Slashdot Mirror


Hackers Use Banner Ads on Major Sites to Hijack Your PC

The worst-case scenario used to be that online ads are pesky, memory-draining distractions. But a new batch of banner ads is much more sinister: They hijack personal computers and bully users until they agree to buy antivirus software. And the ads do their dirty work even if you don't click on them.The malware-spiked ads have been spotted on various legitimate websites, ranging from the British magazine The Economist to baseball's MLB.com to the Canada.com news portal. Hackers are using deceptive practices and tricky Flash programming to get their ads onto legitimate sites by way of DoubleClick's DART program. Web publishers use the DoubleClick-hosted platform to manage advertising inventory." CT: Link updated to original source instead of plagerizer.

47 of 268 comments (clear)

  1. oh great by deftones_325 · · Score: 5, Funny

    So now I need to buy penis-enlargment pills AND and anti-virus.

    --
    "A gentleman never strikes a lady with his hat on." - Fred Allen
    1. Re:oh great by FuzzyDaddy · · Score: 5, Funny

      Yes, those two things often go together.

      --
      It's not wasting time, I'm educating myself.
  2. What are these "ads" you're talking about ? by galaad2 · · Score: 5, Insightful

    That's why Firefox+NoScript+AdBlock Plus+Flashblock were invented

    --
    root@127.0.0.1
    1. Re:What are these "ads" you're talking about ? by galaad2 · · Score: 2, Informative

      i beg to differ, Flashblock does have a purpose even together with NoScript:

      on some sites i want to allow scripts but block flash... and this is the best solution i've found.

      --
      root@127.0.0.1
    2. Re:What are these "ads" you're talking about ? by Neil+Hodges · · Score: 2, Informative

      No, but AdBlock (Plus or vanilla) will do this for you.

      - Neil

  3. Never Experienced This by ilovegeorgebush · · Score: 3, Insightful

    I've never come across one of these ads. In fact, I rarely get ads as I use the Adblock Plus plugin for Firefox. This just gives even more reason to ban advertisements entirely. Thanks!

    1. Re:Never Experienced This by Otter · · Score: 3, Funny
      Adblock doesn't block these, as they constantly change the domain names. NoScript, which is otherwise way too paranoid and obtrusive for my taste, will do it.

      Unrelated thoughts:

      1) YouTube video is a rather inefficient way to distribute this analysis.

      2) The security guy is way too kind to the sites hosting these ads. I've written to several of them, telling them how sleazy the ads are and how bad they make the site look, and the ads are still there.

      3) How did YouTube decide that "ridiculously hot LATINA girl dancing, not asian!" is a Related Video? Except in the sense that it's always relevant, I mean.

    2. Re:Never Experienced This by doombringerltx · · Score: 5, Funny

      3) How did YouTube decide that "ridiculously hot LATINA girl dancing, not asian!" is a Related Video? Except in the sense that it's always relevant, I mean. Finally a reason to RTFA
    3. Re:Never Experienced This by orclevegam · · Score: 3, Insightful

      Actually, these are getting into some reputable sites through places like DoubleClick, which is one of the domains that AdBlock targets, so in this case it will protect you. Now, on less reputable sites that are getting these things directly instead of through DoubleClick, yeah, AdBlock won't do much there.

      --
      Curiosity was framed, Ignorance killed the cat.
    4. Re:Never Experienced This by rucs_hack · · Score: 2, Informative

      most advert serving domains still, for some reason place the images to be used in */ads/* or */banners/*, something like that anyway. A well written rule file for adblockplus (e.g most available ones) have the capacity to block many previously unknown ad servers. Then of course if they are spotted, they go on the list.

    5. Re:Never Experienced This by Constantine+XVI · · Score: 2, Informative

      AdBlock Plus, as mentioned by GP, has a built-in filter updater to combat exactly what you mentioned.

      --
      "I think an etch-a-sketch with an ethernet port would beat IE7 in web standards compliance."
    6. Re:Never Experienced This by Strilanc · · Score: 2, Informative

      A large number of ads can be identified without even paying attention to the website. /ad((space)|(border)|(centric)|(cycle)|(farm)|(frame)|(image)|(logs)|(mentor)|(serv)|(vert)|(vus)|(header)|(zone)|(fetch)|(vo)|(id=)|(client)|(data)|(srv)|(view))/

      is by far the best performing filter I have.

