We are currently on Day 3 of the malware ad issue. Hiro has tweeted, although its about something completely different...

We are currently on Day 3 of the malware ad issue. Hiro has tweeted, although its about something completely different. It is clear he is ignoring this issue and hoping we all just forget about it.

Other urls found in this thread:

gitlab.com/N3X15/argon-dissection/blob/master/payloads/argon/01-annotated.js
gitlab.com/N3X15/argon-dissection
gitlab.com/N3X15/argon-dissection#workarounds
desuarchive.org/desu/thread/2700/
archived.moe/qa/thread/786936/#789006
reverse.it/sample/b9a80ddbaf41d303b0ed9abb0f6aabf5f851dd39909aaead3cb3257474fd7dc4?environmentId=100
twitter.com/SFWRedditVideos

this is how that faggot makes his money
we were warned that this was the future of Sup Forums and we ignored it

What could we have done at the time? Right now however we need to find a way to force Hiro to give up control of the site. We need to create a PR nightmare for him

I've checked every box in uBlock, updated the filters and now the CSS breaks.
Also, DNS66 isn't filtering ads anymore on android.
What to do?

With things like this going on, why do so many people use Sup Forums instead of the infinite alternatives that are available? I would've thought that an open source image board, where anyone can create their own boards, where moderation is less strict, and where you don't have to fill out Google captchas with every single post, would be far more popular. Why isn't it?

>give up
Who the fuck is gonna take ownership?

Throw this in your filters: Sup Forums.org##:xpath(/html/head/script[6])

Just keep in mind that if the script tag moves it will break

>infinite alternatives

Like what? Show us the way.

Everything was working perfectly fine 3-4 days ago. Captchas weren't too big of a deal imo. I consider this a bigger deal though since Sup Forums now serves potentially malicious obfuscated javascript and tries to intentionally break the site for power users who want to block sketchy third parties from serving potential malware.

>Why isn't it?
Users' inertia. Without the whole community migrating together the switch is rather difficult. Also, nobody's moving from a well established service, regardless how shit it becomes as long as the alternatives are slightly different versions of the same service.

Thanks, but it doesn't seem to work.

So even with Ublock and custom filters I still cant saftely use Sup Forums at all? No posting on /vg/, Sup Forums, /cgl/, /m/ or /p/?

I'm still getting white pages even though I purged and updated ublock and added in that new script that prevents it from happening

Sell it to a corporation. Sell it to someone who will fire the mods and replace them and will not interfere with the site's culture.

Anywhere you could go would have a much smaller userbase with a good portion of those people being those who left earlier and are still bitter. From the outside looking in, every other imageboard looks the same as here, but with an even shittier, more insular community.

Careful what you wish for. It could be sold to the people who were interested in it during the election last year who wanted to axe almost everything but Sup Forums and use the whole site as their personal right-wing incubator/ meme factory.

You don't know that for a fact. Also apparently moot was very close to selling Sup Forums to some corporation before GamerGate and The Fappening happened. Hiro was not his first choice

Literally give it to notch, have him shut down Sup Forums that's it.

Notch backed out like a cuck cause SJW's started threatening him on Twitter.

Of course I have no insight into anything like that, but I wouldn't be surprised if somebody like Breitbart put in an offer if this place was up for sale.

User count. I tried for years to find another community that allowed anonymous posting and where actual discussion can happen. But discussion requires users and a userbase that isn't like modern Sup Forums (where if I don't agree with you you must be a kike shill nigger and I refuse to google before posting shit also I'm a foremost expert in this field I've never even heard of before - back in the days, people would ask for info in an aggressive manner, but drop out of lost conversations or google shit to fact-check and come back with good questions in an even more aggressive format). All in all, we can find quality communities of 5 people (if we're lucky), or garbage communities of 10% of Sup Forums's population (see: 8ch, Sup Forums). Aside from that, there's nothing beside non-anonymous shit communities with powertripping mods and post count epeen shit.

Breitbart would actually allow Sup Forums to be a bastion of free speech and would probably put in competent mods. I don't know if Steve Bannon would want to be associated though due to the history we got. That faggot Milo would be the best bet, but I doubt he has money to keep the site afloat

>implying they wouldn't use it to serve a political agenda

>Breitbart would actually allow Sup Forums to be a bastion of free speech and
True I can't see them bothering to censor anything, but at the same time, I don't know if they'd leave up all the anime and porn boards. Sup Forums is such an eclectic mix of everything I can't imagine any traditional corporation wanting the whole package.

The decoded strings seem kinda crazy with ad partners (I assume).

"marketgid", /* a[633] */
"marketgid.com", /* a[634] */
"tovarro.com", /* a[635] */
"dt00.net", /* a[636] */
"lentainform.com", /* a[637] */
"mgid.com", /* a[638] */
"steepto.com", /* a[639] */
"traffic-media.co", /* a[640] */
"traffic-media.co.uk", /* a[641] */
"adskeeper.co.uk", /* a[642] */
"novostionline.net", /* a[643] */
"trafmag", /* a[644] */
"trafmag.com", /* a[645] */
"admixer", /* a[646] */
"admixer.net", /* a[647] */
"privatbank.ua", /* a[648] */
"rt-rrr.ru", /* a[649] */
"gemius.pl", /* a[650] */
"tns-ua.com", /* a[651] */
"bemobile.ua", /* a[652] */
"recreativ", /* a[653] */
"recreativ.ru", /* a[654] */
"yottos", /* a[655] */
"yottos.com", /* a[656] */
"mixadvert", /* a[657] */
"mixadvert.com", /* a[658] */
"redtram.com", /* a[659] */
"mediainform", /* a[660] */
"mediainform.net", /* a[661] */
"teaser.ws", /* a[662] */
"adpartner", /* a[663] */
"adpartner.pro", /* a[664] */
"adriver", /* a[665] */
"adriver.ru", /* a[666] */
"createjs.com", /* a[667] */
"traffim", /* a[668] */
"traffim.com", /* a[669] */
"mixmarket", /* a[670] */
"mixmarket.biz", /* a[671] */
"gnezdo", /* a[672] */
"gnezdo.ru", /* a[673] */
"2xclick.ru", /* a[674] */
"adwise", /* a[675] */
"franecki.net", /* a[676] */
"worldssl.net", /* a[677] */
"acdnpro.com", /* a[678] */
"begun", /* a[679] */
"begun.ru", /* a[680] */
"price.ru", /* a[681] */
"rambler.ru", /* a[682] */
"azbne", /* a[683] */
"azbne.net", /* a[684] */
"etcodes", /* a[685] */

They probably would. I don't think they would give a shit.

Their comment section gets a mix of liberals shitposting in it that the mods don't bother to delete.

Guys?

Install F-Droid and use Clover?

And Hirogooki still remains silent. He is digging his own grave now

Why would he say something? The only thing that went wrong is the countermeasures getting spread around so fast.

Because he's only going to draw more and more attention as this drags on. This isn't going to go away

>shut down things I don't like
Very progressive.

Here is the link if anyone interested in the dissection.
gitlab.com/N3X15/argon-dissection/blob/master/payloads/argon/01-annotated.js

He's remained silent about shit in the past, and yet here we/he are/is. Don't pretend like this is going to be the straw breaking the camel's back.

As an aside, I've been keeping to mobile posting since this whole fiasco started, and I've noticed that the post reply popup has been broken for the entire duration. Is this a symptom of the same browser-breaking bullshit PC users are reporting, or something else?

>someone who will fire the mods and replace them
How about sell it to someone who will hire more mods?

If you shut down Sup Forums, they will just spill out onto other boards moreso than they already have.

Should I try coming back in a week to see if everything's fixed?

Bullshit. That's always the threat Sup Forums uses. If Sup Forums was deleted they'd leave without a central base.

Nah, being on Sup Forums is something that they will continue to do. They'd probably re-establish themselves on Sup Forums and scatter across the site.

I'd actually venture out a middle ground, where the first few months would be full of constant bullshit trolling in the major boards, but would then quickly die off once they migrated to another trash heap. It would be the same symptoms that allow them to hyperfocus on bullshit "news" for several month periods, before getting bored and hopping to the next made-up issue.

Any new news about the script? So its just anti ad blocker combined with invasive ads? No ransomware?

That's a lot more .ru sites than I anticipated

Already have F-Droid, I'll check clover out. Still, the problem remains for desktop browsing.

bumped because fuck Hiro

The company mentioned in that Discord image was founded by a Ukranian and financed by a Russian billionare

is there an updated pastebin on using ublock and whatnot?

i was going to call you nigger monkey, but you are right. i guess i am the nigger now. now i am scare. whatt i will do wen Sup Forums is kill? i have no friends.

>Should I trust gookmoot and his non-free js-botnet?
ofc. hiro did absolutely nothing wrong.

>the guys that hired Milo specifically to engineer something like gamergate
>and admitted to shitposting on Sup Forums in droves to drive it further into the arms of right-wing faggots
>wouldn't completely ruin the site

uh huh

How do tell if i've been infected?
I ran a scan with the newest malwarebytes and it found nothing

This CSS-breaking issue is fucking bullshit, I have to reload the page like 20 times for it to properly display.

Drama info.

