here is whats the truth bout instart logic code..

`Instart Logic's technology used to disguise third-party network requests as first-party network requests, including the writing/reading of third-party cookies as first-party cookies. I consider this to be extremely hostile to users, even those not using a content blocker, as it allows third-party servers to read/write cookies even if a user chose to block 3rd-party cookies through your browser setting.`



also this instart logic is making dns tweaks to news content before it passes to its end users,it might result in future malicious payload........

ublock origin uses static filter lists,if it has no filter lists against those ,it will no work...

privacy badger not working....see here.....https://github.com/EFForg/privacybadger/issues/1044

webroot should prevent(dns change) this g00 adware insertion at earlier time...

now this affects more no of popular news websites,,,

Reply