  4. AdBlock and NoScript by Timinithis · · Score: 5, Interesting

    I use these exclusively, are there reports that this method gets by them? I know that if the ad is blocked, it isn't downloaded, but is that all it takes, download the ad and you have the virus?

    Sounds like a reason to just block all double-click items...

    I don't enable flash/scripts on any page unless it is needed -- like scripts for /.

    --
    Sig? What's a Sig?
    1. Re:AdBlock and NoScript by secPM_MS · · Score: 2
      I don't see a need for blocking adds. The problem is not the adds per. se., but the active content. Active content may be malicious. Unfortunately, rich media is the draw for the bulk of the viewer base and rich media tends to use active content.

      The viewer / user if presented with Hobson's choice: accept active content, get the desired benefit - while taking the risk; or block active content, be safe, and not get the desired benefit.

      If the user wants to view the content and be relatively safe, they can run Vista as a normal user and NOT elevate to administrator to install stuff when the malicious site downloads malware to their system.

      They can run NoScript or equivalent and be very careful to authorize only those domains that they trust to run script.

      I am paranoid. I run Windows Server 2008, running as a normal user. IE 7 is configured as my default browser in enhanced security mode, which is locked down and secure. IE will not allow me to download many types of items in the Internet zone, so I use Firefox with NoScript installed and kept current. I am very cautious about what sites I allow to run script, but I have blacklisted doubleclick. I do not run flash.

    2. Re:AdBlock and NoScript by Stradivarius · · Score: 2, Insightful

      Even passive content like a JPEG may be malicious/unsafe. Suppose someone discovers a buffer overflow exploit in how IE processes images. You can bet that you'll start seeing images crafted to trigger the exploit and thus hijack the viewing computer. They may well end up on Doubleclick's network.

      When you have (inevitably) imperfect software paired with untrusted content providers, there is no guaranteed way to be safe. Which is what makes Doubleclick such a menace - you can't even trust reputable sites anymore, because they're serving ads from unknown and untrusted sources via Doubleclick.

  5. who is to blame by cpearson · · Score: 2, Insightful

    Great, now we can await a round of finger pointing to begin over who is liable.

    --
    Windows Vista Help Forum
  6. Very stupid idea by TheMeuge · · Score: 2, Informative

    This just gives even more reason to ban advertisements entirely.


    The "let's ban it" attitude seems awfully familiar. Are you a member of the US, UK, or EU parliament by any chance?

    Like it or not, but advertising generates (directly and indirectly) the revenue that drives the Internet. When advertisement is passive, and does not attempt to hijack your computer, it is theoretically an win-for-all scenario: the advertisers get their clients, the consumers get their products, and the sites that host the advertisement get their costs and expenses covered.
    1. Re:Very stupid idea by Anonymous Coward · · Score: 3, Insightful

      The "let's ban it" attitude seems awfully familiar. Are you a member of the US, UK, or EU parliament by any chance?

      Like it or not, but advertising generates (directly and indirectly) the revenue that drives the Internet. When advertisement is passive, and does not attempt to hijack your computer, it is theoretically an win-for-all scenario: the advertisers get their clients, the consumers get their products, and the sites that host the advertisement get their costs and expenses covered.


      You are very much mistaken. Advertising seeks good mediums to exploit, and always shows up AFTER the medium has established itself. Advertising funds garbage content.

      Advertising does NOT generate the revenue that drives the internet, and without it, the internet would not only continue to thrive, but would improve. You're probably too young to remember it, but the internet existed long before anyone thought of using it for advertising. HTML existed long before anyone thought of using it for advertising. If every single ad-supported site vanished from the webernets overnight, things would be better. People with something worthwhile to publish would continue to publish, and those who spout useless drivel and subsist on advertising would have to crawl back to the holes from whence they came.

  7. Ah, let the blame game begin by SuperBanana · · Score: 4, Insightful

    The malware-spiked ads have been spotted on various legitimate websites, ranging from the British magazine The Economist to baseball's MLB.com to the Canada.com news portal.

    ...and since those sites outsource to Doubleclick, they'll point a finger at them. Doubleclick will no doubt point the finger at some previously-unheard-of company that "solicits advertisements for the Doubleclick network", and they'll point the finger at their "client."

