info trojans inserting iframes which can't be removed

Hello

Perhaps this is usefull for someone.

http://www.qualitycodes.com/tutorial.php?articleid=29


Welcome to the forums, webmiep. :slight_smile:

Thanks for posting the information.


Hoi webmiep,

Yes these infections are due to webadmins and website hosters that have not been fully upgrading and patching their software.
The iframes can infect users by visiting the infected websites. You should not get infected as the infecting script is being blocked by using the NoScript extension in browsers like Firefox or Flock, especially as you set the extension not to run iFrames.
If you decide to run so, there is also the shield detection in your avast av solution that makes you will disconnect there not to get infected. So in using these methods you are twice protected,

groetjes,

polonus

Hi polonus, How do I set my firefox NoScript extension not to run iFrames.

Open the NoScript Options, Plugins tab ns check the Forbid iFrame option.

Hi DavidR, thanks for showing me how to make my firefox extensions not to run Iframes, I was kind of surprised that firefox did not have that setting by default, and I log to some sports websites that have these ad’s on the side of the page to show it’s blocked and a Iframe tag show’s the coding.

But I dont think the ad is malicious as avast didnt pick it up.

The NoScript iframe block, just stops all iframes from loading. it isn’t based on malicious content or any thing else, just the iframe. (this is what the webshield is for ;))

That means even some of the annoying ads are removed - not a bad thing :stuck_out_tongue:

Although there are other extensions you could use to filter this sort of thing as well.

The iframe is a legitimate HTML object, used for delivering dynamic content, etc. and this is often used for delivery of ads. However, this is a powerful function which is hijacked more and more for malicious purposes, e.g. to run a script in that iframe from another site.

So there really would be no reason for firefox or any other browser to block a legitimate HTML object/function. You are using NoScript to enhance firefox’s security by not running scripts (again a legit HTML function), unfortunately even NoScript doesn’t stop iframes (which may be trying to run scripts) by default. That is why beefing up the default actions of NoScript is suggested.

So as has been said it isn’t the intention only to block malicious scripts, etc. as NoScript doesn’t differentiate, just block all script/functions that you or the default settings enable/disable.