Sunbeltblog comments

Gravatar Nasty, nasty stuff. And I love how the Yapbrowser site takes every chance to redirect you to the UA content should you mistype any of their urls.

Same smelly stuff, different day...


Gravatar That's some nasty stuff! What's the name of the Russian website it's translated from?


Gravatar Hello

I am representic of web site yapbrowser.
We are a leading development company in internet
Some days ago we got information that anybody told about us really missunderstanding things.
look at this article: http://www.vitalsecurity.org/200...o- andchild.html

We and all our staff wanted to say that this is really big mistake, becouse we can show you all garanty that
this article do not have any confirmations. The problems had been connected with our hosting comapny provider.
This guys try to sell their products in traffic of our project and not inform us about.
We will try to do all possible that this guys will responsible for this act.

And we are really sorry to all our users and partners which work we hope we will continue our business as ever.
All our sites will be work in new hosting in some days.

The best
Enigma Global Inc.
Director


Gravatar Note that the icons in the browser are stolen from Firefox.


Gravatar I noticed that you kept yapsearch(dot)com from being a clickable link at the bottom of the page, but higher up - in the "how you can screw over the computer user" you left a clickable link to that very site.


Gravatar "We are a leading development company in internet", yes, and I'm the Pope.

But hey, let me use a language that you maybe would understand better: "the your program is an bad softwares programs which is teh spywares and we do not want these shit on the ours computers".


Gravatar Thanks for responding. My questions:

1) Why is Yapbrowser avilable to download again, when the application doesn't actually work? (Any search made results in a page cannot be found message)?

2) On your site apology, you say:

Some links of our browser direct on 404 page on which our hosting provider promoted an illegal content.

Presumably you are referring to the fact that any "mis-types" of your domains redirected to the porn (which I touch on later).

This is informative, but does not explain what was happening inside the Yapsearch application. None of the links in the Yapsearch page worked. Neither did typing anything into the search bar inside the Yapsearch page (for example, the search for the word "Spam" resulted in...a blank page).

No, what's interesting here is this extract from the logs, when Andrew tries to reach Microsoft:

+++GET 60+++
GET /search?q=http://www.microsoft.com HTTP/1.0
Connection: keep-alive
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, */*
Accept-Language: en-us
Cookie: PHPSESSID=pkt2t4q58jl5q9rdvuto04sp24
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Host: yapsearch.com

+++RESP 60+++
HTTP/1.1 302 Found
Date: Sun, 16 Apr 2006 19:54:18 GMT
Server: Apache/2.0.54 (Fedora)
Location: [redacted]
Content-Length: 307
Connection: close
Content-Type: text/html; charset=iso-8859-1
+++CLOSE 60+++

What appears to be a 302 redirect. A common hijack employed by (sometimes rogue) search engines, where valid URLs are shunted out of the way by dubious pages. On many occasions, it's an error - however, in this case it looks like someone went a bit further and crafted some kind of built-in 302 redirect into the Yapbrowser application. And nobody noticed?

3) All you had to do to see the porn was hit the green "go" button. Are you telling me that from the point where you tested the application, up until launch, and then while people were downloading Yapbrowser, nobody in your company noticed this? It wasn't difficult to spot, after all.

4) As mentioned earlier, when attempting to get the download for Yapbrowser to work on the adult page, typing in numerous attempts at what I thought would be the download link resulted in me being redirected to the X-Treme Lolitas page. So, not only had someone managed to hijack your application without anybody noticing, they also managed to somehow have every one of your mis-typed urls also direct to the pornography. Again - how did nobody notice this?

The Yapbrowser site was registered in December, 2005. It's now April. That's an awful long time to miss something so serious. No end-users complained about this, either?

5) Why is the name "John Malkovich" down as the contact for Yapcash? Seems awfully funny that Petr Rian is down for all the other domains, but the one that sorts out the money-making deals has the world's craziest actor as the domain contact.

6) On the subject of being John Malkovich, (and with a big chunk of text lifted from Andrew Clover), the same details are used for a group of sites at Eltel, a Russian ISP, including one site that redirects the user to browser exploits at paradise-dialer.com, which load trojans, spyware and dialers. Paradise-dialer's whois places it as part of the CWS group known as Dimpy, aka BigBuks. Since the BigBuks whois is also given by mix-click, referred to by the yapbrowser/yapsearch whois, and the aforementioned servers at Pilosoft and Eltel (as well as the paradise-dialer server also at Pilosoft just a few IP addresses away) run many other sites that link back to browser exploits and child porn promotions run by BigBuks, it seems reasonable to assume that they are the same group of people.

So, is this you or not? And if not, how come the contact details are the same?


Gravatar To Enigma Global Inc., Director:

Are you one of the people discussing yapbrowser and planning to use nasty spyware in this document?

http://www.sunbelt-software.com/ ...sdfasdw2oiu.pdf


Gravatar Oh snap, someone let slip the dogs of war!


Gravatar TNT wins for best comment.


Gravatar hands down


Gravatar Huh, thanks. :D

PS - sorry, I noticed "we are a leading development company in internet", but somehow I missed the part where he calls himself and signs himself as "The best"... talk about modesty.


Gravatar "Oh snap, someone let slip the dogs of war!"

...I predict a riot...


Gravatar http://crutop.nu/Vbulletin/showt...ead.php? t=63868


Gravatar Interesting link...


Gravatar Yes.. if you speak russian! Great >


Gravatar Use the Babelfish translator. Not brilliant but you'll get the general idea...


Gravatar therejust fighting at each other :P


Gravatar this is my story with all publications
I was convicted for child porn
http://brian.carnell.com/ discuss...ead$msgnum=8064


Gravatar My full story
http://www.inquisition21.com/ art...page_num~3.html


Gravatar I can read russian


Name:

Email:

URL:

Comment:  ? 

 

Commenting by HaloScan