    Meanwhile, The Economist, MLB, Canada.com, etc won't take responsibility for the content they present on their website (after all, they chose to use Doubleclick, they chose to put advertisements on the website, they chose not to require approval of ads before they were shown on their website, etc.) Funny how everyone is trigger-happy when it comes to copyright, but when it comes to content they present causing harm, it ain't theirs, eh? :-)

    Doubleclick, of course, won't accept responsibility for vetting advertising distributed via their channel (which seems like a standard business procedure for, oh, an advertising network?) The only comfort is the mechanism of the free market: if website users get pissed enough, said websites might put pressure on Doubleclick or leave them altogether. That's bad for Doubleclick business, so maybe Doubleclick will consider vetting ads better, or run checks to see that flash code doesn't do certain things, etc. Then again, if the malicious banner ad suppliers are paying good enough money, Doubleclick may be perfectly happy to issue a press release "apologizing" and keep right on doing business as usual.

    1. Re:Ah, let the blame game begin by Frosty+Piss · · Score: 4, Informative

      Meanwhile, The Economist, MLB, Canada.com, etc won't take responsibility for the content they present on their website (after all, they chose to use Doubleclick, they chose to put advertisements on the website, they chose not to require approval of ads before they were shown on their website, etc.) Funny how everyone is trigger-happy when it comes to copyright, but when it comes to content they present causing harm, it ain't theirs, eh?
      And speaking of "trigger-happy", you seem to point the finger right back at the Web sites for not inspecting the ads and the underlaying code. Well, that's what they hire DoubleClick for, thats one of the points for using outside ad servers. DoubleClick (and its Mother Ship Google) where not doing their jobs. It was THEIR responsibility to know that the ads THEY served where ligit or not. That's why THEY make the "big bucks". Google is good, Google is God...
      --
      If you want news from today, you have to come back tomorrow.
  8. TFA = Site scraping? by Anonymous Coward · · Score: 5, Informative

    The flibby link is identical to this Wired blog post by Betsy Schiffman, dated four days earlier.

  9. ISP's should block DoubleClick by RichMan · · Score: 2, Interesting

    This is a good enough reason for ISP's concerned about security to block DoubleClick. You spam the net with bad referrals you get binned. Also think of the traffic that would get binned, way better than blocking p2p.

    Do it for a month and DoubleClick and their ilk will be extra sure about not hosting bad stuff.

  10. Your company/family/school by KiloByte · · Score: 5, Interesting

    Right, we all use Adblock and the like. Yet, you can't force everyone in the vicinity to do so, there are lesser minds who opt for Opera, and there's even a tiny portion of giants on Links -- and let's not even mention how low SOME folks can fall.

    I would say that adzapper (if you use squid) or a DNS-based blacklist is quite mandatory wherever you do have a say. Glancing at the logs of ISPs I have root at, roughly 1/4 of all freaking http requests go to lowlifes -- and even that based on my grossly incomplete list of ad/spyware/tracking scum.

    Yeah, 25%. That's horrible.
    And there are some customers dumb enough to complain if you do protect them from ads, so you can't do this in an ISP scenario. But in a company, school or family? Hell yeah, there's no reason for doubleclick.com to get through, ever.

    --
    The creatures outside looked from Alt-Right to Antifa; but already it was impossible to say which was which.
    1. Re:Your company/family/school by Nicolay77 · · Score: 4, Informative

      Opera is faster and more secure. Opera 9.5 is even faster, making Safari bite the dust. It also uses less memory.

      It also can block ads (although not with a blacklist as FF, but you can block whole domains).

      To me the lesser minds are the ones that can't respect other people choices.

      --
      We are Turing O-Machines. The Oracle is out there.
  11. Not exactly new by Anonymous Coward · · Score: 5, Informative

    This has been going on since flash 8 was released with a vulnerability. I got hit by this about a year ago, maybe a little more.

      Suddenly windows security center, that I routinely turn off because I can't stand the nagging, started up and told me that my computer was insecure and that I should go to a certain website and buy their virus defender software.

    Not very subtle to a savvy person like myself, but I imagine some people would fall for it.

    The box also started throwing up connection error message boxes, presumably because my external firewall were blocking outgoing connection attempts. Again not subtle, but it's an uncommon setup for a home user.

