Slashdot Mirror


Yahoo Advertising Serves Up Malware For Thousands

wjcofkc writes "Thousands of users have been affected by malicious advertisements served by ads.yahoo.com. The attack, which lasted several days, exploited vulnerabilities in Java and installed malware. The Netherlands based Fox-IT estimates that the infection rate was at about 27,000 infections per hour. In response to the breach in security, Yahoo issued the following statement, 'At Yahoo, we take the safety and privacy of our users seriously. We recently identified an ad designed to spread malware to some of our users. We immediately removed it and will continue to monitor and block any ads being used for this activity.' While the source of the attack remains unknown, Fox-IT says it appears to be 'financially motivated.' The Washington Post cites this incident as a reminder that Java has become an Internet security menace."

184 comments

  1. Become? by gstoddart · · Score: 5, Insightful

    The Washington Post cites this incident as a reminder that Java has become an Internet security menace.

    As far as I've been concerned, Java and Javascript have both always been security menaces.

    Letting web-sites and advertisers execute code has been a recipe for problems for a long time, which is why many of us here likely already block it.

    This is just another example of why we can't trust the companies doing the advertising, because they're part of the problem -- if Yahoo is serving malware, Yahoo can't be trusted.

    --
    Lost at C:>. Found at C.
    1. Re:Become? by Nerdfest · · Score: 4, Insightful

      Java as a language is pretty much as secure as any other. Allowing it to run arbitrary code as 'applets' by default is a huge problem as the sandboxing seems quite poor.

    2. Re:Become? by gstoddart · · Score: 0

      oh oh, I forgot, Google can do no evil

      No, you're a fucking idiot.

      The story is about Yahoo, so that is who I mentioned. I don't trust Google either (or any other advertiser for that matter).

      Just because an advertiser accepts money to serve ads, doesn't mean I have any trust in the people actually serving the ads, and I sure as hell don't let them run scripts. Not ever.

      --
      Lost at C:>. Found at C.
    3. Re:Become? by gstoddart · · Score: 4, Insightful

      Java as a language is pretty much as secure as any other.

      In the abstract, as a standalone app, sure.

      But on the web? No bloody way. Certainly not by default -- because it's always been a vector from annoying crap and malware.

      --
      Lost at C:>. Found at C.
    4. Re:Become? by Nerdfest · · Score: 4, Insightful

      Any other language deployed the same way would offer a very similar attack surface. Simply put, it's the new ActiveX.

    5. Re:Become? by Anonymous Coward · · Score: 0

      A tag to disable active content was proposed more than ten years ago. http://lists.w3.org/Archives/Public/www-html/2002May/0021.html

      Mozilla proposed CSP some years later: https://wiki.mozilla.org/index.php?title=Security/CSP/Spec&oldid=133465

      If this sort of thing was widely implemented this malware thing might have been easily blocked - apparently the malware ads didn't require the victim to click! And many of those XSS worms in the past might not have spread.

      But nobody really cares about security.

    6. Re:Become? by gstoddart · · Score: 4, Informative

      Yup, didn't trust that either.

      NoScript, AdBlockPlus, Ghostery, ScriptSafe, and everything else you can find to keep the crap at bay is the only safe way to use the internet these days.

      Between advertising companies who feel entitled to your data, and all of the crap on the internet ... leaving that stuff on by default is just asking for problems.

      --
      Lost at C:>. Found at C.
    7. Re:Become? by Nerdfest · · Score: 4, Interesting

      RequestPolicy for FireFox is great as well.

    8. Re:Become? by Z00L00K · · Score: 2

      Almost all ads are malicious in one way or another. If they don't carry bad stuff to your computer you can be misled to click on them and $DIETY knows where you end up sometimes. If nothing else they burn a lot of CPU ticks and makes your computer consume more power.

      --
      If builders built buildings the way programmers wrote programs, then the first woodpecker would destroy civilization.
    9. Re:Become? by ColdWetDog · · Score: 4, Funny

      Those blank white screens are refreshingly calm.

      --
      Faster! Faster! Faster would be better!
    10. Re:Become? by Arker · · Score: 2

      I know, this is how I do it too, but doesnt it strike you as a little crazy to have to install all these *extensions* - not to add optional functionality, but to disable all this insanity that should never have been enabled by default to begin with?

      Web browsers should ship with support for the web (that means HTML, semantic markup, period) and extensions should be used to add to that, rather than by default supporting every piece of nonsense any adware/spyware/malware pusher might ever want to use, and then having extensions to try and turn that off after the fact.

      --
      =-=-=-=-=-=-=-=-=-=-=-=-=-=-
      Friends don't let friends enable ecmascript.
    11. Re:Become? by Anonymous Coward · · Score: 0

      Advertising companies do not 'feel entitled to your data'. The sites you visit feel entitled to give your information away to the highest bidder - in exchange for the free use of the site. Advertisers and ad networks are not the problem, the policies of the sites you visit are the problem. The data your browser sends to the sites you visit is available to the highest bidder, some of the data is available to all possible bidders.

      I can safely assume that you do not like my post. Want to the third party advertising networks that track you to go away? Then start paying for all of the sites you visit - give the site operators a way to make money that does not involve contracting with Advertisers or ad networks.

      You get paid a salary or hourly wage or contract rate because someone values you work. At the same time, you expect web sites to be free. How do you propose that the folks that produce those sites get paid, paid just like you are for your work?

      I use ad and script blockers too but I don't blame the advertisers for needing it, I blame the sites that sold me out.

    12. Re:Become? by Lennie · · Score: 1

      Java exploits, sure. Or plugins in general really.

      But Javascript ? How many Javascript exploits have you see that infect the browser or the host ?

      I do see Javascript being used to 'deliver' or 'bootstrap' many exploits though.

      --
      New things are always on the horizon
    13. Re:Become? by Anonymous Coward · · Score: 0

      That's exactly what GP meant by the following:

      Allowing it to run arbitrary code as 'applets' by default is a huge problem as the sandboxing seems quite poor.

    14. Re:Become? by Anonymous Coward · · Score: 2, Funny

      Almost all ads are malicious in one way or another.

      They may even trick you into buying stuff you don't need.

    15. Re:Become? by Anonymous Coward · · Score: 0

      I remember at least one notable instance: TOR Browser bundle's Firefox had an unpatched JS vulnerability allowing arbitrary code execution.

      It was used at least once, to make all Freedom Hosting hosted sites serve a piece of code to ping back to FBI from visitors' real IP addresses. Google for "freedom hosting takedown" for more details.

