# Possible illicit adware injected into SDMB posts??

**URL:** <https://boards.straightdope.com/t/possible-illicit-adware-injected-into-sdmb-posts/582138>\
**Category:** About This Message Board\
**Created:** [May 16, 2011, 8:54pm UTC](https://boards.straightdope.com/t/possible-illicit-adware-injected-into-sdmb-posts/582138 "2011-05-16T20:54:51Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [May 16, 2011, 8:54pm UTC](https://boards.straightdope.com/t/possible-illicit-adware-injected-into-sdmb-posts/582138/1 "2011-05-16T20:54:51Z")

</div>

Twice today I’ve clicked on a link somebody embedded in a post and ended up being routed through an ad company

Here’s an example link (but broken by me):  
htt p://api.viglink.com/api/click?format=go&drKey=1259&loc=http%3A%2F%[2Fboards.straightdope.com](http://2Fboards.straightdope.com)%2Fsdmb%2Fshowthread.php%3Ft%3D608721&v=1&libid=1305578363227&out=http%3A%2F%[2Fxkcd.com](http://2Fxkcd.com)%2F899%2F&ref=http%3A%2F%[2Fboards.straightdope.com](http://2Fboards.straightdope.com)%2Fsdmb%2Fforumdisplay.php%3Ff%3D4&title=XKCD%3A%20Mathematicians%20Discuss…%20-%20Straight%20Dope%20Message%20Board&txt=Lookee%20here.

And here’s the thread it came from: [XKCD: Mathematicians Discuss... - Miscellaneous and Personal Stuff I Must Share - Straight Dope Message Board](http://boards.straightdope.com/sdmb/showthread.php?t=608721) . The link is the first thing in the body of the OP.

I do not recall where the other [viglink.com](http://viglink.com) link I clicked came from, but it was in a thread I read here in the last 24 hours.

I’m \*\*not \*\*accusing the OPs of deliberately posting adware. But I am wondering whether the board has a problem. Or maybe one of the advertisers is yet again doing evil. Or maybe (eep!!) I’ve got a problem on my machine.

Anybody have any insight?

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [May 16, 2011, 9:18pm UTC](https://boards.straightdope.com/t/possible-illicit-adware-injected-into-sdmb-posts/582138/2 "2011-05-16T21:18:46Z")

</div>

ETA: Upon further checking I see the raw html coming from SDMB doesn’t have [viglink.com](http://viglink.com) in it. So either I’ve got a problem, or one of the advertisers is injecting javascript to hijack the links.

---

<div class="post-metadata">

**Author:** ![TBG](https://avatars.discourse-cdn.com/v4/letter/t/c89c15/32.png) [@TBG](https://boards.straightdope.com/u/TBG)\
**Post date:** [May 16, 2011, 10:18pm UTC](https://boards.straightdope.com/t/possible-illicit-adware-injected-into-sdmb-posts/582138/3 "2011-05-16T22:18:23Z")

</div>

Just to confirm, in the topic you link to, I’m not seeing all that illicit stuff in any of the links in the thread. Sounds like you’ve got malware on your system, unless this is something AdBlockPlus stopped on my end.

---

<div class="post-metadata">

**Author:** ![fubbleskag](https://avatars.discourse-cdn.com/v4/letter/f/c2a13f/32.png) [@fubbleskag](https://boards.straightdope.com/u/fubbleskag)\
**Post date:** [May 17, 2011, 12:53am UTC](https://boards.straightdope.com/t/possible-illicit-adware-injected-into-sdmb-posts/582138/4 "2011-05-17T00:53:09Z")

</div>

> [@TBG](#):
>
> Just to confirm, in the topic you link to, I’m not seeing all that illicit stuff in any of the links in the thread. Sounds like you’ve got malware on your system, unless this is something AdBlockPlus stopped on my end.

Same here.

---

<div class="post-metadata">

**Author:** ![iftheresaway](https://avatars.discourse-cdn.com/v4/letter/i/ecae2f/32.png) [@iftheresaway](https://boards.straightdope.com/u/iftheresaway)\
**Post date:** [May 17, 2011, 7:36am UTC](https://boards.straightdope.com/t/possible-illicit-adware-injected-into-sdmb-posts/582138/5 "2011-05-17T07:36:09Z")

</div>

I’ll echo that I didn’t see the viglink stuff on that link, but I have noticed that I’ve been having trouble with links on the Dope for the last week or so. They often don’t work at first, taking me instead to a SDMB-branded “404 not found” page, but work fine on a second click. I’ll have to look and see if they seem to be routed through somewhere else.