    Third, it must have rooted the box somehow because certain files became invisible. "test.exe" among them. Renaming a textfile to text.exe would make it disappear, and the folder would be unremovable. Cygwin came to the rescue there. Also I noticed only because I happened to have lots of little crap programs laying around.

    The virus scanners did not pick up on this.

    This is the only time I have actually contracted a virus. Needless to say I hosed the box (PING is not disk image). What I learned from the experience is that knowing your system is way more effective than a virus scanner, and B) don't trust flash which is how I got the damn thing. I thought I was safe with firefox.

    1. Re:Not exactly new by orclevegam · · Score: 2, Insightful

      FlashBlock is your friend.

      --
      Curiosity was framed, Ignorance killed the cat.
  12. Terrible relationships with their advertisers by sseaman · · Score: 4, Insightful

    Content providers need to be responsible for the content of the ads posted on their sites - that's a given. TFA indicates that these content providers (the people behind NHL.com, for example) simply received payment for these ads via credit card or wire transfer and then posted the content. If these sites used a network television model, they would have intimate relationships with the advertisers and would work together to provide less offensive and more effective ads. I don't think they need to go that far (network television ads are far from perfect, although they are quite effective), but clearly MLB.com and NHL.com need to be held responsible for the content on their sites, and hopefully this will encourage better cooperation between site hosts and advertisers.

  13. Say.. doesn't Slashdot use Doubleclick? by Animaether · · Score: 3, Interesting

    I'm pretty sure it does because I had to wait 30 seconds for any page of Slashdot's to render fully yesterday because Firefox was busy waiting for ad2.doubleclick.com or somesuch subdomain of theirs. The current page source certainly has doubleclicky ads.

    Now, granted, the malware distributors typically tag ads for subjects not often seen on Slashdot (but I get them on, e.g., the Sinfest comic - huh, imagine that).

    I'd say it's about time Doubleclick (that's you, Google, if you finally get to say you did indeed acquire it and everybody OK'd the deal.) gets held a little more responsible for this sort of thing being done through their network for which they collect money.

