LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Puppy
User Name
Password
Puppy This forum is for the discussion of Puppy Linux.

Notices


Reply
  Search this Thread
Old 06-28-2015, 12:41 PM   #1
Fixit7
Senior Member
 
Registered: Mar 2014
Location: El Lago, Texas
Distribution: Ubuntu_Mate 16.04
Posts: 1,374

Rep: Reputation: 169Reputation: 169
Browser hijacker


This site took over my 2 browsers. It is set up as my home page and my bookmarks go to it.

How do I get rid of iit.

Code:
https://wifilogin.xfinity.com
 
Old 06-28-2015, 05:48 PM   #2
John VV
LQ Muse
 
Registered: Aug 2005
Location: A2 area Mi.
Posts: 17,627

Rep: Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651
are you trying to login to your comcast xfinity box ?
for running linux OS with comcast you NEED!!!!! do disable what comcast calls there " ?? firewall ?? "
( for YOUR protection they will "protect you from BAD icky programs" )

it ONLY blocks GOOD programs
tor
bittorrent
ClamAV
ftp
ssh
svn
 
Old 06-28-2015, 06:26 PM   #3
Fixit7
Senior Member
 
Registered: Mar 2014
Location: El Lago, Texas
Distribution: Ubuntu_Mate 16.04
Posts: 1,374

Original Poster
Rep: Reputation: 169Reputation: 169
Do not have an xfinity box.

But Verizon is my ISP.

I put the site in my hosts file.
 
Old 06-28-2015, 06:34 PM   #4
John VV
LQ Muse
 
Registered: Aug 2005
Location: A2 area Mi.
Posts: 17,627

Rep: Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651
then are you trying to loggin or use to your Neighbors comcast wi-fi

the Comcast xfinity box is set to DEFAULT to a public wi-fi
there are two wi-fi channels used
a public and a private
 
Old 06-28-2015, 07:31 PM   #5
Fixit7
Senior Member
 
Registered: Mar 2014
Location: El Lago, Texas
Distribution: Ubuntu_Mate 16.04
Posts: 1,374

Original Poster
Rep: Reputation: 169Reputation: 169
I do not use wifi.

I have a ethernet cable from modem to my laptop.
 
Old 06-28-2015, 08:21 PM   #6
astrogeek
Moderator
 
Registered: Oct 2008
Distribution: Slackware [64]-X.{0|1|2|37|-current} ::12<=X<=15, FreeBSD_12{.0|.1}
Posts: 6,269
Blog Entries: 24

Rep: Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196
Quote:
Originally Posted by Fixit7 View Post
I put the site in my hosts file.
Could you be more explicit about this - what exactly did you put in your hosts file (paste here) and for what purpose?

Last edited by astrogeek; 06-28-2015 at 08:23 PM.
 
Old 06-28-2015, 08:32 PM   #7
Fixit7
Senior Member
 
Registered: Mar 2014
Location: El Lago, Texas
Distribution: Ubuntu_Mate 16.04
Posts: 1,374

Original Poster
Rep: Reputation: 169Reputation: 169
This blocks the offending site.

Quote:
127.0.0.1 localhost puppypc24566
192.168.1.1 pc2
192.168.1.2 pc3
192.168.1.3 pc4
0.0.0.0 wifilogin.xfinity.com
 
Old 06-28-2015, 08:45 PM   #8
astrogeek
Moderator
 
Registered: Oct 2008
Distribution: Slackware [64]-X.{0|1|2|37|-current} ::12<=X<=15, FreeBSD_12{.0|.1}
Posts: 6,269
Blog Entries: 24

Rep: Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196
I thought that was what you meant, but wanted to be sure, thanks.

So if that site is somehow now set to be your browsers' home page, why is less important, simply change the home page in your browsers...?

... afterthoughts ...

Will the homepage reset to something else?

You also say all your bookmarks go there - what about non-bookmarked URLs, can you reach other sites at all?

Last edited by astrogeek; 06-28-2015 at 09:06 PM.
 
Old 06-28-2015, 09:11 PM   #9
Fixit7
Senior Member
 
Registered: Mar 2014
Location: El Lago, Texas
Distribution: Ubuntu_Mate 16.04
Posts: 1,374

Original Poster
Rep: Reputation: 169Reputation: 169
Though my homepage was altavista.com, it went to the xfinity site in both Seamonkey and Firefox.

I had to uninstall both browsers as well as delete the .mozilla directory.

This also happened a couple of months ago.
 
Old 06-28-2015, 09:17 PM   #10
astrogeek
Moderator
 
Registered: Oct 2008
Distribution: Slackware [64]-X.{0|1|2|37|-current} ::12<=X<=15, FreeBSD_12{.0|.1}
Posts: 6,269
Blog Entries: 24

Rep: Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196
That sounds like browser malware or plugin hi-jacker then.

You might try to correlate it with some plugin or some particular site, probably not the site you are being directed to.

But it does not sound like a Linux or network config problem actually.

Is there more than one user account on that computer? If so, does this happen for all users or just one?
 
Old 06-28-2015, 09:19 PM   #11
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,349
Blog Entries: 28

Rep: Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145
I don't know what's going on, but this might help.

A dig gave me this. Apparently it's a legit address.