>Sup Forums malware ADs, defacing the site when blocked
gitlab.com/N3X15/argon-dissection

>Workarounds
- clover, overchan, dashchan
- purge + update ublock filters
- gitlab.com/N3X15/argon-dissection#workarounds

>Sup Forums blocks archive IPs
desuarchive.org/desu/thread/2700/

>Seems it was planned anyway
archived.moe/qa/thread/786936/#789006

>Current state
Malicious ADs which load unknown/obfuscated payloads, fucking with CSS and images. No confirmed ransomware or bitcoin miners. Gorhill (ublock) added filter to prevent malware from loading. Hiro (Sup Forums owner) silent on topic. Paniced normies installing Gentoo. OP is a faggot as always.

Come on, be honest. Is ublock enough or not? Sup Forums is the only place where I talk to people ;_;

You should probably add that the blocking the archivers is apparently due to cloudflare, it can effect regular users too if their update frequency is set too high.

The only site images I've ever seen on Sup Forums are ones like this. Nothing has changed in the past 3 days for me, site looks the same as it has for years.
Do people not use add blockers? Or did this bypass them somehow.

It was bypassing it and screwing over site until filters got updated.

So even if I never saw an image, I still got shit on?

Is there a step by step guide on what di for brainlets? I'm using Firefox with ublock origin and umatrix. Do I need to change something?

I wish I knew too. One people say I did, others that I did not.

I dont see any signs of infection or unusual cpu activity, however.

Basically no. If the site looks shit, purge ublock filters and update them, that should do the job.

I can confirm this happened to me.

>gitlab
the slowest git site i had to deal with, why not bitbucket or any other shit?

Same feels. I wished there was a github clone without tracking, censorship and all that trash.
Currently hosting my projects on my own toaster server.

So if I see no ads and the site looks fine am I safe

>Day 3
It's Day 5. It started on Monday and it's friday over here already.

>infinite alternatives
I see what you did ther ;)

Pretty much for now, but nobody knows if they change their tactics and scripts. Keep filters up to date and hope that hiro removes the bullshit.

>malware ad issue
Has there been any actual evidence that the new scripts are in fact malware or do anything else beyond just interfering with CSS/images/other JS loading if they are blocked?

yes.

>is there any proof that its malware except these confirmed malicious practices?

>open source image board
Um, I've got some bad news for you...

Scripts being obfuscated is not evidence of them being malicious. This situation is bullshit, but don't try to make it out to be something it isn't and drive away people who may care with baseless conspiracy theories.

Scripts on a site making features on a site break when not allowed are not malware, even if those features worked previously. Otherwise all JS and website redesigns that have made old websites dependent on JS would be malware, and the word malware would become another meaningless buzzword.

not him, but reread that post.

Woops. Thanks.
Disregard
I suck cocks

holy shit, so by allowing the sites to run, it'll load ads from all those sites?

jesus chrst

If you’re really worried just get Adguard since it blocks stuff at the system level. Use the free trial.

I wonder who is behind this post.

Nice botnet

>baseless
reverse.it/sample/b9a80ddbaf41d303b0ed9abb0f6aabf5f851dd39909aaead3cb3257474fd7dc4?environmentId=100

The best botnet

source:

he literally just described eightchan

>I would've thought that an open source image board, where anyone can create their own boards, where moderation is less strict, and where you don't have to fill out Google captchas with every single post, would be far more popular. Why isn't it?

The system says it's spam if I write "eight" as a number wtf that's just low

>these scripts may hide something, yeah, and they break the 1st party host site, OK, but there's no reason to think they're hiding something malicious you tinfoils

>where moderation is less strict
Not quite, just more transparent.

8 mch isn't free software anymore since a long time senpai

8ch is garbage.
need something else

Looks for openIB in github.

Brainlet here, I have some questions.

Does this affect OSX, Linux, etc and if so is there anything different that should be done to protect browsers on those systems from this shit?
Is there an acceptable alternative to Clover for a non-jailbroken soyPhone to use as an internet condom in this instance?

Thoughts ob lainchan?

install gentoo

It's good.

Clover is safe, Windows/macOS/GNU+Linux eg. browsers are safe with uptodate ublock origin installed.

the cloudflare 503 "botcheck" broke my firefox despite any filters, opening an image direct link allowed the site to load again, resetting and starting ff from scratch allowed me to see css but auto update just gave connection errors.

switched back to chrome with the same rulesets in ublock and etc, and it works fine.

really activates my pistachios

Fuck off jewgle shill

clover gives me an error too desu

>switched to the botnet and everything seems botnet free
>really makes me think

...

really makes me think

This shit is caused by the new thingy right?
I've read that I should update my filters, but I don't really know the right procedure on my ipad.
Could somebody give me an advice how to fix it? I tweaked around with my limited adblockers, but I don't seem to be able to fix it.

>tfw have ublock with the Sup Forums recommended filters
>dont have umatrix
A-am I safe Sup Forums? The site is working fine, I'm using Iridium Browser.