---

<div class="post-metadata">

**Author:** ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)\
**Post date:** [May 17, 2011, 10:35am UTC](https://boards.straightdope.com/t/possible-illicit-adware-injected-into-sdmb-posts/582138/6 "2011-05-17T10:35:17Z")

</div>

Viglink is not malware, it is an advertising scheme that pays the SDMB if a users clicks through to a product or service and buys something, SDMB earns a commission.

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [May 17, 2011, 11:50am UTC](https://boards.straightdope.com/t/possible-illicit-adware-injected-into-sdmb-posts/582138/7 "2011-05-17T11:50:23Z")

</div>

Ahh that makes sense. Next time it occurs I’ll check the page that actually loaded. It seems to be intermittent & when I said in my second post above that the raw page didn’t have the viglink link, that was after I 'd reloaded the page to check. I’ll report back here whatever I notice for everyone’s benefit.

---

<div class="post-metadata">

**Author:** ![TubaDiva](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tubadiva/32/507_2.png) [@TubaDiva](https://boards.straightdope.com/u/TubaDiva)\
**Post date:** [May 17, 2011, 1:51pm UTC](https://boards.straightdope.com/t/possible-illicit-adware-injected-into-sdmb-posts/582138/8 "2011-05-17T13:51:06Z")

</div>

Reported.

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [May 17, 2011, 2:09pm UTC](https://boards.straightdope.com/t/possible-illicit-adware-injected-into-sdmb-posts/582138/9 "2011-05-17T14:09:07Z")

</div>

This morning I’ve seen viglink links in several other SDMB posts. In each case the raw html (from the browser’s “view source”) had the pure link the OP posted, not the viglink-modified link.

I was not able to identify anything obviously evil in the html, but I didn’t go to the trouble of manually pulling in all the referenced js files & scanning them.

---

<div class="post-metadata">

**Author:** ![Irishman](https://avatars.discourse-cdn.com/v4/letter/i/b487fb/32.png) [@Irishman](https://boards.straightdope.com/u/Irishman)\
**Post date:** [May 17, 2011, 6:54pm UTC](https://boards.straightdope.com/t/possible-illicit-adware-injected-into-sdmb-posts/582138/10 "2011-05-17T18:54:35Z")

</div>

I have noticed this as well. The link on the page looks normal, the link in the info bar at the bottom looks normal, but when I paste into a browser window, all I see is the vigilink text that apparently lists the vigilink site, the straightdope page I’m on, and the text field from that page - but not the link itself.

Several times the link has not loaded. Sometimes it does work.

---

<div class="post-metadata">

**Author:** ![Darth\_Panda](https://avatars.discourse-cdn.com/v4/letter/d/ee7513/32.png) [@Darth\_Panda](https://boards.straightdope.com/u/Darth_Panda)\
**Post date:** [May 17, 2011, 10:35pm UTC](https://boards.straightdope.com/t/possible-illicit-adware-injected-into-sdmb-posts/582138/11 "2011-05-17T22:35:10Z")

</div>

I’ve noitced this as well - and it’s definitely slowed the linked page’s loading. I’m at a work computer where we have pretty strong security, fwiw.

---

<div class="post-metadata">

**Author:** ![SenorBeef](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/senorbeef/32/2220_2.png) [@SenorBeef](https://boards.straightdope.com/u/SenorBeef)\
**Post date:** [June 14, 2011, 9:39pm UTC](https://boards.straightdope.com/t/possible-illicit-adware-injected-into-sdmb-posts/582138/12 "2011-06-14T21:39:08Z")

</div>

Wait, so is the SDMB software itself injecting the vigilink middleman request to random user links? I know that some crappier/less reputable sites use software that does keyword searches on the text of the post and links those keywords to certain advertiser sites. Is the SDMB doing some stealthy form of that?

I had the vigilink thing going on for a while but I was sure it was some sort of malware on my system. But here I am on a brand new windows install still getting the vigilink stuff. What exactly is going on?