    16. Re:Become? by hairyfeet · · Score: 2

      They can bitch about "Waaah how can we make money on our websites, waah" but since I started making adblock plus mandatory? The rate of customers bringing PCs back infected has dropped right off the map.

      I USED to allow websites who asked nicely to have an exception but I found they abused the goodwill every. single. time. without fail. I consider an ad to be unacceptable if 1.- Its served by flash, too many zero days for flash to allow it s a delivery vehicle. 2.- No Java, see rule 1. 3.- NO THIRD PARTIES, this is a sticking point for some but it really comes down to responsibility. If you use some fly by night third party you can pass the blame and in reality you have no damned clue from minute to minute what is even running on your site when you give space to third parties. YOU might tell your readers "Oh we won't use flash or java for ads" but do you think the third party will care about your pledge? Not a chance.

      Until sites come up with a way to serve ads without cranking up the risk to my customers? they can fuck right off. Your "right" to make a living of your dumb ass blog does NOT trump my customers right to have a virus free PC and considering what a nightmare ID theft is I feel zero guilt for blocking your malware spewing third party flash crap. Even Ars Technica, who made a big deal about begging and making their case for unblocking....what did they do with 3 days of me unblocking? they broke rules 1 and 3, showing their ads to be just as dangerous as anybody else. So there will be no exceptions and I'll be happily spreading ABP to everyone who brings a PC through my door.

      --
      ACs don't waste your time replying, your posts are never seen by me.
    17. Re:Become? by afgam28 · · Score: 1

      "In the abstract"?! In what world do you live in where standalone, server-side Java and Android apps are rare?

      In the abstract, Java applets are a problem, sure. But by far most Java code runs on servers and on Android devices and there isn't as much of a problem with poor sandboxing in those environments.

    18. Re:Become? by gstoddart · · Score: 1

      You know, I don't find there to be many sites I actually want to use that don't get by mostly without allowing scripts and the tracking shit.

      --
      Lost at C:>. Found at C.
    19. Re:Become? by Darinbob · · Score: 1

      Which is ironic since one of its principle design goals, that set it apart from being yet-another-language, was emphasis on sandbox security. But then features crept in...

    20. Re:Become? by easyTree · · Score: 1

      I know, this is how I do it too, but doesnt it strike you as a little crazy to have to install all these *extensions* - not to add optional functionality, but to disable all this insanity that should never have been enabled by default to begin with?

      I know; it's almost as if you've completely misunderstood what *insanity* and *should* mean which has led you to erroneous conclusions.

      javaScript is *useful* - its presence in browsers indicates that on balance, is benefits are considered to outweigh the risks it creates / allows.
      knives are useful - their presence in the world indicates that on balance, their benefits are considered to outweigh the risks they create / allow.

    21. Re:Become? by Anonymous Coward · · Score: 0

      This. Javascript itself doesn't have access to the system, it can't save and launch an executable like Java can. The most it can do on its own is make the browser hang.

    22. Re:Become? by Anonymous Coward · · Score: 1

      Personally I use
      1. AdBlock Edge which is a fork of AdBlock Plus(No ads. Ever. From anyone. For any reason)
      1a. Element Hiding Helper for AdBlockPlus (Also works with AdBlock Edge and can remove individual elements of a website)
      2. Noscript (All security conscious people ought to know this one)
      3. Ghostery (with auto-update which is bizarrely not default)
      4. Self-Destructing Cookies (kills ALL cookies. No exceptions. So what if I have to type my email address a few times.)

      If you have more then post them here.

    23. Re:Become? by fast+turtle · · Score: 1

      and this is exactly why I use a god damn hosts file to block most of the fucking advertisers. It's not perfect by a long shot but it certainly helps prevent much of the problem by blocking any connection to known ad-servers like Yahoo's that can and will be compromised. Hell even Doubleclick has served malware in the past and I've blocked them for over a decade in the hosts file (Remember those god damn "Punch the Monkey" ads?) that's what got me started on using the hosts file and the really nice thing about it is the solution is cross platform. I've used it on Linux and Windows and even gave a copy to a friend using a Mac. Worked like a charm for them.

      Where in hell is APK when you need him? Lazy fucking bum. Get back to work and earn your money.

      --
      Mod me up/Mod me down: I wont frown as I've no crown
    24. Re:Become? by exomondo · · Score: 1

      Web browsers should ship with support for the web (that means HTML, semantic markup, period) and extensions should be used to add to that, rather than by default supporting every piece of nonsense any adware/spyware/malware pusher might ever want to use, and then having extensions to try and turn that off after the fact.

      So fork Firefox or Chromium or build a browser atop webkit and offer such a thing. Nothing stopping you from doing it if you really think that's the way it should be.

    25. Re:Become? by exomondo · · Score: 1

      Almost all ads are malicious in one way or another. If they don't carry bad stuff to your computer you can be misled to click on them and $DIETY knows where you end up sometimes. If nothing else they burn a lot of CPU ticks and makes your computer consume more power.

      Yeah displaying a link and a one-sentence blurb is really burning a lot of CPU clocks and making my computer consume more power.

    26. Re:Become? by hairyfeet · · Score: 2

      Insightful? Really mods? We ARE talking about Java ya know, a language run by company that infests its customers with shit like the Ask toolbar when they update the thing.

      And if what you are saying is true Nerdfest, where is all the C attacks? Obj-C? Visual C++? Hell that last one is probably on more machines than even Java as pretty much every Windows box that has play a stand alone game in the last 5 years has had to install VC++.

      Like it or not you hit closer to home than you think with the Active-X comparison, because like Active-X Java is frankly not very good at security. It was written by Sun who wrote shitty code, see the mess that is Open Office for an example, and when Oracle bought it they certainly didn't raise the quality level of the code. There is a reason why you see more people with VC++ or with Chrome browsers yet Java is the one targeted, crooks always good for the easy mark.

      --
      ACs don't waste your time replying, your posts are never seen by me.
    27. Re:Become? by Sudline · · Score: 1

      And we should pay for each website we visit.

    28. Re:Become? by dinfinity · · Score: 1

      Actually, if you use Chrome, ScriptSafe can be set to allow Javascript for the domain you're visiting. This still negates a lot of the security risks, yet allows most of the functionality to work for properly programmed websites, without further interaction.
      The only annoyances are having to whitelist scripts from affiliated domains or domains that provide useful external features such as Youtube or Disqus, especially when they trigger a cascade of script inclusions.