  14. Doubleclick sent out a notice Friday by night_flyer · · Score: 4, Informative

    here's a list of the sites that contained the malware:
    100it.info, 10smi.info, 2greatfind.com, 2quickfind.com, 3akoh.net, Ad2cash.net, Ad2profit.com, Adcomatoz.com, Adgurman.com, Adhokuspokus.com, Adnetserver.com, Adredired.com, Adsolutio.com, Adtraff.com, Adverdaemon.com, Adverlounge.com, Adzyclon.com, Alg-search.com, Alhoster.com, Aligarx.biz, All-search-it.com, Alphatown.us, Anmira.info, Anonymbrowser.com, Antivirussecuritypro.com, Aptprog.com, Art-earn.biz, Astalaprofit.com, Autodealer-search.com, B2adz.com, Bazaard.com, Belkran.com, Belshar.com, Bestadmedia.com, Best-biznes.info, Best-cools.info, Bestdatafinder.com, Besteversearch.com, Bestpharmacydeals.com, Best-screensavers.biz, Bestsearchnet.com, Bestshopz.com, Bestwm.info, Bestwnvmovies.com, Bezzz.info, Bi-bi-search.com, Bizadverts.com, Bizmarketads.com, Blessedads.com, Bm-redy.com, Bovavi.com, Brandmarketads.com, Bucksinsoft.com, Burnads.com, Cancerno.com, Candid-search.com, Carpropane.com, Cashloanprofit.com, Casinoaceking.com, Casinoby.com, Casinodealsgalore.com, Cha-cha-search.com, Cheap-auto-deals.com, Checkstocklist.com, Chushok.com, Clever-at-search.com, Clubheat.info, Come-from-stars.com, Co-search.com, Creamme.net, Cryptdrive.com, Cyndyk.info, Deuscleanerpay.com, Didosearch.com, Diphelp.biz, Dmitry-v.info, Doma2000.com, Durtsev.com, Easybestdeals.com, Energostroj.com, Enothost.com, Eroticabsolute.com, Errordigger.com, Errorinspector.com, Evrogame.info, Fandasearch.com, Fantazybill.com, Fastwm.info, Fastzetup.info, Fati-gati-search.com, Favourable-search.com, Favouriteshop.com, Feel-search.com, F-host.net, Fifaallchamp.com, Fight-arts.com, Fileprotector.com, Findbyall.com, Firstbestsearch.com, Firstlastsearch.com, First-ts.com, Foamplastic.net, Fokus-search.com, Force-search.com, Forceup.com, Forex-instruments.info, Forvatormail.com, Freepcsecure.com, Freerepair.org, Freetvnow.net, Friedads.com, Fulsearch.com, Getfreecar.com, Gibdd.us, Glass-search.com, Glorymarkets.com, Gosthost.net, Great4mac.com, Greyhathosting.com, Gt-search.com, Hackerpro.us, Hardlinecenter.com, Hebooks-service.com, Hintway-international.com, Homeofsite.com, Hromeos.com, Hyip2all.org, Icq-lot.org, Iddqdmarketing.com, Ideal-search.com, Idea-rem.com, I-forexbank.biz, I-games.biz, Imamis.net, Individ-search.com, Information-advertising.info, Infyte.com, Initial-search.com, Insochi2014.com, Installprovider.com, Internetadaultfriend.com, Internetanonymizer.com, Internetsupernanny.com, Intervarioclick.com, Investmentsgroup.org, Invulnerableads.com, It-translation.biz, Izol-tech.com, Kamerton-tests.com, Kazilkasearch.com, Keytooday.com, Keywordcpv.com, Kiridi.net, Kpoba.net, Kurgan45.info, Ladadc.com, Lanastyle.com, Ldizain.info, Libresystm.com, Liders.biz, Linii.net, Liveclix.net, Loffersearch.com, Londasearch.com, Lovecraft-forum.net, Loveopen.info, Lseom.biz, Luckyadcoin.com, Luckyadsols.com, Mad-search.com, Magicsearcher.com, Mailcap.info, Manage-search.com, Marketingdungeon.com, Mass-send.com, Max-expo.net, Maxyanoff.com, Mediatornado.com, Mega-project.biz, Megashopcity.com, Mightyfaq.com, Misc-search.com, Mobilesoftmarketing.com, Mobiletops.com, Mobilorg.org, Moneycometrue.com, Moneypalacecash.com, Mounthost.net, Myfavouritesearch.com, Myhealth-life.org, Myonlinefinance.com, Mysurvey4u.com, Mythmarketing.com, Mytravelgeek.com, Myusefulsearch.com, Napol.net, Navygante.com, Netmediagroup.net, Netturbopro.com, Newbieadguide.com, Nryb.com, Of-by.info, Olgalml.com, Ol-search.com, Onedaysoft.com, Onestopshopz.com, Onwey.com, Opensols.com, Original-search.com, Osetua.com, Osminog.org, Parischat.org, Passwordinspector.com, Pcsoftw.com, Pcsupercharger.com, Performanceoptimizer.com, Piramidki.com, Podelkin.info, Popadprovider.com, Popsmedia.com, Popupnukerpro.com, Postcity.info, Prenetsearch.com, Prevedmarketing.com, Prizesforyou.com, Pro-dom.info, Propotolok.info, Pro-svet.info, R2d2adverising.com, Radiosfera.net, Rocktheads.com, Roller-search.com, Rombic-search.com, Rus-invest.net, Rusnets.info, Russia-post.com, Sajruen.info, Samson-pro.com, Sauni.net, Se7ensearch.com, Search-and-win.com,

    --


    Thanks to file sharing, I purchase more CDs
    Thanks to the RIAA, I buy them used...
  15. hosts file by phrostie · · Score: 4, Informative

    all the more reason to set up a host file

    http://www.mvps.org/winhelp2002/hosts.htm

  16. Re:I only found these ads on.... by morgan_greywolf · · Score: 5, Informative

    BTW these ads are not directly dangerous unless you are running on some old browser/old Windows system, but yes, they are annoying as hell. Um, wrong. Watch the video. The guy is running Windows XP SP 2.
  17. Why aren't we blaming the browser? by bhmit1 · · Score: 3, Insightful

    Everyone is cheering for AdBlock when they read this, but why is it ok that a browser can install spyware, viruses, etc when you are browsing a web page? Shouldn't this be something that can only happen on sites that you explicitly permit or upon agreeing to a dialog asking if it's ok to run a given program? If you can experience this problem with double-click, then you can experience the same problem with any web site out there, so I'd much rather see us fixing the security holes in various browsers.

