• Login
    • Search
    • Categories
    • Recent
    • Tags
    • Users
    • Groups
    • Rules
    • Help

    Do more on the web, with a fast and secure browser!

    Download Opera browser with:

    • built-in ad blocker
    • battery saver
    • free VPN
    Download Opera

    Opera Automatic Webpage Redirect to Update Page that Auto-Downloaded a JavaScript file

    Opera for Windows
    4
    9
    3028
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • fatguy1121
      fatguy1121 last edited by

      I just had my browser redirect a site I was looking at to a page that looked very legitimate claiming that Opera was out of date, and automatically downloaded a javascript file. Is this normal behavior or nefarious, I have the javascript file saved in an archive and can upload it if needed. I immediately closed and re-opened opera then checked for updates where it updated to 62.0.3331.18.

      Reply Quote 0
        leocg 1 Reply Last reply
      • burnout426
        burnout426 Volunteer last edited by

        Sounds shady to me, but you can upload the script somewhere if you want. Also, what domain did the redirect take you too if you remember? Did you have 58 before Opera updated to 62?

        Reply Quote 0
          1 Reply Last reply
        • fatguy1121
          fatguy1121 last edited by

          Specifically this was the website I was on. http://justsomething.co/kitten-breaks-his-owners-earphone-cable-and-returns-with-snake-as-a-replacement/?fbclid=IwAR00IFQZAMtKldKhe2w5-s3_-5kiANpfp_RmvsZJHrbxVrh1ih15FWVoV-I

          The update screen just popped up, it didnt change the web address, in fact history shows the website url with Opera update as the url. I was previously on 62.0.1 or something like that, it only updated a minor build

          Reply Quote 0
            1 Reply Last reply
          • burnout426
            burnout426 Volunteer last edited by

            Yeah, I wouldn't trust that link. It just told me Chrome needed to be updated when I have the latest. The update link is a data URI that represents a json file. I was going to save it to see what was in it, but I closed the tab and can't get the redirect to happen now. Might remember by ip address on this one.

            Anyway, I would think that Opera updating for real on you was just a coincidence. If you're unsure though, you can uninstall Opera while choosing to keep your data, delete the program files folder for Opera if it's still there, download the Opera installer from opera.com and install.

            Reply Quote 0
              1 Reply Last reply
            • fatguy1121
              fatguy1121 last edited by

              Here is the JS file itself. (7zipped for security) https://drive.google.com/open?id=1ZMjHAD700AKchyiViDPD6wcaUh0kct44

              Here is the text out of the JS file https://pastebin.com/rYFsdfTj

              it looks like a bunch of arrays and obfuscated code. I dont know JS well enough to decipher it.

              Reply Quote 0
                burnout426 1 Reply Last reply
              • leocg
                leocg Moderator Volunteer @fatguy1121 last edited by

                @fatguy1121 For me, the fact that you were redirected from a page you were seeing to that one with the update needing message already shows that is not a good thing. Opera would never do something like that and a serious page would just have pointed a kibk to the official Opera site.

                This kind of message ('Your browser needs update', 'There is a virus in your computer', 'You have to update your computer' and so on) are somewhat regular ones used to make you install malware in your system.

                Reply Quote 0
                  fatguy1121 1 Reply Last reply
                • burnout426
                  burnout426 Volunteer @fatguy1121 last edited by

                  @fatguy1121 said in Opera Automatic Webpage Redirect to Update Page that Auto-Downloaded a JavaScript file:

                  it looks like a bunch of arrays and obfuscated code

                  There's a string at the end passed to the anonymous function that is base64 data that represents some binary data. Didn't investigate further, but definitely shady.

                  Reply Quote 0
                    1 Reply Last reply
                  • fatguy1121
                    fatguy1121 @leocg last edited by

                    @leocg I tried to get it to happen again from a different IP on a different computer and couldnt get it to happen, but it was the most legitimately designed page I've seen. It genuinely looked like a real update page that could have been created within the browser. If anyone else clicks it and gets it to pop up, take a screenshot.

                    Reply Quote 0
                      1 Reply Last reply
                    • A Former User
                      A Former User last edited by

                      For me, this happened just now on techerator.com from this Google search result. It was a well-made page that was convincing if it were not for the suspect auto download that didn't seem right.

                      Note I have added "broken" to the domain so it's rendered impotent.

                      https://broken.google.co.uk/url?sa=t&rct=j&q=&esrc=s&source=web&cd=14&cad=rja&uact=8&ved=2ahUKEwil6dv-j5vjAhUJTsAKHWP3AysQFjANegQIDBAB&url=http%3A%2F%2Fwww.techerator.com%2F2011%2F12%2Fhow-to-embed-images-directly-into-your-html%2F&usg=AOvVaw1o2EaUH52r53_GPKHeuClu

                      It wasn't until I scrolled or maybe was on the site for a few seconds. The JS file was obfuscated, starting like this:

                      (function(lyfwxi){var adubxo={};function egisur(){ymejig4=ygffipyv[["y","E","j","Z","D","T","G"][(-597+599)]+["o","C","a","b"][0]+"i"+"n"]("");diep......
                      

                      Most concerning is that Opera was obviously coerced into auto downloading a script file.

                      Reply Quote 1
                        1 Reply Last reply
                      • First post
                        Last post

                      Computer browsers

                      • Opera for Windows
                      • Opera for Mac
                      • Opera for Linux
                      • Opera beta version
                      • Opera USB

                      Mobile browsers

                      • Opera for Android
                      • Opera Mini
                      • Opera Touch
                      • Opera for basic phones

                      • Add-ons
                      • Opera account
                      • Wallpapers
                      • Opera Ads

                      • Help & support
                      • Opera blogs
                      • Opera forums
                      • Dev.Opera

                      • Security
                      • Privacy
                      • Cookies Policy
                      • EULA
                      • Terms of Service

                      • About Opera
                      • Press info
                      • Jobs
                      • Investors
                      • Become a partner
                      • Contact us

                      Follow Opera

                      • Opera - Facebook
                      • Opera - Twitter
                      • Opera - YouTube
                      • Opera - LinkedIn
                      • Opera - Instagram

                      © Opera Software 1995-