      When some website refuses to function properly without (temporarily) whitelisting all their crap, I either stop caring about the content or accept the risk and fire up Firefox (where no Javascript blocking occurs).

    29. Re:Become? by cbhacking · · Score: 1

      Um, what's the difference? If I find, say, a user-after-free vulnerability in a JavaScript runtime (these have been found, and exploited, in the past) and use it overwrite an objects function table with arbitrary code (by, say, creating a long JavaScript string that contains the hex-encoded values of the machine cade that I want to execute) and then calling a function on the overwritten object to gain arbitrary code execution... is that not actually a JavaScript exploit for some reason? Did I merely use JS to "deliver" the exploit in a way that is different from exploiting a vulnerability in the Java applet sandbox?

      --
      There's no place I could be, since I've found Serenity...
    30. Re:Become? by Anonymous Coward · · Score: 0

      5. BetterPrivacy

    31. Re:Become? by TheRaven64 · · Score: 1

      ActiveX made no attempt at sandboxing. Java does, but the problem is a monoculture. There are four JavaScript implementations in widespread use, and so if you want to exploit a vulnerability in JavaScript you won't get more than one browser. Exploitable JavaScript bugs tend to be partly due to the DOM and other components of the browser. In Java, there is one widely deployed JVM, including all of the supporting libraries. If you find a bug in it, then you can exploit anyone who still has the Java plugin installed. The same is true of Flash.

      --
      I am TheRaven on Soylent News
    32. Re:Become? by TheRaven64 · · Score: 1

      How many Javascript exploits have you see that infect the browser or the host ?

      Last time I did a CVE search, I found about 20 within the six months prior to when I did the search, across a small handful of browsers. I haven't looked for a few months though, so maybe there's been a miraculous improvement recently.

      --
      I am TheRaven on Soylent News
    33. Re:Become? by Anonymous Coward · · Score: 0

      yeah, obviously a reminder that yahoo can't trusted, if anything.

    34. Re:Become? by Billly+Gates · · Score: 1

      Yes

      Java was great and well written at the time in the 1990s. Bare in mind people had Pentium 166's and 28k modems and ran crappy browsers like Netscape back when the opinion of java being slow was ingrainded. A standard cpu today is probably a good 100x - 200x faster.

      It is dated now true and Oracle is the one who put Ask crapware. But Java at least has a sandbox unlike VC?! Of course it has not been updated until recently but it is there and it worked until the last couple of years.

      Java executes code but so does any other language. So does any other language that is more bare metal than interpreters like JavaScript. The problem is code execution without the user doing anything. Terrible idea!! Even reader has logic in it so it also executes code hence security issues with that too.

      ActiveX has no sandboxing at all. However, it does have signed applets default in IE 6 and higher which make running untrusted code harder but still these should not be in a browser.

      VC++ is not as safe as Java and would be a fucking disaster. I wished Java could have turned into something more and came more up to date. Oracle is trying but slowly as Java 8 will have things C# had since 2005 with Lambda. Still no LinQ like functionality. Java is a classic example of a great technology left to be bad management. The fact it is so and still widely used showed it was certainly not a crappy product and was cutting edge and is still modern even today even if its sandboxing is lacking.

    35. Re:Become? by Anonymous Coward · · Score: 0

      Back in 2000 sites with applets/javascript running were seen as insecure and sites with large volumes of traffic would not use them.

    36. Re:Become? by Anonymous Coward · · Score: 0

      The best way to not get any of this malware ofcourse is to use Lynx. Or my preferred way is to not use the browser for any pages that don't start with an IP of 127.0.0.1

    37. Re:Become? by DarwinSurvivor · · Score: 1

      For the amount of money Yahoo is being paid to serve these adds, they should be heavily reviewing any that are anything more than an image with a link.

    38. Re:Become? by DarwinSurvivor · · Score: 1

      Not quite. Javascript can also make outgoing connections. There used to be a lot of attacks that used javascript to connect to machine on your side of the router (or even local ports). Browser developers have been working on closing these for a while now, but they haven't fixed them all yet.

  2. The usual platitudes and bullshyte promises by stevez67 · · Score: 3

    They'll continue to monitor, as in do something about a malicious ad once someone else identifies it and spreads the word.

  3. Slashdot Serves Up Epic Fail Beta by Anonymous Coward · · Score: 3, Funny

    Hey samzenpus, you better have another job lined up.

    Netcraft confirms http://beta.slashdot.org is dying!

    1. Re: Slashdot Serves Up Epic Fail Beta by Anonymous Coward · · Score: 3

      It does seem to be dying. I used to come one here several times a day. Now I might come by once a week. Mostly hoping the old site would reappear. Sad watching a once great site die.

    2. Re: Slashdot Serves Up Epic Fail Beta by Nerdfest · · Score: 1

      I just had a look at it. It doesn't look awful, but continues the same mistake made with other attempts, in that it has *way* the hell too much white space.

    3. Re: Slashdot Serves Up Epic Fail Beta by Anonymous Coward · · Score: 1

      Don't you know you're not supposed to use a PC on the net any more? It's strictly for tablets and phones -- tiny screens, most options removed, no keyboard support. Get out of the stone age and stop being productive!

    4. Re:Slashdot Serves Up Epic Fail Beta by Kimomaru · · Score: 2

      It looks fine, but it's too fancy for my taste. Personally, when a someone tries to doll up a site to make it prettier, it always kind of irks me. It feels like it's losing its quality, so they have to compensate by making it prettier. I'm sure that's not the case here, but let's drop this redesign stuff. Unless you make it easier to navigate with a text-based browser.

    5. Re:Slashdot Serves Up Epic Fail Beta by ConceptJunkie · · Score: 1

      But beta.slashdot.org serves you tons of stock photos. A stock photo for every story! That's what made /. great: meaningless images.

      --
      You are in a maze of twisty little passages, all alike.
    6. Re: Slashdot Serves Up Epic Fail Beta by Anonymous Coward · · Score: 0

      Here's hoping that http://classic.slashdot.org will be long-lived.

  4. Image/text only ads by El_Muerte_TDS · · Score: 5, Insightful

    This wouldn't be an issue if they could only serve image or text only ads. Possible image based exploits can easily be prevented by re-saving the uploaded image so that the image only contains valid content.

    But no, ad farms want to provide functionality to reach maximum annoyance for the users. You can blame Java all you want, but it's not the source of this problem.