    1. Re:Why aren't we blaming the browser? by moderatorrater · · Score: 4, Insightful

      Flash is a plugin, it's what needs to enforce a security model. Also, sites need to step up and stop allowing exploitative ads. If an ad is clearly posing as a windows dialog box, then that ad shouldn't be allowed onto your site.

  18. Re:I only found these ads on.... by foobsr · · Score: 3, Informative

    WareZ engines like astalavista.com

    It is 2007!

    They now say: "Note: Astalavista.com is NOT affiliated with Astalavista.box.sk, there are NO cracks/serials/keygens/warez etc. hosted on the Astalavista.com's server, and never were! Moreover, Astalavista.com is a security site, therefore requests for anything illegal are simply directed to the wrong party, and get ignored immediately!"

    CC.

    --
    TaijiQuan (Huang, 5 loosenings)
  19. Doubleclick could fix this in 2 seconds by oni · · Score: 4, Insightful

    From TFA: The malware looks like a ordinary Flash file, with its redirect function encrypted, so that when publishers upload it, the malware is not detectable.

    All Doubleclick has to do is require the actionscript source code for all ads. There is *no good reason* for an advertiser to hide anything from doubleclick. Send doubleclick your sourcecode. They will compile it into a .swf file. If you don't like that policy, then you can find another distributer for your ads. If your actionscript is so convoluted or obfuscated that doubleclicks programmer can't figure it out, then you can wait in line until the programmer can figure it out, or you can simplify it.

    Problem solved.

    1. Re:Doubleclick could fix this in 2 seconds by elchuppa · · Score: 2, Insightful

      Having the source code doesn't automatically mean you can detect funny business. There can be heavy layers of obfuscation that makes source code just as unreadable.

  20. Yeah sure by gerf · · Score: 2, Insightful

    When you find a company that allows people to use their copyrighted material however they want, and also takes responsibility (monetarily and apologetically both), for their own mistakes, let me know. And they have to still be in business, that is..

  21. Google hole that allows a similar attack by Animats · · Score: 3, Informative

    There's a related hole in Google Maps, an "open redirector", that allows this exploit. Here's an example:

    Caution - hostile URL Close the page displayed; don't click on anything on it. .

    Note that it fools Slashdot, and most link scanners in spam filters, into accepting the URL as leading to "google.com". But, in fact, it redirects to the "malware-scan.com" hostile site, which will try to install an Active-X control.

    We've been finding attacks like this up with SiteTruth, by using PhishTank information to down-rate sites that have open redirectors. We've found open redirectors on Google and AOL. They're actively being exploited.

    So we're currently down-rating Google, and AOL.. It may seem drastic to downrate an entire major site because they have a few "minor" exploits. PhishTank itself only blacklists specific hostile URLs. But that's no longer enough. Most modern phishing attacks use a unique URL, and often a unique subdomain, for each user attacked. SiteTruth thus takes a harder line. If a domain hosts something one of the data sources says is an attack, it downrates the whole domain automatically.

    It's within the power of the site operator to close such security holes. We encourage them to do so.

  22. Re:I only found these ads on.... by gazbo · · Score: 2, Informative
    Oh no, I just assumed that not everybody would be as credulous as the person who made the video. Of COURSE it's not scanning his PC, any more than you're really the 1,000,000th visitor to the webpage. It's nothing more complex than

    window.confirm('Do you want to scan....');window.location.href='http://advert.com/pretend_to_scan.gif';
    And yes, it asks you repeatedly. How is that "directly dangerous?" Annoying, yes (as the OP said), but not directly dangerous (as, once again, the OP said).
  23. chain of responsibility by SuperBanana · · Score: 4, Insightful

    And speaking of "trigger-happy", you seem to point the finger right back at the Web sites for not inspecting the ads and the underlaying code. Well, that's what they hire DoubleClick for,

    And who decided to hire DoubleClick, instead of (as you mention) Google AdSense or a hundred other advertising networks, all of varying reputation, levels of annoying-ness, etc? Who negotiated the terms of the contract, which could have required vetting of ads by Doubleclick? Who had the power to chose between text, GIF, and Flash based ads? Who benefits financially from the presentation of those ads?

