Kill Drive-By Malware-Installing Pages - Printable Version +- The Un-Official Proxomitron Forum (https://www.prxbx.com/forums) +-- Forum: Proxomitron Filters (/forumdisplay.php?fid=38) +--- Forum: Privacy/Security/Spam (/forumdisplay.php?fid=10) +--- Thread: Kill Drive-By Malware-Installing Pages (/showthread.php?tid=1081) |
Kill Drive-By Malware-Installing Pages - Kye-U - Aug. 28, 2008 07:51 PM In an attempt to prevent malicious pages (such as Antivirus XP 2008/9) from going through with their fake scanning progress bar, I've decided to write a pretty simple filter to kill all SCRIPT, IFRAME, OBJECT, EMBED, APPLET tags and ON____/HREF attributes, with the ability to bypass the filter (after having to click on "OK" on a genuine confirm message). For those wanting to truly test this filter out, you can test it on an ACTUAL Antivirus XP 2008 site here (use caution, if you somehow have the following filter disabled or Proxomitron disabled, and you see the prompt to start scanning, go to the Task Manager and terminate the IEXPLORER or FIREFOX process): http://###avxp-2008.###net/sysscan/ (remove the two sets of ###) Code: [Patterns] Take a look at Malware Database's list of Malicious Domains for August 2008: http://malwaredatabase.net/blog/index.php/2008/08/21/malicious-domains-of-the-month/ See anything that's RegEx-able? (aka, see any patterns?) RE: Kill Drive-By Malware-Installing Pages - Kye-U - Aug. 29, 2008 02:43 PM For additional security, I'd recommend importing the two Header filters in this topic: http://prxbx.com/forums/showthread.php?tid=1029 RE: Kill Drive-By Malware-Installing Pages - besafe - Sep. 05, 2008 12:00 AM Thanks for the filters. RE: Kill Drive-By Malware-Installing Pages - Oddysey - Sep. 11, 2008 03:28 PM Fearless Leader; Instead of Kill Drive-By Malware-Installing Pages, shouldn't that be Kill Surf-By Malware-Installing Pages? Oddysey |