Team-BHP - Virus problems/spyware problems! post here!
Team-BHP

Team-BHP (https://www.team-bhp.com/forum/)
-   Gadgets, Computers & Software (https://www.team-bhp.com/forum/gadgets-computers-software/)
-   -   Virus problems/spyware problems! post here! (https://www.team-bhp.com/forum/gadgets-computers-software/50187-virus-problems-spyware-problems-post-here-3.html)

Quote:

Originally Posted by roamer012 (Post 4450383)
I find the issue crops up on specific networks and devices.

Okay, this could be two things:

1) Your ISP messing around (as others have posted)

2) DNS Poisoning/hijacking. Basically your router or modem has been compromised, and the DNS server IPs have been changed to spammy servers that will sometimes open the site you want, and other times open an ad page.

I've seen both of these things happen first hand. Rather unbelieveable in case #1. More info later...

Quote:

Originally Posted by roamer012 (Post 4450383)
However the pop up is usually restricted to Team BHP and few other websites.

This might be because Team-BHP allows http & httpS -- while most other sites force httpS. We'll be doing that soon.

POSSIBLE SOLUTIONS:

1) Browse Team-BHP on httpS only (or better yet, use an extension like 'httpS everywhere') that should help.

2) Block cabalten in Chrome - thanks to Siva Kumar D
Go to chrome://settings > Content Settings > Javascript - Manage Exceptions > Add [*.]cobalten.com and select Block
3) Check that your DNS server IPs on your modem & router are legitimate (Google DNS or OpenDNS are best)

4) Get another ISP. There are many good options these days.


Quote:

Originally Posted by i_see (Post 4450453)
It seems BSNL is injecting adds for additional revenue:Frustrati

Wouldn't be a first... and even Airtel was responsible for doing the same at one point.

Quote:

Originally Posted by samaspire (Post 4450715)
Can't we do anything about it? Complain to somebody?

Here's what I did for MTNL, and I'm not sure what effect it had, but it eventually stopped!

Shady Business: Airtel & MTNL injecting advertisements / js into websites you visit!

Quote:

Originally Posted by Rehaan (Post 4451323)
Okay, this could be two things:

2) DNS Poisoning/hijacking. Basically your router or modem has been compromised, and the DNS server IPs have been changed to spammy servers that will sometimes open the site you want, and other times open an ad page.

This might be because Team-BHP allows http & httpS -- while most other sites force httpS. We'll be doing that soon.

SOLUTIONS:

1) Browse Team-BHP on httpS only (or better yet, use an extension like 'httpS everywhere') that should help.

2) Block cabalten - thanks to Siva Kumar D
If using chrome go to chrome://settings > Content Settings > Javascript Manage Exceptions > Add [*.]cobalten.com and select Block
3) Check that your DNS server IPs on your modem & router are legitimate (Google DNS or OpenDNS are best)

4) Get another ISP. There are many good options these days.

Thanks a lot for your response Rehaan. Will definitely try java script exception technique (on Windows Laptop and Mac) and get back here. However i haven't seen option for java settings or chrome extensions (for Https everywhere) on iOS (Since Chrome for iOS is still Safari at heart, I know i am oversimplifying a bit however would be happy to be enlightened on the matter if i am wrong).
As for DNS - Already using Google DNS servers (BSNL wifi forces you to use or else several sites do not open), Open DNS resulted in slower speeds while browsing however Google DNS does comes with its costs (Read Privacy).
As for changing ISP, do not have choice in the matter because at office its corporate decision (Plus i do not use it much anyways) and for home since i am living in a flat, wiring (Fiber Routing) is pre-done by builder and at the moment BSNL is the only ISP.

One more reason to avoid clicking links:

Quote:

WhatsApp recently confirmed that a spyware was being used by Israel based company NSO Group to spy on government officials, journalists, activists, lawyers, and various countries globally, including India. The confirmation about the use of Pegasus spyware came earlier this week after WhatsApp sued NSO Group, which had long been suspected in the WhatsApp cyberattack that happened earlier this year. Reportedly WhatsApp has warned several Indian users who are expected to be targets of the illegal snooping spyware.
https://www.news18.com/amp/news/tech...l-2369893.html


All times are GMT +5.5. The time now is 19:21.