    1. Re:Image/text only ads by Anonymous Coward · · Score: 4, Insightful

      Indeed, the ad ops teams that "screen" these ads cant read code, and even if they could, the code in the ad tags is "minified" JS and they just can't logistically read each ad tag because of the sheen number of ads they need to run each day/week.

      If Java didn't exist, nor Flash or Acrobat, these criminals would STILL be using the ad networks to compromise the browser itself. That's not to say the plugin model is a good one, but it's important to focus on the real problem.

      This is true for all websites too. I suspect the WashPo uses the same ad ops standards Yahoo does, same as Slashdot, same as everyone. It's ad networks running arbitrary, 3rd-party, unknown code on users machines that's really fucking dangerous.

    2. Re:Image/text only ads by SpaceLifeForm · · Score: 3, Interesting

      Ask yourself this: How many ad farms are really NSA operations?

      --
      You are being MICROattacked, from various angles, in a SOFT manner.
    3. Re:Image/text only ads by digitalaudiorock · · Score: 3, Interesting

      I use NoScript all the time. Just recently...the last few week actually...I started noticing that a number of things on yahoo finance just plain stopped working because they required javascript from yimg.com...as if I'm going to allow that...ffs.

    4. Re:Image/text only ads by Anonymous Coward · · Score: 0

      In my experience working with two teams, a small fraction of ad ops people can read and understand javascript. That same fraction applied to the subset of ad ops folks could actually identify malicious activity in the javascript. And 0 of them would attempt to fix it in any case, as opposed to reporting it to the ad service. Granted I have not seen ad ops identify javascript based ad-driven malware, so I can't actually guess at that approximately.

    5. Re:Image/text only ads by Ol+Olsoc · · Score: 2

      I use NoScript all the time. Just recently...the last few week actually...I started noticing that a number of things on yahoo finance just plain stopped working because they required javascript from yimg.com...as if I'm going to allow that...ffs.

      Last few weeks? You're lucky.

      I did a script check on aoms sites recently. just kept enabling them until the sites worked. Ones like the New York Times had dozens of scripts that had to be enabled just to see the content. Yahoo is bad enough, but no where near the worst. They really do want you to allow facebook in order to see or comment.

      And thtat's the interesting part. Facebook and twitter - and of course Google in one form or another are tracking you even if you've never been to the respective sites.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    6. Re:Image/text only ads by Anonymous Coward · · Score: 0

      And thtat's the interesting part. Facebook and twitter - and of course Google in one form or another are tracking you even if you've never been to the respective sites.

      That's why you should use Ghostery and/or RequestPolicy. Unfortunately, Google hosts Javascript libraries, and can track you when you allow a page to load those necessary libraries from Google. Hmmm... it seems like one could write a proxy/browser extension that would cache those libraries locally instead of querying Google for them...

    7. Re:Image/text only ads by Ol+Olsoc · · Score: 1

      Wasn't there something posted in here a few months ago about spoofing tracking reports? It might be fun to have google think the whole world only visited Goatse and tubgirl.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    8. Re:Image/text only ads by Anarchduke · · Score: 1

      it appears yimg.com is owned by https://www.markmonitor.com/
      Not sure exactly what markmonitor does, even though it says they do "brand protection" I just downloaded one of markmonitors white pages to try and figure it out.

      --
      who prays for Satan? Who in 18 centuries has had the humanity to pray for the 1 sinner that needed it most? ~Mark Twain
    9. Re:Image/text only ads by Anonymous Coward · · Score: 0

      If they can read the code and prove it's fine, they would have solved the halting problem.

      The solution is stuff like CSP (or the "disable active stuff" tag I proposed). Which is like working around the halting problem by forcing stuff to halt whether or not the code halts or not.

      Apparently the exploit didn't require users to click on stuff to get redirected. If you do the CSP or similar tech stuff right, Yahoo would be able to limit ads to only do certain things - and autoredirect/meta refresh stuff would be disabled.

      The situation with HTML now is stupid - it's like a car with thousands of "Go" pedals and not a single "Brake/Stop" pedal, to stop you have to make sure all of the "Go" pedals are not pressed! And people like the W3C are busy making more "Go" pedals every year.

      A "Stop" pedal will help when the clowns in the W3C release new ways to get pwned. If the "Stop" pedal is at "100%" the browser would see it and those new ways won't be active whatever they are. You don't need to update any escaping library, and you don't have to worry so much about different browsers parsing things differently (and thus have to escape things differently depending on what browser it is). Once the browser sees the equivalent of "Only static image and text allowed in this frame/between these tags" then it's a bug in the browser if active stuff is allowed.

  5. Source Unknown? by Anonymous Coward · · Score: 5, Interesting

    Source unknown? Bullshit! Yahoo didn't run the ads without payment. Payment == traceable. Or is Yahoo accepting Bitcoins now?

    1. Re:Source Unknown? by KingOfBLASH · · Score: 2

      No they're just going to blame the NSA for being malicious hackers, and skip over taking any sort of responsibility for the situation.

    2. Re:Source Unknown? by hawguy · · Score: 2

      Source unknown? Bullshit! Yahoo didn't run the ads without payment. Payment == traceable. Or is Yahoo accepting Bitcoins now?

      Unless, of course, payment==stolen credit card number.

    3. Re:Source Unknown? by Anonymous Coward · · Score: 0

      Actually, you are wrong. There is tons of reselling going on and every entity in the chain has plausible deny-ability. Also, the payments are not instantant but aggregated each month. I'm sure yahoo serves billions of ads a month, even a big malware incident like this is a small fraction of total traffic. It is harder to track these things than you think. That is why the attack worked. Advertisers and ad networks do NOT want to be associated with malware. As much as you don't want to believe it, they want to show you ads that might interest you and nothing else.

    4. Re:Source Unknown? by Anonymous Coward · · Score: 0

      It's my understanding that the online ad industry has many, many layers of middlemen, which serves to obfuscate ad origins. But how they can reliably track effectiveness and control delivery with such a convoluted system, I have no idea, let alone shirking of accountability.

  6. adaware by fermion · · Score: 5, Interesting

    It has been my contention that when websites no longer serve malware through Ads, then they can start complaining that users blocks ads. This is not an uncommon occurrence, even for large websites, and the fix is not always immediate. I recall not that long ago when the New York Times was serving malware for the entire weekend.