Code:
$ dig wifilogin.xfinity.com

(snip)

; <<>> DiG 9.10.2 <<>> wifilogin.xfinity.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 18122
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;wifilogin.xfinity.com.         IN      A

;; ANSWER SECTION:
wifilogin.xfinity.com.  6135    IN      CNAME   xfwweb.g.comcast.net.
xfwweb.g.comcast.net.   25      IN      A       69.252.205.105

;; Query time: 24 msec
;; SERVER: 8.8.8.8#53(8.8.8.8)
;; WHEN: Sun Jun 28 22:09:24 EDT 2015
;; MSG SIZE  rcvd: 100
Trying to go to wifilogin.xfinity.com in a private window on Firefox produced this. There was no attempt to hijack my browser or set the homepage. Note that Comcast does not have a presence in my part of the world. Here it's either Cox or Verizon and, in some parts, Charter.

Code:
There was a problem connecting to the XFINITY WiFi Network.

    If the problem persists, please contact a customer service representative at 1-800-XFINITY (1-800-934-6489).
    Comcast Business customers please call 1-800-391-3000.
Similarly, a traceroute produces an output that looks quite legit. Here's the bit after it left my router.

Code:
 10.5.48.1 (10.5.48.1)  11.652 ms  12.584 ms  12.584 ms
 3  68.10.8.213 (68.10.8.213)  12.988 ms  12.988 ms  12.993 ms
 4  172.22.51.96 (172.22.51.96)  90.859 ms  91.976 ms  91.965 ms
 5  ashbbprj02-ae3.0.rd.as.cox.net (68.1.4.246)  22.875 ms  21.830 ms  22.862 ms
 6  * te-1-0-0-5-cr01.seattle.wa.ibone.comcast.net (75.149.228.17)  15.674 ms  14.761 ms
 7  he-0-3-0-1-cr02.ashburn.va.ibone.comcast.net (68.86.82.209)  19.249 ms he-0-3-0-2-cr02.ashburn.va.ibone.comcast.net (68.86.82.221)  19.647 ms he-0-3-0-9-cr02.ashburn.va.ibone.comcast.net (68.86.88.109)  20.600 ms
 8  be-10114-cr02.56marietta.ga.ibone.comcast.net (68.86.85.10)  33.241 ms  31.928 ms  33.235 ms
 9  be-11314-cr01.dallas.tx.ibone.comcast.net (68.86.85.21)  53.199 ms  52.184 ms  53.184 ms
10  be-11317-cr02.denver.co.ibone.comcast.net (68.86.84.230)  63.959 ms  60.456 ms  61.472 ms
11  be-7922-ar02-d.potomac.co.ndcwest.comcast.net (68.86.95.10)  67.960 ms  66.751 ms  67.957 ms
12  te-6-1-ur02-d.potomac.co.ndcwest.comcast.net (68.86.206.18)  65.657 ms  65.634 ms  65.632 ms
13  xfwweb-po-vip.sys.comcast.net (69.241.73.141)  65.620 ms  65.184 ms  65.186 ms

Last edited by frankbell; 06-28-2015 at 09:22 PM.
 
Old 06-28-2015, 09:24 PM   #12
astrogeek
Moderator
 
Registered: Oct 2008
Distribution: Slackware [64]-X.{0|1|2|37|-current} ::12<=X<=15, FreeBSD_12{.0|.1}
Posts: 6,269
Blog Entries: 24

Rep: Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196
Quote:
Originally Posted by frankbell View Post
I don't know what's going on, but this might help.

A dig gave me this. Apparently it's a legit address.
Yes, I think the URL itself is legit, but it is probably NOT the hijacker - it is just being used as a dead-end target by the hijacker.
 
Old 06-28-2015, 09:31 PM   #13
astrogeek
Moderator
 
Registered: Oct 2008
Distribution: Slackware [64]-X.{0|1|2|37|-current} ::12<=X<=15, FreeBSD_12{.0|.1}
Posts: 6,269
Blog Entries: 24

Rep: Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196Reputation: 4196
A little googling turned up this link.

The text-speak gibberish in some comments was too much for me to slog through, but I surmize that it is a browser hijacker maybe called "Hijack this" that is installed by many games, malware, browser plugins and generally bundled with third party crapware, mostly for M$ machines but other OSs as well.

What plugins do you have installed? Have you installed software from places other than the distro repos?

Last edited by astrogeek; 06-28-2015 at 09:51 PM.
 
Old 06-28-2015, 09:41 PM   #14
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,349
Blog Entries: 28

Rep: Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145
Quote:
Yes, I think the URL itself is legit, but it is probably NOT the hijacker - it is just being used as a dead-end target by the hijacker.
Astrogeek, could you expand on this? "Dead-end target" is a term I haven't run into before. A web search turns up mostly stuff about the Target stores' website being hacked.
 
Old 06-28-2015, 09:46 PM   #15
Fixit7
Senior Member
 
Registered: Mar 2014
Location: El Lago, Texas
Distribution: Ubuntu_Mate 16.04
Posts: 1,374

Original Poster
Rep: Reputation: 169Reputation: 169
I fixed the problem and am happy with the results.

Thanks for all the investigating.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Can't install chromium-browser.tcz from App Browser in Tinycore-5.3-19 M.Tenenbaum Linux - Newbie 1 06-05-2014 11:18 AM
LXer: PeerJS enables WebRTC browser-to-browser banter LXer Syndicated Linux News 0 02-16-2013 03:20 AM
LXer: Proprietary Browser vs. Open Source Browser | Market Share Analysis LXer Syndicated Linux News 0 11-01-2012 07:21 PM
[SOLVED] Light Weight Web Browser/File Browser CincinnatiKid Linux From Scratch 16 06-27-2012 01:37 PM
LXer: Chromium Browser talks with Telepathy (IM/Chat Library) to provide an in-browser IM client - LXer Syndicated Linux News 0 10-04-2011 10:00 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Puppy

All times are GMT -5. The time now is 12:16 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration