Need help with an investigation - Browser Instance Hijacking
1 26 Oct 2018 04:16 by u/LiberalTalkingPoints
If you guys have the ability to stack trace rogue instances of your browser, this is a fun target.
For years I have been watching my TV shows and movies via streaming. BitTorrent offers higher quality etc, but torrenting opens you up to DMCA and other violations. Quality isn't so good, but if I do some major browser-fu then it is not an issue.
So normally I watch my teevee through my Linux workstations. I monitor processes and kill any that don't service me. With some adblockers and other tricks, I can keep the popups under control.
But I have a Windows Gaming machine, and I like to watch Teevee here too. I don't trust it enough to ever use it for email or banking or even ordering pizza, but it's Windows 7 and the best thing for gaming. [Yes yes, Steam on Linux is DOPE but lets be real]
So when you go to this site; you can expect to get popups that will completely dominate your PC.
The best is the artificial voice that warns you of a virus and hooks into Win7 so hard it locks foreground through unrelenting dialogue building on top of faux Windows security prompts which are better than your average bear. [Eg. stripping normal dialogue navigation and rendering faux Windows prompts which are indistinguishable through the interface to me]
Now I have gotten into looking through processes on Win7 and the last two days I binge watched Oceans 11-13. I have found some completely interface-transparent processes which even hide their bandwidth usage expertly.
They have no special permissions so I just launch MMC or Task Manager and kill them, continue to watch my movie.
But I'm curious, in 2018, what are those processes doing?
Back in my day, they would have been processing credit card transactions for off the radar groups. Forwarding encrypted distributed ledger chats, or TBH most of them would be sending porn e-mails.
What are they doing today? I don't have the tools or the time to tell.
The site currently is lev ... idia ... ch
and I usually go to wootly as the video server. Each of lev ... idia ... ch hub-servers have their own advertising. This is how they have stayed alive for ~15 years through various names.
I have other interests, such as how they might be using subliminal manipulation, but Occams Razor allows us to look at the most likely motivational locus of this system. What are those processes doing?
1 comment
0 u/Kayleb 26 Oct 2018 08:59
Have you tried process explorer ? should give you all the details including stack traces and registers