    --
    "She's a scientist and a lesbian. She's not going to let it slide." Orphan Black
    1. Re:adaware by Anonymous+Brave+Guy · · Score: 4, Informative

      It has been my contention that when websites no longer serve malware through Ads, then they can start complaining that users blocks ads.

      Indeed. I block 100% of ads my tools can identify, I consider this a routine security precaution, and I make no exceptions. Sorry to the honest site operators, I won't take offence if you decide to block me because I block your ads, but no, I won't whitelist you. This became my policy shortly after the only virus infection I've ever been aware of picking up on any computer I operate, which was a Java zero day exploit I picked up browsing normally reputable tech news sites.

      --
      If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
    2. Re:adaware by A_Non_Moose · · Score: 1

      Agreed.

      Similar story here, when I left an IE session open on Drudge and went to sleep.

      Woke up and saw "Antivirus 2009" or some such crapware.

      Turned out to be 2 0-day exploits to javascript and pdfs to load executable code.

      Insult to injury was I turned off javascript in pdfs explicitly and an update turned it back on. Son of a beeyotch.

      Flew under the radar of Symantec 9 or 10, IIRC. Sucked because I was still in .edu and had no time for that kinda shite, but dealt with it just the same.

      Now it is the "only if I allow it" kinda rule...even then there is a 90% chance of "oh, hell no!".

      --
      Have you read the moderator guidelines? Well, have you, PUNK? (and I want a Karma: Gnarly option)
    3. Re:adaware by Billly+Gates · · Score: 1

      Don't use IE. Its been said here for over 10 years now and you should know better.

      Even if its not IE 6 anymore it still does not support adblock. Get foxit unless you really need adobe. You can disable launch in browser. Also create a standard user and stop using XP. You never would have become infected.

    4. Re:adaware by flappinbooger · · Score: 1

      It has been my contention that when websites no longer serve malware through Ads, then they can start complaining that users blocks ads. This is not an uncommon occurrence, even for large websites, and the fix is not always immediate. I recall not that long ago when the New York Times was serving malware for the entire weekend.

      Yeah, they outsource their ad space to someone, that company gets them from who knows where. It isn't necessarily that easy to find out where each ad comes from.

      Ads and email attachments are obviously the most common attack vectors I hear about. Also binding malware to pirated files or crackz are notorious too. Not all cracks or pirated warez are malwared but a lot are.

      --
      Flappinbooger isn't my real name
    5. Re:adaware by PNutts · · Score: 1

      A guy at work went to Druge a few years ago and got his work PC zapped. A visit to LiveLeak set off my A/V but nothing got in.

    6. Re:adaware by cbhacking · · Score: 1

      IE has had a built-in ad blocking solution (it's marketed as an anti-tracking solution, but it works fine on ads) since IE8. IE9 and later can even load filters from EasyList (who do the most widely-used AdBlock Plus list) and automatically update it. Extensions (called add-ins, sometimes "Browser Helper Objects") that provide ad-blocking have been available since at least IE6, and probably before.

      In the interest of avoiding monoculture, not using IE makes some sense (although these days, anything much more mainstream than Opera has enough users to be an attractive target).
      In the interest of supporting open-source browsers (or if you believe that the "many eyes..." theory makes up for the relative lack of resources for security testing compared to a major corporation), using Chromium or Firefox makes sense, but they've had exploits as well.
      In the interest of punishing MS for its past behaviors, using something other than IE makes sense.
      But complaining that IE can't block ads or similar, well, that really doesn't make any sense at all. IE has more built-in ad blocking than many of its competitors, even though it's turned off be default and most people don't know how to turn it on.

      In any case, the exploit that got A_Non_Moose was a JS bug in his PDF reader. You'd do better to recommend he stop using Acrobat (the only reader I know of that not only enables JS by default but turns it back on, silently, each time you update). If his browser was configured to open PDFs in Acrobat automatically, it doesn't matter *what* browser he was using.

      --
      There's no place I could be, since I've found Serenity...
  7. "has become"? by grub · · Score: 1, Insightful


    a reminder that Java has become an Internet security menace

    Java has always been a security menace.

    --
    Trolling is a art,
    1. Re:"has become"? by Anonymous Coward · · Score: 2, Insightful

      Not sure if parent is trolling, or just confused.

      Most of us know the difference between Java (a perfectly secure language) and the ability to run applets in a browser (a feature that can be exploited if the sandboxing is insecure). It doesn't matter whether we're talking about Java Applets or ActiveX. Hell, even interactive PDF forms have been used as attack vectors.

    2. Re:"has become"? by grub · · Score: 1

      I meant running in the browser, not playing Minecraft. That ActiveX or PDF are also insecure doesn't change the fact that Java (in the browser) is shit and always in need of security updates.

      --
      Trolling is a art,
    3. Re:"has become"? by Anonymous Coward · · Score: 0

      IE6 and WinXP were the big threat back then, especially in the pre-sP2 days. But for the last few years Java has been the main culprit. 90%+ of the viruses I remove can be easily traced back to something like browsing to a page with Java-based malware.

      Back then I used to tell people not to use IE. Using Firefox pretty much took care of virus problem. Nowadays it's "don't install Java". Then again, new versions of the better browsers block it by default, and that's gonna help a lot!

      Of course, it's not Java the language that's the problem, it's the annoying browser plugin. Then again, it still comes bundled with other crapware like the ask toolbar that you have to opt out of.

    4. Re:"has become"? by Billly+Gates · · Score: 1

      Anything that executes code or reads it is potentially insecure.

      Best defense is always to run updated oses with updates on, do not as root or admin, turn off anything that launches in a browser like PDF and Java. And for heavens sake run Av folks!

      I know many say with a smile they run XP with an admin account with an ancient version of ff like 3.6 with no protection whatsoever!! Lord I bet such things have tons of Trojans and key loggers on (ff 3.6 has +40 holes as it is not maintained?!)

      Anyway Avast is light and it as well as comodo dragon filter less trusted ad networks. You can disable PDF reader in its preferences and you can keep Java for eclipse but disable it in your browser addons. Done with a limited account, adblockers, Av software and a modern os mixed with shit launching automatically and you are pretty secure.

    5. Re: "has become"? by Anonymous Coward · · Score: 0

      Download the JRE or JDK from oracle.com to avoid annoyware in the installer.

  8. Not Java but shitty Java browser plugins by Anonymous Coward · · Score: 1

    Java is a much safer language than say C because of the built in checks. It's the proprietary crappy browser plugins that make this kind of attacks possible.