---

<div class="post-metadata">

**Author:** ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)\
**Post date:** [June 14, 2011, 10:15pm UTC](https://boards.straightdope.com/t/possible-illicit-adware-injected-into-sdmb-posts/582138/13 "2011-06-14T22:15:15Z")

</div>

> [@SenorBeef](#):
>
> Wait, so is the SDMB software itself injecting the vigilink middleman request to random user links? I know that some crappier/less reputable sites use software that does keyword searches on the text of the post and links those keywords to certain advertiser sites. Is the SDMB doing some stealthy form of that?

No. Viglink does not redirect links when you click on them.

> [@](#):
>
> I had the vigilink thing going on for a while but I was sure it was some sort of malware on my system. But here I am on a brand new windows install still getting the vigilink stuff. What exactly is going on?

Viglink is not malware that installs on your computer. Viglink is an advertising company that contracts with vendor sites to affiliate member sites with vendors. Vendors pay Viglink a commission if anybody buys something after clicking on a link on the SDMB, and Viglink pays the SDMB a portion of that commission. Nothing nefarious, though it might slow loading of links slightly as Viglink processes the link. People have been whining for years to affiliate with Amazon or other vendors as a way to make the SDMB profitable. Viglink just expands that to a larger circle of vendors.

Here is the[FAQ on the Viglink website](http://www.viglink.com/support/faq).

---

<div class="post-metadata">

**Author:** ![elfkin477](https://avatars.discourse-cdn.com/v4/letter/e/a9a28c/32.png) [@elfkin477](https://boards.straightdope.com/u/elfkin477)\
**Post date:** [August 1, 2011, 11:25am UTC](https://boards.straightdope.com/t/possible-illicit-adware-injected-into-sdmb-posts/582138/14 "2011-08-01T11:25:44Z")

</div>

It may not be nefarious, but a lot of the links don’t work properly. Instead of going on to the proper website, it’s failing with viglink still part of the URL.

---

<div class="post-metadata">

**Author:** ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)\
**Post date:** [August 1, 2011, 12:13pm UTC](https://boards.straightdope.com/t/possible-illicit-adware-injected-into-sdmb-posts/582138/15 "2011-08-01T12:13:02Z")

</div>

Try deleting your temporary internet files.

---

<div class="post-metadata">

**Author:** ![Morgyn](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/morgyn/32/3041_2.png) [@Morgyn](https://boards.straightdope.com/u/Morgyn)\
**Post date:** [August 1, 2011, 4:34pm UTC](https://boards.straightdope.com/t/possible-illicit-adware-injected-into-sdmb-posts/582138/16 "2011-08-01T16:34:29Z")

</div>

No issues for me, if that’s any help. I have AdBlock Plus, NoScript, and Redirect Remover plugins installed in Firefox.

---

<div class="post-metadata">

**Author:** ![Sunspace](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sunspace/32/1250_2.png) [@Sunspace](https://boards.straightdope.com/u/Sunspace)\
**Post date:** [August 1, 2011, 4:58pm UTC](https://boards.straightdope.com/t/possible-illicit-adware-injected-into-sdmb-posts/582138/17 "2011-08-01T16:58:22Z")

</div>

Now I know what it is, it seems …not bad. But it would be a _really_ good idea to mention that Viglink is in use somewhere on the header of each SDMB page… so that we don’t think it’s malware. Viglink itself ‘strongly’ recommends informing the viewers.

---

<div class="post-metadata">

**Author:** ![Ed\_Zotti](https://avatars.discourse-cdn.com/v4/letter/e/fbc32d/32.png) [@Ed\_Zotti](https://boards.straightdope.com/u/Ed_Zotti)\
**Post date:** [August 3, 2011, 4:13pm UTC](https://boards.straightdope.com/t/possible-illicit-adware-injected-into-sdmb-posts/582138/18 "2011-08-03T16:13:01Z")

</div>

Viglink is indeed a partner of ours; we get a small commission every time you click on a link to one of their clients. The process is supposed to be more or less invisible and doesn’t load any software on your computer. We’ve had scattered reports of malware from clicking on a link, e.g., the infamous phony virus scan popup. This isn’t supposed to be happening. If you see it, save a screen shot before bailing (Alt-Print Screen) and let us know; we’ll investigate.
