Malwareads that fuck the CSS fix

Sup Forums.org##script:inject(abort-current-inline-script.js, String.fromCharCode)

Here use this alone, remove the other quickfixes.
Now everyone fuck off.

Other urls found in this thread:

github.com/uBlockOrigin/uAssets/commit/43eb4648ba1126a58c933177da00154d469536dd
youtube.com/watch?v=kfHwMbIkNbg
urlscan.io/domain/piguiqproxy.com
github.com/uBlockOrigin/uAssets/blob/0f848c5a50965ab39b026e8cceffcc6a97465777/filters/resources.txt#L1852
twitter.com/SFWRedditImages

how do I use that?

...

Bump

thanks user

It works, but how?

thanks :)

this was literally posted in the first ~50 replies in the very first thread started about this earlier this morning. Just no one paid attention.

This was the fix created by gorhill, what's the point of spamming this? Just fucking update ublock.

A script:contains version was posted but that only works in old non webextension firefox and palemoon.

>Just fucking update ublock.
Update WHICH filter exactly? For now, this is easier for most users.

There is absolutely no reason to be using anything other than uBlock Origin at this point.

github.com/uBlockOrigin/uAssets/commit/43eb4648ba1126a58c933177da00154d469536dd

It's the uBlock filters specifically or you can just purge and update them all.

>Just fucking update ublock.
i updated ublock and it didn't fix anything

Clover user here. What css changes?

So what does the line actually do? How does it specifically bypass the CSS fuckups?

>If ad doesnt load fuck everything
>If it does do nothing but run the obfuscated load(Javascript).

Amazing how one little line of code saved everything.
Too bad legacy Captchas don't work anymore.

What do you mean? They still work...

Sup Forumsack here, can someone please tell me what's going on? What does the code do? How do I get rid of it and how do I avoid getting it?

I've been hearing some FUD about the new AIDS injecting a cryptosheckel miner in your browser's JS. Buttcoin et al have value at all because they can be used as quickly verifiable one-time access codes. Such codes could be used to partially or completely replace replace recaptcha if Sup Forums implemented them. If yonchon had it's own flavor of this, people could potentially use their gayman rigs, phones, whatever to generate them and make as many captcha-less posts as their hardware allows, or turn them over for points towards a Sup Forums Pass, or any kind of incentive scheme at all without involving some third party. That could get Sup Forums closer to being the single most popular website to use no google services, which kick ass.

Basically the whole site goes text-only.

Sup Forums x user here. Not sure if it worked or not since it hides adds anyways.

i'm getting a bunch of connection error when i try using the legacy captcha after this. don't get it with the picture capts.

>github.com/uBlockOrigin/uAssets/commit/43eb4648ba1126a58c933177da00154d469536dd

That didn't fix anything to me I had to manually block every single new address in my host file
The updated origin filters contain the last change but it didn't fix anything here

Hiro was hired by a company called MGID to put ads in Sup Forums.
Their anti-adblock tool contains a obfuscated code and a payload.

The obfuscated code checks if the ad that drops the payload is executed correctly, if it doesnt it kills CSS of the site.
If it does it does nothing but the payload executes which scans and tracks you, takes some stuff from your PC such as PC name and ID, among other retarded stuff.

There is no miner, that wasonly shitposting.
Also its retarded to mine BTC from a browser, if anything it would be XMR(Monero).

Gook Moot is sending your information directly too Russia when you access Sup Forums, though hidden obfuscated links.

Also what is funny is that most ads were just Russian dating and impregnation propaganda.
This is MGID, youtube.com/watch?v=kfHwMbIkNbg
Now go back and shitpost in Sup Forums about it.

I didn't say there was one. But actually having one that generated Sup Forums playmoney that helped the site function better would be a neat feature.

Maybe I spoke too soon, fuck the little shits come and go on noscript and Ublock.
It seems like they're blocked though for now so maybe I'm safe? As long as they're blocked and the features work I guess I'm fine.

Turning ublock origin on kills 4chanx
What do?

Read.

>the payload executes which scans and tracks you, takes some stuff from your PC such as PC name and ID, among other retarded stuff.
How can I verify if this code has executed in a firefox based browser? Just messed up CSS?

It does every time the ad opens, it leaves no trace so all you have to do is block it.

So it's not served from Sup Forums.org or 4cdn.org? That's a relief.

thanks basedanon

Someone got an Adblock Plus version?

If not, I'll read through the documentation tomorrow. Too tired to focus on it at the moment.

do i get rid of the scripts user?

werks for me

This isn't working for me.

thanks user.

No, it comes from these sites.
It will be blocked by default once the ublock 3rd party filter is updated, for some it is for others it isn't yet.

That is what the line is for, put it in ublock.

A photo would help.

Upgrade to uBlock Origin.