    1. Re:Not Java but shitty Java browser plugins by Jawnn · · Score: 1

      Java is a much safer language than say C because of the built in checks. It's the proprietary crappy browser plugins that make this kind of attacks possible.

      For 99% of the users out there, that is an absolutely pointless distinction.

    2. Re:Not Java but shitty Java browser plugins by Anonymous Coward · · Score: 0

      You're only half right. If the plugins were properly isolated, you could compile C onto the JVM and have the same level of security. In fact, tools exist for compiling C and C++ into bytecode. Your general point is valid though. It's not the language. It's the crappy plugins.

    3. Re:Not Java but shitty Java browser plugins by Anonymous Coward · · Score: 0

      99% of the users out there may not know anything about computers but that is no reason for the rest of us to also act clueless, some would say on the contrary.

  9. And this is why... by bmo · · Score: 3, Insightful

    ... using ad blocking and/or host files to deep-six ad networks not only produces a nicer user experience, but it's a valid security measure.

    Trusting the web site is not enough. You have to trust the ad network too. Since any Joe Schmoe can buy ad space on an ad network, trusting the ad network means you're trusting Joe Schmoe.

    I don't know about you guys, but I don't.

    --
    BMO

    1. Re:And this is why... by TubeSteak · · Score: 1

      FireFox + NoScript replaced my ad-blocker for years

      Now, I only find ad-blockers or hosts files to be necessary for handling crap that's embedded in flash files.

      /Does Chrome have a proper NoScript equivalent yet?

      --
      [Fuck Beta]
      o0t!
    2. Re:And this is why... by gstoddart · · Score: 3, Interesting

      /Does Chrome have a proper NoScript equivalent yet?

      ScriptSafe + DoNotTrackMe + Ghostery + AdBlockPlus are what I have in Chrome.

      ScriptSafe does about the same as NoScript.

      --
      Lost at C:>. Found at C.
    3. Re:And this is why... by Billly+Gates · · Score: 1

      Unfortunately Windows 8 and higher ignore host files. You can use avast or Comodo dragon which blocks less trusted ad networks in addition to adblock.

    4. Re:And this is why... by Anonymous Coward · · Score: 0

      Win8 doesn't ignore the hosts file, but it does protect it from being changed by malware. You just have to disable tracking of the hosts file if you're going to edit it.

      dom

    5. Re:And this is why... by perpenso · · Score: 1

      Unfortunately Windows 8 and higher ignore host files. You can use avast or Comodo dragon which blocks less trusted ad networks in addition to adblock.

      What Windows 8 does is irrelevant if one takes some old retired PC and installs Linux or *BSD on it and sets it up as a router.

    6. Re:And this is why... by allo · · Score: 1

      use adblock edge, abp is getting more and more stuff you do not want. read the blog entries from some time ago. Its not only the acceptable ads* stuff, they are working with ad companies at some more points.

      * which is a big deal anyway, because one of the first types of acceptable ads were the sedo-typo-squatting ads on misspelled domains.

    7. Re:And this is why... by Arker · · Score: 1

      The last I checked there was no way to block scripts prior to download - the best the extension could do was step in after they have been downloaded and parsed and then walk them back out. Not acceptable, not even close.

      --
      =-=-=-=-=-=-=-=-=-=-=-=-=-=-
      Friends don't let friends enable ecmascript.
    8. Re:And this is why... by Anonymous Coward · · Score: 0

      ScriptSafe does about the same as NoScript.

      Do you work for Google? Unless I have missed something or it has changed ScriptSafe is no where near as functionally selective as NoScript. If one is going to enable any scripting at all it should be as selectively minimal as possible and not every fucking script on a given URL. Say for instance you actually want to waste some time and bandwith at Hulu, then with noscript you can enable Hulu.com and Hulumim.com and watch the show without enabling the additional annoyance and spying links wanting you to socialize with them. Of course even with NoScript you may want to remove many of the default whitelisted sites, including the 3 Yahoo listings IMO. AdBlock+, for whatever reasons, doesn't block all the ads in the Hulu video player. That you can take care of via changing the hosts file. Of course once you do then the Hulu player figures out your blocking the ads and increases the time it waves the "click here to enable ads screen" in your face thus increasing your time to go to the restroom, wash your hands and go to the kitchen to make a sandwich and/or grab a drink.

      Oh, and does anyone know why there are only half the blocking options in Ghostery when run in Chrome or just why it is that there is not available a valid substitute for NoScript or NoScript itself? If I have missed something about Chrome and ScriptSafe, please enlighten me as I would love to be wrong just as I would love for their to be a valid substitute for NoScript in Chrome and for things like Ghostery to be as fully functional in Chrome as they are in FireFox. Of course it would be best if none of those addons were even necessary because none of those problems existed or at least the necessary functions were incorporated into the browsers. Until it is then Firefox and its variants are the only options to just completely denying scripting or doing such browsing on a diskless computer etc.

    9. Re:And this is why... by Anonymous Coward · · Score: 0

      I am still having a lot of trouble figuring out how to NOT manually copy my username into the body of every single one of my posts. Lord knows how I manage to muster the necessary intelligence just to log in to this site, considering my complete stupidity when it comes to basic posting skills that everyone else seems to grasp without issue.

      --
      BMO

    10. Re:And this is why... by zippthorne · · Score: 1

      Chrome has per-domain javascript white/blacklisting built-in.

      --
      Can you be Even More Awesome?!
    11. Re:And this is why... by cbhacking · · Score: 1

      Erm... bullshit? The only thing I'm aware of that's even *close* to what you're saying is that in Win8 and newer, the built-in anti-malware feature (Windows Defender) will remove entries for several well-known domains, including some advertising networks but also things like search engines and such, from the HOSTS file. Either turning off Defender, or setting it to Exclude the HOSTS file, will cause HOSTS to work like normal.

      --
      There's no place I could be, since I've found Serenity...
    12. Re:And this is why... by Anonymous Coward · · Score: 0

      In addition to the integrity of my system, I also value my privacy. Until Google stop profiting from private information, Chrome will never have sufficient privacy protection addons.

      Unfortunately, due to Mozilla being bought by Google, Firefox is also in the danger zone.

  10. Yahoo is getting worse everyday by Anonymous Coward · · Score: 3, Insightful

    New Yahoo Mail = complete unusable dog shit

    New Flickr = complete fuck up! They don't even read user feedback.

    New Ad delivery = source of malware! Even porn sites don't do that.

