Slashdot Mirror


Hackers Use Banner Ads on Major Sites to Hijack Your PC

The worst-case scenario used to be that online ads are pesky, memory-draining distractions. But a new batch of banner ads is much more sinister: They hijack personal computers and bully users until they agree to buy antivirus software. And the ads do their dirty work even if you don't click on them.The malware-spiked ads have been spotted on various legitimate websites, ranging from the British magazine The Economist to baseball's MLB.com to the Canada.com news portal. Hackers are using deceptive practices and tricky Flash programming to get their ads onto legitimate sites by way of DoubleClick's DART program. Web publishers use the DoubleClick-hosted platform to manage advertising inventory." CT: Link updated to original source instead of plagerizer.

10 of 268 comments (clear)

  1. oh great by deftones_325 · · Score: 5, Funny

    So now I need to buy penis-enlargment pills AND and anti-virus.

    --
    "A gentleman never strikes a lady with his hat on." - Fred Allen
    1. Re:oh great by FuzzyDaddy · · Score: 5, Funny

      Yes, those two things often go together.

      --
      It's not wasting time, I'm educating myself.
  2. What are these "ads" you're talking about ? by galaad2 · · Score: 5, Insightful

    That's why Firefox+NoScript+AdBlock Plus+Flashblock were invented

    --
    root@127.0.0.1
  3. AdBlock and NoScript by Timinithis · · Score: 5, Interesting

    I use these exclusively, are there reports that this method gets by them? I know that if the ad is blocked, it isn't downloaded, but is that all it takes, download the ad and you have the virus?

    Sounds like a reason to just block all double-click items...

    I don't enable flash/scripts on any page unless it is needed -- like scripts for /.

    --
    Sig? What's a Sig?
  4. TFA = Site scraping? by Anonymous Coward · · Score: 5, Informative

    The flibby link is identical to this Wired blog post by Betsy Schiffman, dated four days earlier.

  5. Your company/family/school by KiloByte · · Score: 5, Interesting

    Right, we all use Adblock and the like. Yet, you can't force everyone in the vicinity to do so, there are lesser minds who opt for Opera, and there's even a tiny portion of giants on Links -- and let's not even mention how low SOME folks can fall.

    I would say that adzapper (if you use squid) or a DNS-based blacklist is quite mandatory wherever you do have a say. Glancing at the logs of ISPs I have root at, roughly 1/4 of all freaking http requests go to lowlifes -- and even that based on my grossly incomplete list of ad/spyware/tracking scum.

    Yeah, 25%. That's horrible.
    And there are some customers dumb enough to complain if you do protect them from ads, so you can't do this in an ISP scenario. But in a company, school or family? Hell yeah, there's no reason for doubleclick.com to get through, ever.

    --
    The creatures outside looked from Alt-Right to Antifa; but already it was impossible to say which was which.
  6. Not exactly new by Anonymous Coward · · Score: 5, Informative

    This has been going on since flash 8 was released with a vulnerability. I got hit by this about a year ago, maybe a little more.

      Suddenly windows security center, that I routinely turn off because I can't stand the nagging, started up and told me that my computer was insecure and that I should go to a certain website and buy their virus defender software.

    Not very subtle to a savvy person like myself, but I imagine some people would fall for it.

    The box also started throwing up connection error message boxes, presumably because my external firewall were blocking outgoing connection attempts. Again not subtle, but it's an uncommon setup for a home user.

    Third, it must have rooted the box somehow because certain files became invisible. "test.exe" among them. Renaming a textfile to text.exe would make it disappear, and the folder would be unremovable. Cygwin came to the rescue there. Also I noticed only because I happened to have lots of little crap programs laying around.

    The virus scanners did not pick up on this.

    This is the only time I have actually contracted a virus. Needless to say I hosed the box (PING is not disk image). What I learned from the experience is that knowing your system is way more effective than a virus scanner, and B) don't trust flash which is how I got the damn thing. I thought I was safe with firefox.

  7. Re:Never Experienced This by doombringerltx · · Score: 5, Funny

    3) How did YouTube decide that "ridiculously hot LATINA girl dancing, not asian!" is a Related Video? Except in the sense that it's always relevant, I mean. Finally a reason to RTFA
  8. Re:I only found these ads on.... by morgan_greywolf · · Score: 5, Informative

    BTW these ads are not directly dangerous unless you are running on some old browser/old Windows system, but yes, they are annoying as hell. Um, wrong. Watch the video. The guy is running Windows XP SP 2.
  9. Adding insult to disgust to injury... by JRHelgeson · · Score: 5, Insightful

    PayPal has a "Virtual Debit Card" that you can use to access your PayPal account. Prior to downloading the software, you're asked to verify your system requirements. If everything checks out, you can then download and install the software.

    Here's the rub - when you click on the "Download Now" button, it actually sends you to DoubleClick.net site. Then the DoubleClick.net site redirects you back to the PayPal site and starts downloading the application. If you have DoubleClick.net blocked in your hosts file, like I do, then you can't download the software.

    Why?

    It is so that DoubleClick.net can plant a first-party cookie, spy on your activities, direct advertisements to you... PayPal has just submitted ALL your information AND the fact that you use PayPal, AND the fact that you purchase stuff online, AND, AND, AND... Then DoubleClick.net can target you for highly targeted advertisements.

    This is just unconscionable. PayPal deserves all the flame they're gonna get over this one.

    --
    Good security is based upon reality and common sense. Common sense is a function of having common knowledge.