Unsolved
This post is more than 5 years old
5 Journeyman
•
5.8K Posts
•
17.3K Points
0
9645
October 7th, 2008 21:00
a2 anti-malware in action
Since upgrading to a2 AM 4.0, I've been receiving some interesting alerts.
I received one when I clicked on a link in Leo Notenboom's "Ask Leo" weekly newsletter (not the best security newsletter out there, but one which I still read. Perhaps no more!).
The alert said:
"a-squared Anti-Malware has detected a connection attempt to the suspicious host:
kona.kontera.com
The connection has been blocked automatically."
So I checked the website out at WOT, and sure enough, it's a baddie:
http://www.mywot.com/en/scorecard/kona.kontera.com
I notified Leo, and will be interested in his response.
No Events found!


melboy
336 Posts
0
October 7th, 2008 22:00
Interesting stuff Joe!
I scanned Ask leo 10 mins ago with Dr.Web's online URL scanner ( thanks Red Dawn! ) and it came up with numerous scripts attributed to google ad's etc and a Javascript file (.js 40kb) for kona.kontera.com. Just scanned again a couple of minutes ago and there is a couple of just Ask.leo scripts, the others are gone!
joe53
5 Journeyman
•
5.8K Posts
•
17.3K Points
0
October 8th, 2008 00:00
Thanks for the confirmation, melboy.
I'm not sure what to make of it, since "Ask Leo's" website is not flagged by WOT. I just visited that link with a2 AM disabled, and do not appear to have contracted anything. Hovered over all the links there, and none pointed to kona.kontera.com.
joe53
5 Journeyman
•
5.8K Posts
•
17.3K Points
0
October 8th, 2008 02:00
Hmmm, on second thought:
When I do a View Source on that "Ask Leo" link, I do see this buried in the html:
"... kona.kontera.com/javascript/lib/KonaLibInline.js"
That is enough for me to nix Leo's letter!
melboy
336 Posts
0
October 8th, 2008 05:00
"When I do a View Source on that "Ask Leo" link, I do see this buried in the html:
"... kona.kontera.com/javascript/lib/KonaLibInline.js""
That's what Dr Web detected first time round, strange it doesn't find it now though??
dalem29
2 Intern
•
2.2K Posts
0
October 8th, 2008 11:00
melboy
336 Posts
0
October 8th, 2008 15:00
joe53
5 Journeyman
•
5.8K Posts
•
17.3K Points
0
October 8th, 2008 16:00
Dale:
I have a2 AM set for automatic updates, but don't recall anything other than the usual sig definition update today. The big update to 4.0 was 2 days ago, and as I recall it came in 2 big packets.
joe53
5 Journeyman
•
5.8K Posts
•
17.3K Points
0
October 8th, 2008 18:00
Leo said:
Put simply, mywot.com is wrong.
kona.kontera.com is an ad server, nothing more, nothing less.
You can disable it if you like:
http://ask-leo.com/how_do_i_turn_off_those_ads_that_look_like_links_on_your_site.html
--
Thanks for asking,
Leo Notenboom
-------------------------------------
Interesting.
WOT, a2 AM, MVPS HOSTS file, and Dr Web all blacklist kona.kontera.com, but Leo says it's just ads.
Leo's free newsletter is supported by advertising, and I don't believe anything on his site is malicious. Sometimes I feel a little guilty blocking the ads at free sites. But I get over it.
Dave Lyle
2 Intern
•
2K Posts
0
October 8th, 2008 19:00
melboy
336 Posts
0
October 8th, 2008 19:00
"kona.kontera.com is an ad server, nothing more, nothing less."
Its my understanding that theses ad servers can unwittingly serve malicious advertisements on legitimate sites from time to time. A lot of these use malicious Javascript to exploit vulnerable/insecure browsers to attempt to re-direct surfers to such as fake scan sites etc, leading ultimately to them becoming infected with the likes of xp anti-virus 2008.
Maybe a some point kona.kontera.com has served one (or more) of these ad's.
Sandi Hardmeier's Blog has some excellent info on this kind of topic.
http://msmvps.com/blogs/spywares*cks/archive/2008/08/28/1646045.aspx
(replace the * with a "u", because of the Smut Filter)
joe53
5 Journeyman
•
5.8K Posts
•
17.3K Points
0
October 8th, 2008 20:00
As I understand it, WOT uses several methods, which certainly include user ratings.
From one of the developers of WOT:
"How much can you trust reputations computed from anonymous testimonies? We get that question every now and then from our users. It's a good question. Sometimes people even suggest that we add to the add-on the number of testimonies that were used to compute the reputation, similarly to eBay . However, in an anonymous system like WOT, the number of testimonies alone doesn't really tell you all that much about the reliability of the reputation. Besides, we have something better for you.
As already discussed in a number of previous posts, not everyone has an equal say in WOT reputations. You must prove yourself before we take you seriously. This makes it more difficult to manipulate the system, and also allows us to more precisely compute exactly how much the reputation estimates can be trusted. In addition to reputation, our algorithms also calculate another value, the confidence in the reputation."
ref: http://www.mywot.com/en/blog/2006/12/20
In my own experience, WOT has proved reliable. I've tested known dodgy sites, and WOT's ratings are in agreement. Conversely, I've seen no reputable sites get a bad rating. I have abandoned Firetrust's SiteHound in favor of WOT. It is probably not perfect, but I think it useful. Just my 2 cents.
I would be interested to hear of anyone else's experiences, or opinions of WOT.
beversoll
2 Intern
•
301 Posts
0
October 9th, 2008 00:00
Hi Joe53,
Which browser(s) are you using WOT on? I have had bad luck with any toolbars/BHO prevention programs in IE7. On one pc I have Site Hound on FF2 and my other pc I have Site Advisor on FF3. Site Hound crashes my FF3 with Vista OS. I plan to put WOT on the FF3 PC to test it out, but would like to hear which browser(s) you are using it on.
Thanks again!
joe53
5 Journeyman
•
5.8K Posts
•
17.3K Points
0
October 9th, 2008 00:00
beversoll:
I use WOT with both IE7, and with Firefox 3. No problems for months now.
It was because of problems with SiteHound and Site Advisor that I switched. This is on an XP MCE 2005 system. YMMV.