Slashdot Mirror


Malware Delivered By Yahoo, Fox, Google Ads

WrongSizeGlass writes "CNET is reporting that Avast has tracked over 2.6 million instances of malware that have been served up to unsuspecting web surfers since last December by ad services such as Yahoo's Yield Manager, Fox Audience Network's Fimserve.com and even some from Google's DoubleClick. Some high-profile sites include The New York Times, Drudge Report.com, TechCrunch and WhitePages.com. The practice has been dubbed 'malvertising.' I usually suspect the users of 'careless web activity' when I delouse a PC, but now I'm going to have to give some the benefit of the doubt."

21 of 319 comments (clear)

  1. Surprise! Oh, wait... by bhamlin · · Score: 2, Insightful

    Really, who is surprised by this? What's the cost of an ad and fake credentials compared to getting a chance to infect millions of computers?

  2. Re:Say No To Flash by somersault · · Score: 4, Insightful

    Say no to unsolicited content altogether! Adblockers ftw.

    --
    which is totally what she said
  3. Adblockers anyone by Galestar · · Score: 4, Insightful

    Yet another reason to use ad blockers. I'm starting to think Firefox should come with it out of the box.

    --
    AccountKiller
    1. Re:Adblockers anyone by Monkeedude1212 · · Score: 3, Insightful

      The problem is that a large amount of money on the internet is made through advertisements. If Firefox gains marketshare, and starts with adblocking, thats tons of revenue stream being cut off. Google makes a lot of money through advertising, and they seem to be the only ones pushing for progress right now. I don't know if I'd want to go and reduce their income.

      In Alberta - it's illegal to have a billboard on a Highway. Based solely on the idea that it causes more accidents because billboards are distracting. This isn't a direct attack on the speed limit, a major factor, or Alchohol, another major factor. Because attempting to control those other 2 factors would cause a huge upset.

      Same with internet advertising, you can't just stop it all and make the world a better place.

  4. Re:Yup....seen it. by tivoKlr · · Score: 5, Insightful

    Having been an IT admin in my former life, and also having operated in a similar fashion to you, allowing unfettered access to the internet for our employees (it was a Fire Department, and the staff was there for 48 hrs straight, so allowing them some creature comforts such as facebook and youtube was appreciated). Having solid, centrally managed AV on each client machine, along with limited local user rights seemed to be effective.

    I wish more facilities would take this tact instead of letting some firewall with a blacklist subscription slowly narrow the available internet to static sites that are considered "safe." True irony that advertising from some of these safe sites are now delivering payloads. Ironically, where I work now (not in IT), plenty of popup ads from news sites make it through, so I would assume we're vulnerable through this vector.

    --
    Ocean is land, covered with water.
  5. Adblocker by wisnoskij · · Score: 4, Insightful

    I would like to support sites by viewing their ads but if it leaves you more open to viruses even on high-profile sites then it is not worth the risk.

    --
    Troll is not a replacement for I disagree.
  6. Re:Much more profitable than click-throughs... by julesh · · Score: 2, Insightful

    1) Flash-based Banner Ad
    2) JRE Exploit (CVE-2008-5353)
    3) Adobe Reader Exploit
    4) Profit?

    From what I saw when this happened to me:

    1) Javascript-based banner ad
    2) MFSA2010-01 (or something similar that was present in Firefox 3.5.7)
    3) Mozilla extension to redirect links from google, yahoo and bing to a site of your choice
    4) Site that serves large numbers of per-impression banners for dubious porn sites
    5) Profit.

  7. Ars Technica by Anonymous Coward · · Score: 5, Insightful

    And Ars Technica says I shouldn't block ads.

    I repeatedly told their staff that I don't block Ars Technica, but I do block ad servers. If they want to send me ads let them server them from their own domain.

    Sites resposible for ad-vectored infections should be hit with hundreds of small claims court lawsuits to recoup the costs to clean up the infections.

    Maybe then they'll learn.

  8. 'careless web activity' by John+Hasler · · Score: 3, Insightful

    > I usually suspect the users of 'careless web activity' when I delouse a PC...

    They are guilty of 'careless web activity': not blocking ads.

    --
    Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
  9. Re:Yup....seen it. by Em+Emalb · · Score: 4, Insightful

    Obviously, the biggest hurdle we're having to deal with is user education. I've got a select few folks in various departments learning to work with ad-block and no script, but for the average person, it's hard to figure out what they need to unblock and what they can block with no ill effects. It's frustrating to them, and by extension, our helpdesk guys who end up fielding calls from the same people (over and over) with the same questions. Of course, the other issue we have is vendor lock in, with their stupid sites working correctly ONLY in IE. I hate that, but in my case (financial industry) it's so rampant there's nothing we can do about it except lock stuff down as best we can.