    So, again tell me who is responsible for ME getting an infected PC visiting that website? If GM makes a car and the wheel falls off because Bob's Bolts sold them defective bolts, I can still sue GM for selling me a car on the reasonable assumption that GM would test bolts before putting them in a hundred thousand vehicles...and GM made the decision to buy from that particular supplier.

    The way the world works is: I sue GM. GM then sues Bob's Bolts for damages (ie to reputation, the money they had to give me and spend on legal defense, cost of recall, etc.) Bob's Bolts then may sue Smith's Steel for selling them crappy steel.

    Or, in this case: I sue The Economist for infecting my machine. The Economist turns around and sues Doubleclick for providing malicous ads. Doubleclick may then turn around and sue the company that made the malicious ads, for violating the terms of contract with Doubleclick specifying no malicious content...

  24. In Soviet Russia by Scroatzilla · · Score: 2, Funny

    ...the monkey punches you.

  25. Adding insult to disgust to injury... by JRHelgeson · · Score: 5, Insightful

    PayPal has a "Virtual Debit Card" that you can use to access your PayPal account. Prior to downloading the software, you're asked to verify your system requirements. If everything checks out, you can then download and install the software.

    Here's the rub - when you click on the "Download Now" button, it actually sends you to DoubleClick.net site. Then the DoubleClick.net site redirects you back to the PayPal site and starts downloading the application. If you have DoubleClick.net blocked in your hosts file, like I do, then you can't download the software.

    Why?

    It is so that DoubleClick.net can plant a first-party cookie, spy on your activities, direct advertisements to you... PayPal has just submitted ALL your information AND the fact that you use PayPal, AND the fact that you purchase stuff online, AND, AND, AND... Then DoubleClick.net can target you for highly targeted advertisements.

    This is just unconscionable. PayPal deserves all the flame they're gonna get over this one.

    --
    Good security is based upon reality and common sense. Common sense is a function of having common knowledge.
    1. Re:Adding insult to disgust to injury... by JRHelgeson · · Score: 2, Insightful

      True, problem solved. Delete the cookie, no problem.
      My point is that any trust PayPal had was destroyed the moment they redirected my browser... What else are they doing with my financial information?

      --
      Good security is based upon reality and common sense. Common sense is a function of having common knowledge.
  26. Re:I only found these ads on.... by Ron+Bennett · · Score: 3, Insightful

    One should click the "X" to close out such windows - or likely better yet, especially when in doubt, do so via keyboard CTRL-F4 (think that's the combo).

    Anyone who has done some VB programming, etc is well aware that the labels on dialogue boxes can say most anything and be assigned to most anything - problem here is that most Window's users don't know that "Cancel" can be assigned to the same function as "Yes", etc ... don't trust any option shown, use the "X" instead; that's not full-proof either, but much safer than clicking "No", "Cancel", etc.

    Ron

  27. just another reason to go to Linux by rgiskard01 · · Score: 2, Insightful

    Just another reason I am on the Microsoft colonic program!

    Linux Mint
    Firefox
    Adblock Plus
    No Script
    Customize Google
    Safe Cache
    Safe History

    Couldn't be happier with Mint, Open Office, Compiz, Thunderbird, etc.!

  28. Re:Old news.. and a very old problem. by Emetophobe · · Score: 2, Informative

    I clicked on your "not a new problem" link. Avast (free edition) popped up a Trojan warning. What exactly is on that page?

  29. Re:I only found these ads on.... by Metaphorically · · Score: 2, Interesting

    One should click the "X" to close out such windows - or likely better yet, especially when in doubt, do so via keyboard CTRL-F4 (think that's the combo). And why is it that the close button in the corner is special? It may be the safest because normally it isn't hooked but depending on the situation it could be. Windows sends messages to the program whose window is going to be closed. What's more, an application can draw it's own window decorations (like Winamp does, for example) where the corner bit looks like a normal close but isn't.

    Even in a web page, someone can make an image that looks exactly like a default message box on your OS (which can be guessed from the User Agent string) and have every part of that image tied to malicious results.

    btw, yeah, Ctrl-F4 is close for a window (like a message box) and Alt-F4 is close for an application or new browser window.
    --
    more of the same on Twitter.