I got it to work by adding
*.mgid.com
After that line.

sup Sup Forums
urlscan.io/domain/piguiqproxy.com

Also, going to add that the entire website is running faster now after adding *.mgid.com

CSS is still broken on chromium using this, and the botnet domains still show up in umatrix

add *.mgid.com

Block the domains manually, and if you are using the other quickfixes stop using them.

What are the consequences of this?

>Im paranoid
An ad company other than google has some info about you such as PC User name and ID.
>Im not paranoid
No consequences at all.

God bless ya user.

Is there any documentation on how ##script:inject or abort-current-inline-script.js work?

I swear half the advanced features in uBlock are completely undocumented and nobody gives a fuck.

This works, but removes my captcha, thus making it impossible to post.

works 4 me bud

Are you using 4chanX? uMatrix? noscript?

Brainlet here. Can you get avirus for adding random scripts to your filter list?

It is pretty much junk. Janky as it is to use, noscript does a better overall job.

Can noscript block inline scripts depending on their content?

Mine's working fine. What else do you think it could be?

i'm using adnauseam and it seems to work with that too

Got it, I'll burn everything electronic.

was it removed?

here i guess

github.com/uBlockOrigin/uAssets/blob/0f848c5a50965ab39b026e8cceffcc6a97465777/filters/resources.txt#L1852

Just uBlock origin.

Install 4chanX and use fix captcha option in settings also force captcha v1.

>github.com/uBlockOrigin/uAssets/commit/43eb4648ba1126a58c933177da00154d469536dd
Could you please clue me on how to use this?

It's already in uBlock Filters. Just force update it.

Is that Sup Forums Anti-cancer script that was going around earlier obsolete then?

>fucks 4chanx and disables the native extension
neato

Its what is posted in OP.

Does this effect people who use mobile apps?

I am on Mimi Reader right now. I cant imagine it'd be effecting this, right?

ugh, i guess it worked. Thanks user. hopefully i'm not in a big ruse

Seriously user? where the fuck do you think the virus is going to come from? The code doesn't have any url other than Sup Forums.org

Open uBlock Origin logs and refresh this tab if you wanna be sure it doesnt load.

Already found that. I think I understand what it does, but I'm trying to use it on another page and it simply does not work (while it works fine on Sup Forums)

Then you have shit like this in there that makes no sense
var target = '{{1}}';
if ( target === '' || target === '{{1}}' ) { return; }
It sets target to '{{1}}', then returns if target is set to '{{1}}'? What fucking sense does this make?

I did say i was a brainlet... but is it possible though?

>page suddenly starts rendering properly
I didn't do anything... normal right?

You can get malware from running a script (See fucking javascript) But you cant get malware from blocking scripts.

Sup Forums x just updated too to include a fix, still not compatible with the new ub0 rule tho.

don't bother
just update ublock filters (3rd party filters->purge caches->update now)
same thing, no need to add superfluous custom filter.

Can you read one line? What exactly do you think a virus is?

Yeah, no ads.

It got implemented into uBlock Origin, your filters updated.

*affecting
Dumbass phoneposter

I may misspell words

But at least i dont have incurable ransom AIDS

Ok, so I updated to the latest uBO (1.14.23b1), purged all filters, updated filters, refreshed this page, I haven't seen the troublesome ads recently (ever) but when I look at what's being connected through uBO there's obviously still those 3 domains and all the subdomains so, is there some way to prevent those troublesome ones from connecting or showing up at all and not have detrimental effects on the page layout and display?

I mucked with removing them earlier and of course the CSS got itself fucked so I reversed everything.

that worked, thanks

Just block them?
Enable advanced settings, open the menu and click the red button for the 3 of them.

This should be stickied.

wat

any chance hiro knew about the css-script fuckery being used be these sites? why would he do that, he knew people would find out.

Am I doing it right?

I already blocked the domains so they dont show.

>googleapis.com
m8....

the only way you could you could get a virus from a filter is if there was a flaw within your ad blocker's filtering allowing someone to put a payload in the filter text itself and then distributing it as a fix to something, but even if that was possible, you would immediately see that reflected in the filter, probably with a bunch of seemingly random character that don't make sense

Im testing stuff with chrome so i could care less.

look at all this shit

Did you add the code line in the OP?

>i could care less

yes

what the fuck
also you are allowing piguiq?

When I select the red option for uBO for those 3, they still show because the subdomains start pulling. If I then go and block every fucking subdomain they STILL show.

I suppose this is just being more complicated than it really is, and when I see people say "I just blocked it" then I'm going to assume they're blocking things on a router level or somewhere before the browser so that shit never gets to uBO in the first place, but since it's getting to the browser and uBO for me then it's being listed as a domain pulled.

have you actually put the domains in myfilters?