    That said...these large companies that aren't paying attention to the ads their serving are just as at fault as any un-educated (or even educated) user is.

    --
    Sent from your iPad.
  10. Re:One lesson to learn by Anonymous Coward · · Score: 1, Insightful

    Two pieces:

    Ad blocking hosts file

    Flashblock

    Web browsing just got a whole lot faster.

  11. Make the Ads Safe by The+Angry+Mick · · Score: 4, Insightful

    I would like to support sites by viewing their ads but if it leaves you more open to viruses even on high-profile sites then it is not worth the risk.

    Very good point, especially in light of Ars Technica's recent plea to users to stop blocking ads.

    I, too, would be than more willing to disable the protective measures I've got in place, but as long as these sites rely on third party advertisers that are more concerned with eyeball collection than system security, we have a stalemate. If sites want me to see their ads, they have the burden of making sure the ads are safe (less annoying, would also be good). If I lower my guard out of "friendship" for a site, only to get a drive by download as a reward, I'm going to take it as a major breech of trust.

    --

    I'm not tense. I'm just terribly, terribly, alert.

  12. Re:Yup....seen it. by ShadowRangerRIT · · Score: 2, Insightful

    Ouch. The two news sites I browse most often. Good thing I run AdBlock and NoScript, and I wrote myself a Greasemonkey script to rewrite all the internal links to point to the print-friendly (read: ad-free) versions of the articles.

    --
    $_ = "wftedskaebjgdpjgidbsmnjgcdwatb"; tr/a-z/oh, turtleneck Phrase Jar!/; print
  13. Makes it hard to meet them halfway by MikeRT · · Score: 3, Insightful

    They complain about advertising revenues while they are serving up ads that contain malware. To someone who hates ads to begin with, that's like saying "we know you don't enjoy crawling over broken glass, so how about crawling over glass mixed with AIDS-infected blood and barbed wire?"

  14. Re:ORLY? by John+Hasler · · Score: 2, Insightful

    Why don't you think that the top tier services should be held responsible for the results of their daisy-chaining? They got paid for handing you off.

    --
    Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
  15. Re:Yup....seen it. by Victor_0x53h · · Score: 3, Insightful

    I believe using TeaTimer would teach the average user to constantly click "Yes" without thought. As mentioned before this kind of security has a huge education barrier. I haven't run with TeaTimer since it was first introduced with Spybot, but my experience was pretty awful being prompted anytime anything was run.

    Also if TeaTimer prevents changes to the registry prompted by some piece of crapware, said crapware has already been executed. What else has it done; how much protection does blocking changes to the registry really provide?

  16. Re:One lesson to learn by commodore64_love · · Score: 3, Insightful

    Yes becasue it is an established fact that Fox has no bias

    STRAWMAN ARGUMENT. I never said that. What I said was that CNN, MSNBC, ABC, CBS, et cetera have a pro-government and anti-individual-liberty bias.

    Point - They are ALL biased, therefore if you're going to attack FOX for bias, then you should be attacking all the TV media outlets for the same reason.

    --
    "I disapprove of what you say, but I will defend to the death your right to say it." - historian Evelyn Beatrice Hall
  17. Ad CDNs have been a nightmare by Coopjust · · Score: 3, Insightful

    Two weeks ago, someone asked me to reinstall Windows XP for them. Their disk was XP SP3.

    I reinstall, and open IE to visit Windows Update

    Instantly, I get a Vundo variant from a malicious ad attacking the out-of-date Flash Player that came with XP that installs without any user intervention whatsoever.

    This only served to reinforce that I was right and not a webmaster/free content hating jerk when I block ads online.

  18. Re:The real defense line by ShadowRangerRIT · · Score: 2, Insightful

    Well, the browser can lower its own privileges just fine. IE8 (and IE7 IIRC) run with lower privileges than a normal user for that reason. Even if you tell it to execute as admin, it programmatically lowers its privileges at runtime.

    --
    $_ = "wftedskaebjgdpjgidbsmnjgcdwatb"; tr/a-z/oh, turtleneck Phrase Jar!/; print
  19. Re:Why I don't run ads by Seedy2 · · Score: 3, Insightful

    I saw the word "malvertising" and thought it was redundant. I have always considered ALL advertising to be malware. Including print and TV advertising. They are all an attempt to force me to view their message, which I neither want nor asked for, and block or delay me viewing what I want to see.

    --
    Nothing to say here... move along
  20. Remind me by sjames · · Score: 3, Insightful

    Why is it somehow un-ethical to block ads again?

    Perhaps it's a good idea for big sites with a reputation to maintain to borrow just a bit from the old model where they sell ad space with an approval process directly to advertisers and serve the images from their own servers.