2 July 2009

Greens website taken over by spammers?

| johnboy
Join the conversation
7

RiotACT’s all seeing eye has noticed a strange thing. It’s a link to an online payday lender on the ACT Greens’ website.

Now if you go to that website with a modern browser you won’t see it there. The all seeing eye doesn’t use sophisticated web rendering.

But if you take a look at the source code (and I’ve printed out a copy) you’ll find it’s definitely there.

Down at the very tail end of the code there are links to a staggering array of viagra products.

Perhaps time for a revamp?

Join the conversation

7
All Comments
  • All Comments
  • Website Comments
LatestOldest

Oh, now I see.

Hell Skid, how did you do that – find out all that stuff?

E: The viagra ads.

Wierd… Idebate.org are a Soros Group Foundation (as in George “Swimming Around In A Tower Full of Cash, 29th Richest Man On Earth” Soros)

Domain Name:IDEBATE.ORG
Created On:19-May-1999 21:17:10 UTC
Last Updated On:05-Feb-2008 16:27:13 UTC
Expiration Date:19-May-2013 21:17:46 UTC
Sponsoring Registrar:Network Solutions LLC (R63-LROR)
Status:CLIENT TRANSFER PROHIBITED
Registrant ID:21838242-NSI
Registrant Name:Anthony Galietti
Registrant Organization:Open Society Institute – Soros Foundations
Registrant Street1:400 West 59th Street
Registrant Street2:4th Floor
Registrant Street3:
Registrant City:New York
Registrant State/Province:NY
Registrant Postal Code:10019
Registrant Country:US
Registrant Phone:+1.212548069
Registrant Email:agalietti@SOROSNY.ORG
Admin ID:21838242-NSI
Admin Name:Anthony Galietti
Tech Email:HCHANG@SOROSNY.ORG

The source code of any of the documents in the idebate.org/ctac/documents/pfizer-viagra-online/ directories of iDebate.org all point to an italian website called Farmacia-n1.com which is full of both viagra referrers and porn referrers.
So very many porn referrers.
Although at first appearances an Italian website, it is hosted in the Ukraine, with Domain registered to:
LV Inc LTD Li.
James Mosersbrown (bobbba@axigenmail.com)
5841 S. Maryland Avenue
Chicago
3528,60637

(Which according to Google Maps is the University of Chicago hospital)

Good luck chasing phantoms, its probably just easier to go back to scratch and find a better host.

bound to be some pun in this.

channelvision eh?

another great service from transact.

Looks like I lied…finally found the log & it appears to be the channelvision site that has a virus…

Threat Name: VirTool:JS/Obfuscator.D
Detection Date and Time: 2/07/2009 9:10 PM
File Name: C:\Users\Tim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YGKI8V0D\channelvision_com_au[1].htm
Threat Severity: Severe
Threat Category: Tool
Contained Object: (SCRIPT0000)
Virus and spyware monitoring found potentially unwanted software: (ANTIVIRUS_ONACCESS)
Threat Status: Removed

Hmmm the code is still there. Definitely looks like something nasty sitting on their hosting.

OH WAIT I just had a Trojan warning triggered off by my antivirus (obfuscator Trojan) – only had riotact.com and the greens site open…I’m now guessing a Trojan is hanging out on the greens site waiting to infect people behind on Windows Updates, antivirus or using an old browser/OS.

Looking for the log in my antivirus (windows onecare) to see wher eit came from…

Daily Digest

Want the best Canberra news delivered daily? Every day we package the most popular Riotact stories and send them straight to your inbox. Sign-up now for trusted local news that will never be behind a paywall.

By submitting your email address you are agreeing to Region Group's terms and conditions and privacy policy.