    1. Re:Yahoo is getting worse everyday by Anonymous Coward · · Score: 5, Interesting

      yep, blocked *.yahoo at the point i noticed them installing psudo-malware with uTorrent (the persistent default search engine replacement software which uses far more CPU time than something that supposedly just monitors search engine settings and resets them to Yahoo should. It was very malware like in it's choice of installation folder too and of course the fact it was both unwanted and self-repairing)

      once a company starts doing that shit they end up on my block list, permanently. uTorrent made it too for bundling the crap.

      sounds like I dodged a bullet by having them blocked.

    2. Re:Yahoo is getting worse everyday by hyades1 · · Score: 1

      Wish I had a mod point to move you up the food chain a bit.

      --
      I've calculated my velocity with such exquisite precision that I have no idea where I am.
    3. Re:Yahoo is getting worse everyday by Anonymous Coward · · Score: 0

      Yahoo calendar - people complained in 2006 that there was no public RSS feed, no API for creating or reading calendar events, etc etc etc.

      EIGHT YEARS AGO.

      Today? Do a search for a Yahoo Calendar API, it doesn't exist.

    4. Re:Yahoo is getting worse everyday by Anonymous Coward · · Score: 0

      Yahoo mail on Thunderbird seems the same as other mail services, and I also have CalDav too.

      Why do YOU hvae problems with it?

      POP is POP, SMTP is SMTP, CalDav is CalDav.

    5. Re:Yahoo is getting worse everyday by Anonymous Coward · · Score: 0

      Yahoo was never good to begin with.

  11. Wut? by Anonymous Coward · · Score: 0

    you should disable Java (but not JavaScript, a completely separate technology) as a precaution.

    I lol'd. Javascript SO SECURE. NO HACK.

  12. Thunderbird is my friend. by couchslug · · Score: 1

    I kept my old Yahoo webmail accounts but use Thunderbird to read those as well as Gmail. Avoids dealing with asstastic webmail page layout as well as being bothered with adverts.

    --
    "This post is an artistic work of fiction and falsehood. Only a fool would take anything posted here as fact."
    1. Re:Thunderbird is my friend. by Anonymous Coward · · Score: 0

      I didn't realize I could do that with Thunderbird. I'm installing it right now. If you do nothing else today, friend, you made someone else's life a little better already.

  13. Good on you, Yahoo... by DrPBacon · · Score: 1

    If that's the whole statement, then wow... that's really pathetic.

    --
    Spent All My Mod Points
  14. Dalvik by goombah99 · · Score: 0

    Googles contentious rip off of Java is called Dalvik. In what aspects is it different than JAVA for security?

    --
    Some drink at the fountain of knowledge. Others just gargle.
    1. Re:Dalvik by viperidaenz · · Score: 1

      Because there isn't really much wrong with Java, from a security point of view.

      The Oracle Java Browser plugin on the other hand, is pretty dodgy.

  15. Lemme FTFY by Anonymous Coward · · Score: 0

    a reminder that Yahoo has become an Internet security menace

  16. Really? by kurkosdr · · Score: 1

    " Fox-IT says it appears to be 'financially motivated" (Insert Nicolaw Cage "you don't say" pic here) Also, Yahoo has the billing info, IP address and username of the fine fellows behind this. Can't they sue them, or at least publish that info? Oh, I forgot, that would be "aggravating a partner" which is bad for the bottom line...

  17. This justifies my habits ... by TrollstonButterbeans · · Score: 0

    For security reasons, this why I only browse the web with Internet Explorer 6 with Java disabled.

    --
    Priest: "Universe from nothing, no laws of physics, sped up time"+ huge discrepancies. Creationism? No. Big Bang Theory
    1. Re:This justifies my habits ... by giantgeek · · Score: 2

      The Washington Post cites this incident as a reminder that Java has become an Internet security menace.

      You can read about Java as the Internet security menace in the link above, but first you need to enable Java Script to read the article.

      --
      new letter/phrase: hex-u means "www"
    2. Re:This justifies my habits ... by EmperorOfCanada · · Score: 1

      I used Lynx up until 2010 until I realized that it might be compromised. So now just telnet to port 80 and manually send GETs and POSTs.

    3. Re:This justifies my habits ... by innocent_white_lamb · · Score: 1

      You don't need javascript to read that article. The text and photo are at the bottom of the page. Just scroll past all of the whitespace at the top and you'll fine it.

      --
      If you're a zombie and you know it, bite your friend!
    4. Re:This justifies my habits ... by thestuckmud · · Score: 1

      ]You can read about Java as the Internet security menace in the link above, but first you need to enable Java Script to read the article.

      That, or disable CSS (e.g. View/Page Style/No Style in Firefox).

    5. Re:This justifies my habits ... by Kimomaru · · Score: 1

      Wow, that's hard core.

  18. TY ABP & NS by Anonymous Coward · · Score: 0

    Close call.

  19. Fools who dont run AV by Billly+Gates · · Score: 1

    For the idiots who say with a smile they do not run AV software and think they are malware free because they don't click on anything, I told you so.

    Some people even on Slashdot do not have a basic understanding of online security. Yes Linux Trojans exist too because like Mac users you all think you are invulnerable.

    Basics: if you must use Java disable it in your browsers or put it in intranet zone only if you use IE at work. Disable adobe reader from launching automatically. Use foxit if you can or disable it in browser launching in which I do. Use flashblock and adblock. Even IE has adblock these days. Last do not run a browser with an admin/root account! In Windows I use a separate limited/standard account and do not browse as root in Linux. Doh. Run Windows updates!! But they may break my apps .... Please. I never had an issue and my security is worth it. Do that and these attacks will be plugged 90% of the time.

    Do these in addition to not clicking on shit and then your system will be pretty darn secure.

    1. Re: Fools who dont run AV by Anonymous Coward · · Score: 0

      Please direct me to the AV provider of your choice that prevents zero-days. Because once updates are applied and you don't install software from popup browser windows willy-nilly, there really aren't that many other threats. Only download software from known-good sources, not software.downloadhelper.com that SEOs itself to the top of searches. No AV will protect you from that kind of garbage, and many are paid off to ignore borderline malware/annoyware.

    2. Re:Fools who dont run AV by Bigbutt · · Score: 1

      Hmm, I generally don't run AV software on my systems but I'm pretty sure MSE has been running for a while so I do, just not on purpose. I didn't before that since I first started mucking with computers in 1980 or so.

