uBlock-Safari icon indicating copy to clipboard operation
uBlock-Safari copied to clipboard

embedded coinhive miner on danielcolomb.com not being blocked

Open tweitzel opened this issue 6 years ago • 3 comments

Filter issues MUST NOT be reported here. Read first: https://github.com/gorhill/uBlock/blob/master/CONTRIBUTING.md

Describe the issue

The charming fellow who runs www.danielcolomb.com has either been hacked terribly to the point where someone can inject the coinhive miner straight into his wordpress template, or he has decided to host the coinhive miner himself. Either way, it is not being blocked by ublock origin for safari, but is being blocked in the chrome version.

One or more specific URLs where the issue occurs

http://www.danielcolomb.com

Screenshot in which the issue can be seen

Not a visual issue, but this snippet stuck at the top of the html seems to execute the mining script.

Steps for anyone to reproduce the issue

Take the attached html file, put it anywhere, open it in safari with ublock origin running, view the debugger and the system load.

Your settings

[If you fail to provide this info, I will mark the issue as invalid. Lists all settings which differs from default settings]

  • MacOS version: 10.12.6
  • Safari version: 11.0.3
  • uBlock Origin version: 1.15.4
Your filter lists

uBlock filters​​​​​4,168 used out of 4,202​​​​ uBlock filters – Badware risks​​​​​8 used out of 8​​​​ uBlock filters – Privacy​​​​​62 used out of 65​​​​ uBlock filters – Resource abuse​​​​​206 used out of 208​​​​ uBlock filters – Unbreak​​​​​296 used out of 300​​​​ EasyList​​​​​80,219 used out of 80,449​​​​ EasyPrivacy​​​​​14,203 used out of 14,359​​​​ Malware Domain List​​​​​1,130 used out of 1,146​​​​ Malware domains​​​​​16,668 used out of 16,668​​​​

Your custom filters (if any)

www.metalinjection.net##.cEMfcKtj-1-

coinhive.html.zip

tweitzel avatar Feb 25 '18 22:02 tweitzel

This seemed like a filter issue

ruchernchong avatar Feb 26 '18 01:02 ruchernchong

With the same filter settings, it is blocked in chrome's ublock origin, but not this safari port.

tweitzel avatar Feb 26 '18 18:02 tweitzel

Yeah, I already tried to block the 1st party scripts and 3rd party elements, and the miner is still there. screen shot 2018-03-11 at 10 42 39 am screen shot 2018-03-11 at 10 42 50 am

MacOS: 10.12.3 Safari: 11.0.3 uBlock Origin: 1.15.4 Filter: All existed filters except the region filters. Also AAK filter.

volcbs avatar Mar 11 '18 03:03 volcbs