Author Topic: Baidu advertising slot under attack?  (Read 1066 times)

Offline polonus

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 17217
  • Gender: Male
  • malware fighter
    • Personal Message (Offline)
Baidu advertising slot under attack?
« on: June 30, 2012, 11:28:39 AM »
Hi folks,

Look at this script:  htxp://www.sopopo.com/d/js/acmsd/thea6.js
Is it suspicious or benign? Link syntax issues?
Site was infected with trojan password stealer...

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 20822
    • >>>  avast! Forum - Deutschsprachiger Bereich  <<<
    • Personal Message (Offline)
XP SP3 - avast! 8.0.1489 - CIS 3.14 [FW/D+] - EAM 7.0.0.25 [OD] - Firefox ESR 17.0.6 [NS/ABP/BP/QP/WR] - Thunderbird 17.0.6 [EM/CH]
Deutschsprachiger Bereich -> avast! Wissenswertes (Downloads, Anleitungen und Infos): http://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 17217
  • Gender: Male
  • malware fighter
    • Personal Message (Offline)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • avast! Überevangelist
  • Certainly Bot
  • *****
  • Posts: 66506
  • Gender: Male
  • No support PMs thanks
    • Personal Message (Offline)
Re: Baidu advertising slot under attack?
« Reply #3 on: June 30, 2012, 03:40:10 PM »
<off-topic>
And we questioned why so damn many Baidu spiders crawling the forums in comparison to the big boys Google, MSN and Yahoo.

I still don't know f this doesn't place an adverse load on the forum server/speed at times.
</off-topic>
Core2Duo E8300/ 4GB Ram/ WinXP ProSP3/ avast! free 8.0.1489/ Outpost Firewall Pro8.1/ Firefox 21.0, NoScript, RequestPolicy/ MailWasher Pro/ DropMyRights/ MalwareBytes AntiMalware Pro 1.75/ WinPatrol+/ Drive Image 7.1/ SnagIt 10.0/ avast! mobile security

Offline Asyn

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 20822
    • >>>  avast! Forum - Deutschsprachiger Bereich  <<<
    • Personal Message (Offline)
Re: Baidu advertising slot under attack?
« Reply #4 on: June 30, 2012, 03:41:22 PM »
<off-topic>
And we questioned why so damn many Baidu spiders crawling the forums in comparison to the big boys Google, MSN and Yahoo.

I still don't know f this doesn't place an adverse load on the forum server/speed at times.
</off-topic>

+1
XP SP3 - avast! 8.0.1489 - CIS 3.14 [FW/D+] - EAM 7.0.0.25 [OD] - Firefox ESR 17.0.6 [NS/ABP/BP/QP/WR] - Thunderbird 17.0.6 [EM/CH]
Deutschsprachiger Bereich -> avast! Wissenswertes (Downloads, Anleitungen und Infos): http://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 17217
  • Gender: Male
  • malware fighter
    • Personal Message (Offline)
Re: Baidu advertising slot under attack?
« Reply #5 on: June 30, 2012, 04:02:39 PM »
Hi DavidR and Asyn,

So this was not only obvious to China's Regulators but also to our DavidR. Very good combining of facts
always will bring rewarding insight  :D 
"Well it did not help towards bringing down that baidu related server load, did it?"

Bidders with the highest bid would get the top slot  for their product by via option contracts 
as reporters for CCTV have commented.  "Time for some to take some short positions there!  ;D".

See this report: http://dl.acm.org/citation.cfm?id=2188160 (University College London, Jun Wan, Bowei Chen (authors
of Selling futures online advertising slots via option contracts),

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 17217
  • Gender: Male
  • malware fighter
    • Personal Message (Offline)
Re: Baidu advertising slot under attack?
« Reply #6 on: June 30, 2012, 11:49:17 PM »
Hi DavidR,

To go off-topic a bit. Baidu bot seems to ignore disallow robot.txt
and it is scraping literary anything, image files included.
This is Baidu spider, not the full string...
It is best to have Baidu wait
up to 999 seconds for a page request.
See: http://gelm.net/How-to-block-Baidu-with-PHP.htm (article chelm.net)
this is to better perform on limited bandwidth servers,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • avast! Überevangelist
  • Certainly Bot
  • *****
  • Posts: 66506
  • Gender: Male
  • No support PMs thanks
    • Personal Message (Offline)
Re: Baidu advertising slot under attack?
« Reply #7 on: July 01, 2012, 12:16:45 AM »
I know if it the baidu spider and not the full string, hence my <off-topic> bit, but it is a pain in the rear why it would require 88 spiders and more on occasion to index the forums.

Problem is despite a comment already in another area to block/restrict baidu nothing appears to have been done. But a user can't check the robot.txt file, so I don't know if that may have been modified, if so 88 baidu spiders ignored it (now Baidu = 100 of 109).
Core2Duo E8300/ 4GB Ram/ WinXP ProSP3/ avast! free 8.0.1489/ Outpost Firewall Pro8.1/ Firefox 21.0, NoScript, RequestPolicy/ MailWasher Pro/ DropMyRights/ MalwareBytes AntiMalware Pro 1.75/ WinPatrol+/ Drive Image 7.1/ SnagIt 10.0/ avast! mobile security

Offline Asyn

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 20822
    • >>>  avast! Forum - Deutschsprachiger Bereich  <<<
    • Personal Message (Offline)
XP SP3 - avast! 8.0.1489 - CIS 3.14 [FW/D+] - EAM 7.0.0.25 [OD] - Firefox ESR 17.0.6 [NS/ABP/BP/QP/WR] - Thunderbird 17.0.6 [EM/CH]
Deutschsprachiger Bereich -> avast! Wissenswertes (Downloads, Anleitungen und Infos): http://forum.avast.com/index.php?topic=60523.0

Offline DavidR

  • avast! Überevangelist
  • Certainly Bot
  • *****
  • Posts: 66506
  • Gender: Male
  • No support PMs thanks
    • Personal Message (Offline)
Re: Baidu advertising slot under attack?
« Reply #9 on: July 01, 2012, 12:51:38 PM »
Yes, same thing here really; why would it need 100 Baidu spiders scanning the whole forum when the only real area of interest would be the Chinese sub-forum, with that traffic 1 spider would be all that would be required.
Core2Duo E8300/ 4GB Ram/ WinXP ProSP3/ avast! free 8.0.1489/ Outpost Firewall Pro8.1/ Firefox 21.0, NoScript, RequestPolicy/ MailWasher Pro/ DropMyRights/ MalwareBytes AntiMalware Pro 1.75/ WinPatrol+/ Drive Image 7.1/ SnagIt 10.0/ avast! mobile security

Offline Asyn

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 20822
    • >>>  avast! Forum - Deutschsprachiger Bereich  <<<
    • Personal Message (Offline)
Re: Baidu advertising slot under attack?
« Reply #10 on: July 01, 2012, 01:02:50 PM »
Yes, same thing here really; why would it need 100 Baidu spiders scanning the whole forum when the only real area of interest would be the Chinese sub-forum, with that traffic 1 spider would be all that would be required.

Absolutely..!! And you/we know, who has to answer/check/resolve that. ;)
XP SP3 - avast! 8.0.1489 - CIS 3.14 [FW/D+] - EAM 7.0.0.25 [OD] - Firefox ESR 17.0.6 [NS/ABP/BP/QP/WR] - Thunderbird 17.0.6 [EM/CH]
Deutschsprachiger Bereich -> avast! Wissenswertes (Downloads, Anleitungen und Infos): http://forum.avast.com/index.php?topic=60523.0