AFL.com.au Possible Seedy Actions in Background

Hi All,

Stumbled across the afl website in Opera browser for a change, and 3 things I noticed immediately.

  1. Website not secure
  2. trying to load scripts from unauthenticated sources
  3. High CPU usage

I have tried this in chrome and same same.

I was wondering if someone with some website/programming knowledge has the time and inclination to look into this to see whats going on.

I find it insane that with the cyber crime going on these days, that the first point is even happening.

Would love to get some info on this.

Thanks.

Related Stores

Australian Football League
Australian Football League

Comments

  • Did you lose any money?

  • +1

    Can you please MS Paint your CPU usage for us?

    • no need, it's 99%, when close afl.com.au or afl.com.au/ladder, drops to 5% on avg

      • I have a fast machine with quite a bit of CPU power. When I open a window in the browser with just Google the CPU % in Task Manager is 0%. When I open afl in another window the usage leaps up to 20% for the new window and then falls back to sit on about 12%. Seems to be a bit of activity there. What do you expect when the site manager is Telstra.

        • Thanks for feedback. I just find it hard to understand even without loggin into their site why it is not secured. I read www.thehackernews.com just to see whats going on and dont fully understand it all, but having non-secure websites makes me thinks just time before it gets hijacked…..

  • +2

    I have referred this to Brayshaw for actioning

  • Call the police

  • +1

    maybe their website has been injected with some crypto-mining script.

  • I'm not great at IT, but at a quick glance a bit iffy but seems okay? It doesn't run the whole site through SSL, but the login information is done through telstra login with a certificate, which is where you'd want the cert to be at least I'd think.

    I don't know about the high CPU usage if it has any, I checked a few of the JS scripts, one about buckets which makes me think it has something to do with the infrastructure side, another is the ruxitagentjs which looks to be used at real time user monitoring so likely getting user data? And Mordenizr to find what features (HTML CSS) the browser running has available.

    I would assume if there was a JS script running and high cpu usage it would be a JS cryto miner in the background, but unfortunately I didn't see or didn't spend enough time finding one?

    • Username checks out.

    • thanks for the response and time. Just wanted someone with a little knowledge(which is more than me) to check on it. I did email them 2-3 weeks ago about this stuff, got a reply saying looking into, and still nothing since. Pretty poor really. I suppose being a big pond there is a lot to go through……..

  • +1

    They have the internet on computers now?

    • yep, they got hats too!

  • +1

    I think they do a pile of information gathering together with Telstra.

    It is disgusting that just looking at the ladder gives 10 seconds of the betting odds before showing it, as kids can reasonably be expected to use the site.

    • If that is whats going on, information gathering, I suppose I should not be surprised.

  • Crypto mining

  • Thought this was something else, lol.

    • Yeah lol was wondering if there were pictures

  • I noticed when looking at this site that it does a lot of auto updating of displayed information like scores and ladder positions. They even call the ladder the Live Ladder. I was watching the Sydney v Melbourne game and as the scores changed so did the position on the ladder and the %. Lots of things going on and no doubt a bit of hoovering up your data also.

Login or Join to leave a comment