Directv.com Security Warning

EarDemon

SatelliteGuys Pro
Original poster
Dec 5, 2014
1,603
739
USA
I'm guessing this is a false positive from SEP, but is anyone else getting notifications from their security software when going to directv.com? It started happening two days ago for me.

sepalert.jpg
 
I usually manage my account from my iPhone but I went to their website for the first time today on my desktop and got this from Norton LifeLock (from my understanding even though Symantec Endpoint Protection and Norton LifeLock are now separated it appears they still share some things when it comes to security.)

a2c9da425125a67061cdf3bdaad8db6b.png


However I noticed that the message only appears when using Google Chrome and the new Microsoft Edge browser based on Google Chrome. When using Mozilla Firefox and Internet Explorer the message does not appear.
 
  • Like
Reactions: harshness
Interesting, thanks for posting.

Yeah, Norton Lifelock and Symantec Endpoint are probably going to share the same underpinnings for a long time. If Symantec wanted to separate their consumer and enterprise operations, I wish they would have split the company (like they did with Veritas) instead of selling to Broadcom. Broadcom has really no idea what they are doing, and the integration has been a complete hellish nightmare to deal with. Also have to keep reminding myself that Norton LifeLock is what used to be Symantec Corporation, and Symantec exists in name only when it comes to SEP and GSS.

Good catch on the alert being browser dependent. The new Edge is my default browser, but I also tried in Chrome and Chromium. I don't have Firefox installed, and I forget IE still exists.
 
In the source code of the home page and the DirecTV packages subpage on directv.com there is a Google AdService ad trying to load and there is the "netcheckcdn[dot]xyz" domain for some ungodly reason. Each time the directv.com webpage loads Symantic Endpoint, Norton and Malwarebytes (and possibly other anti-virus software) will automatically block this domain.

I've noticed that the current version of the website has this code:
65b1983f630e38aa673e7d3952b1f643.jpg
475cf95096e01479e1f1de0f4807b564.png

Now sometimes an older version of the website will load that does not have the offending domain and thus the warnings will not trigger (idk why or how this happened)

77f8ebf3424ae0db086151464e71d89b.jpg
e9537653340e8834d80f852f9a890669.png

No other pages on directv.com like the manage account or login pages are affected and they do not have the netcheckcdn domain which is why the anti-virus software doesn't trigger warnings on those pages. The other subpages (premiums, sports packages, etc.) are housed on att.com and are not affected either.

Now... if you are constantly seeing security warnings for netcheckcdn outside of the directv.com homepage or the directv packages subpage on directv.com then you most likely have a virus or an unwanted adware program.

My computer is 100% clean after extensive scanning to confirm and I only experience these warnings with Norton (and now Malwarebytes) when I visit directv.com via Google Chrome, Google Chrome Canary and the new Microsoft Edge (as it is based of Chromium). I'm guessing both Mozilla Firefox and Internet Explorer ignore whatever ad they are trying to run since they are non-Chromium based browsers.
 

AT&T’s massive TV losses continue as another 900,000 customers flee.

Randall Stephenson "retiring"

Users Who Are Viewing This Thread (Total: 0, Members: 0, Guests: 0)

Who Read This Thread (Total Members: 1)