ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Javascript pop up in Firefox on Yahoo Finance

    IT Discussion
    7
    24
    1.9k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • CCWTechC
      CCWTech
      last edited by CCWTech

      I have a client that when they go to finance.yahoo.com they will often get a pop up Window for a Firefox update and asking them to run a firefox-patch.js file. They are smart enough to not run it.

      It only happens in Firefox, and only on Yahoo Finance. 0_1505429706634_Capture.JPG

      In the lower left hand corner, instead of loading and stopping, it keeps trying to load different pages.

      I have run every known AV Scanner, looked for issues using FRST and even nuked and paved. After nuke & pave, going back to finance.yahoo.com I still get the the pop-up. This happens on any computer in the network.

      I am even using Webroot Filtered DNS as the forwarder on the Windows DNS Server as well as in Untangle.

      I'm scratching my head trying to think of what else may be causing this.

      1 Reply Last reply Reply Quote 1
      • scottalanmillerS
        scottalanmiller
        last edited by

        Maybe their DNS is poisoned?

        1 Reply Last reply Reply Quote 1
        • CCWTechC
          CCWTech
          last edited by

          That's my thought as well. I had Untangle support remote in. They looked at the settings and can't see any issues. I was using Comcast DNS (default from the WAN) on untangle and using Google DNS as the forwarders on the Domain Controller DNS. I switched both to Webroot's Secure DNS (paid service) and still no difference. I turned on the Adblocker feature on Untangle and no help there.

          1 Reply Last reply Reply Quote 0
          • DashrenderD
            Dashrender
            last edited by

            There might be malicious ads on the Yahoo page?

            1 Reply Last reply Reply Quote 0
            • CCWTechC
              CCWTech
              last edited by

              Very likely but I can't reproduce it outside of their network. Outside of their network the page loads and stops loading. There isn't the constant lower left activity showing several links loading.

              DashrenderD 1 Reply Last reply Reply Quote 0
              • DashrenderD
                Dashrender @CCWTech
                last edited by

                @ccwtech said in Javascript pop up in Firefox on Yahoo Finance:

                Very likely but I can't reproduce it outside of their network. Outside of their network the page loads and stops loading. There isn't the constant lower left activity showing several links loading.

                That makes me think the firewall might be compromised, or the ISP is injecting things.

                1 Reply Last reply Reply Quote 0
                • CCWTechC
                  CCWTech
                  last edited by

                  Untangle doesn't appear to be compromised (from what I can see). I use Comcast and am geographically ~ 2 miles from their office and can't replicate it. I do use a Meraki instead of Untangle and many other parts of my network are different however. I haven't tried hooking a computer directly to the modem to see what happens if I do that... (I just thought of that while writing this.)

                  1 Reply Last reply Reply Quote 0
                  • gjacobseG
                    gjacobse
                    last edited by

                    It has been some years since I worked with an Untangle box and I know there have been a number of changes since then.

                    I believe if the pop up is the same address, you can block it via the UT GUI,.. I just don't remember how...

                    I would on occasion run off the 70 page report and make adjustments based on the junk that got through - also blocking whole ip ranges (countries) that were trying to brute force the system.

                    1 Reply Last reply Reply Quote 0
                    • CCWTechC
                      CCWTech
                      last edited by

                      They don't want to block finance.yahoo.com and the multiple pages it's loading are too many to block.

                      1 Reply Last reply Reply Quote 0
                      • CCWTechC
                        CCWTech
                        last edited by

                        Here is an example: https://youtu.be/A5Q0efHMbU4

                        gjacobseG DanpD 2 Replies Last reply Reply Quote 0
                        • gjacobseG
                          gjacobse @CCWTech
                          last edited by

                          @ccwtech said in Javascript pop up in Firefox on Yahoo Finance:

                          Here is an example: https://youtu.be/A5Q0efHMbU4

                          From the stream of links and such in the status bar, there was a number of adclick. This is something I recall being able to block with UT.

                          1 Reply Last reply Reply Quote 0
                          • DanpD
                            Danp @CCWTech
                            last edited by

                            @ccwtech FWIW, i see similar behavior when viewing this page from both home and work. No JS popups though...

                            CCWTechC 1 Reply Last reply Reply Quote 1
                            • A
                              Alex Sage
                              last edited by

                              What extensions are install on FF?

                              1 Reply Last reply Reply Quote 0
                              • CCWTechC
                                CCWTech
                                last edited by

                                None. I did a nuke and pave and fresh install of FF from Ninite.com.

                                1 Reply Last reply Reply Quote 0
                                • CCWTechC
                                  CCWTech @Danp
                                  last edited by

                                  @danp That's good info. I'm wondering if you can just leave finance.yahoo.com up in the background. The pop-ups aren't always instant.

                                  DanpD 2 Replies Last reply Reply Quote 0
                                  • DanpD
                                    Danp @CCWTech
                                    last edited by

                                    @ccwtech Sure. I'll report back if anything unusual occurs.

                                    1 Reply Last reply Reply Quote 0
                                    • DanpD
                                      Danp
                                      last edited by

                                      https://support.mozilla.org/en-US/kb/i-found-fake-firefox-update

                                      DashrenderD 1 Reply Last reply Reply Quote 1
                                      • DanpD
                                        Danp @CCWTech
                                        last edited by

                                        @ccwtech The page has been opened for about 15 mins without any popups. FWIW, the page eventually finished loading after between 10 and 15 mins.

                                        1 Reply Last reply Reply Quote 1
                                        • DashrenderD
                                          Dashrender @Danp
                                          last edited by

                                          @danp said in Javascript pop up in Firefox on Yahoo Finance:

                                          https://support.mozilla.org/en-US/kb/i-found-fake-firefox-update

                                          LOL - that was my guess.
                                          malvertising.

                                          1 Reply Last reply Reply Quote 0
                                          • momurdaM
                                            momurda
                                            last edited by

                                            I see this from time to time, only when using firefox. Even on sites like Ars it happens.
                                            They serve bad advertisements to you, and one of them gets you a popup in firefox.

                                            DashrenderD 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • First post
                                              Last post