      I've never had a hit from it though. Well, I take that back. I had some archival e-mails from way way back that I knew had viruses in them (the old 'I Love You' type email viruses). When MSE kicked off the first time, it scanned that directory and pinged on them. But nothing since that initial run and I knew they were there.

      I do run malwarebytes from time to time with no hits.

      But I also run noscript and abp on all my systems. Plus I don't click on links or open documents from folks I don't know, including the link in your signature.

      [John]

      --
      Shit better not happen!
  20. Reminder... by ameline · · Score: 2

    > "The Washington Post cites this incident as a reminder that Java has become an Internet security menace."

    That should read "The Washington Post cites this incident as a reminder that advertising has become an Internet security menace."

    Adblock+ -- part of a sensible security policy.

    --
    Ian Ameline
  21. Yahoo knows by EmperorOfCanada · · Score: 4, Insightful

    The moment that Yahoo allowed advertisers to use java they knew that minimally those ads would be used to annoy the crap out of the users. If your ad is a static picture with a clickable link then you don't need Java. What you need java for is to start prying into the user's business. Animations, sound, geolocations, saving data to the user's machine. So any "legitimate" ad using Java is halfway to being malware already. Plus why use Java instead of Flash? Generally ads should be made by Graphic artist types who are more familiar with Flash. Thus the primary reason to use Java is to access some feature that flash has blocked in Flash.

    So if your goal with a Java ad is to circumvent something that Adobe has blocked then it probably should remain blocked. On top of that most users have turned off Java so it can't be to reach a wider audience.

    So when Yahoo allows advertisers to use Java they knew perfectly well that the advertisers were up to no good whatsoever. Their acting surprised that some of the scumbags took it even further is total BS.

    Basically at this point, anyone who has Java turned on in the browser is the same as having a house with a weeks worth of newspapers stacked up at the front door. Effectively a greeting card inviting the criminals in.

    1. Re:Yahoo knows by asmkm22 · · Score: 1

      For what it's worth, a big reason they changed from making ads in Flash to Java is because

      a. People used to complain about Flash, and how slow and insecure it was.
      b. Flash didn't work very well with mobile phones (or at all for a long time).

    2. Re:Yahoo knows by akozakie · · Score: 1

      "Allow Java"? Sorry, but you can't really block Java if you allow scripting or redirection.

      With redirection, you lose control over what the ad actually serves. You'd have to re-check it all the time. What will you do if it serves malware only to every tenth visitor? And never to yahoo IP space?

      With scripting... Well, unless you have the resources to manually analyze every ad before you allow it (who would accept that much delay?), you will never be entirely sure what the code does. Static analysis can only go so far, there will always be ways to obfuscate the beejeezus out of the script in a way you cannot parse. Dynamic analysis is costly and what will you do if the code is in a way non-deterministic (includes a Java applet depending on time, random number, or whatever)? Plus, if any links appear in either analysis, see redirection, you don't know what will be served.

      The only relatively secure ad service is one that only allows images (uploaded to the ad service, not linked) and text with limited markup. No scripting at all. But that's not what the advertisers want and they are the paying customers.

      The most you can do is some screening of the ads and quick, effective handling of any incoming reports to minimize bad PR. It seems that this is what they do - good for them.

      Sorry, but that's what happens if ads are the main source of income. In this model the ads are inherently unsafe - unless you have a very secure browser setup, but that will break some pages.

      If users pay for a service, secure ads as additional income source are possible - but that's rare. Free = unsafe, sorry. Accept the risk or protect yourself.

  22. Thousands? by wonkey_monkey · · Score: 2

    Yahoo Advertising Serves Up Malware For Thousands

    The attack, which lasted several days... the infection rate was at about 27,000 infections per hour.

    That's nearly 2 million at least. C'mon Slashdot, it's not like you to supply a less sensational headline than necessary.

    --
    systemd is Roko's Basilisk.
  23. How is the source unknown? by viperidaenz · · Score: 1

    The source is a Yahoo ad customer. Do they not know who pays them? Or do they not want to lose a paying customer by outing them?

    1. Re:How is the source unknown? by Greyfox · · Score: 1

      Perhaps they were paid with a stolen credit card. It's not like those are hard to come by.

      --

      I'm trying to teach myself to set people on fire with my mind... Is it hot in here?

    2. Re:How is the source unknown? by Anonymous Coward · · Score: 0

      Where I live (Germany), installing malware is a crime (called computer theft, data alteration, computer sabotage or somesuch). If Yahoo helped the criminals install malware, that's aiding and abetting. If they also protect the criminal now by not identifying him, that's a crime itself. In principle, someone could and should go to jail for up to three years.

      Has anyone sued Yahoo yet? Actually, sueing their CEO personally might move things faster. I bet, if that happened, the source of the malware would be idenfied rather quickly.

  24. Yahoo doesn't immediately know by viperidaenz · · Score: 3, Insightful

    The ad didn't contain a Java applet.
    It directed people to a website that then delivered the malware. Apparently it automatically redirected the browser, but that hasn't been confirmed.

    So Yahoo allow Javascript in the ads, not Java.

    1. Re:Yahoo doesn't immediately know by EmperorOfCanada · · Score: 1

      Ah good clarification. So a good policy for yahoo would be if your site uses Java applets there is an 80% chance you are being a tool. I thought the coverage of Java Applet Ads would be pretty poor. I am not sure of the exact stats but with mobile devices growing this number must also be in freefall.

      The only legitimate sites that I see where a java applet is a critical feature are older science websites. Astronomy calculators would be a common example.

      Personally I am excited about the prospects of asm.js for when you want to put something hardcore in a browser. Something that might have been ported from C++ or some such language.

    2. Re:Yahoo doesn't immediately know by Anonymous Coward · · Score: 0

      The ad didn't contain a Java applet.
      It directed people to a website that then delivered the malware. Apparently it automatically redirected the browser, but that hasn't been confirmed.

      So Yahoo allow Javascript in the ads, not Java.

      I have had ads that redirected the browser. They pop up a alert box and when you close that alert box, your page gets redirected. I have run into them on www.runescape.com (in their wiki) and on one of the tv/movie streaming index sites. I am not sure who was the ad server but I do know that they are extremely annoying (seriously google, why the fk do you let web content create a modal alert in Chrome?). I reported them to the respective websites knowing that they could be used to do stuff like this or phishing...

  25. Use click to play by tulcod · · Score: 1

    Java zero days are easily avoided by using "click to play", which does exactly what it sounds like: disable flash and java applets until you click them. In Chromium, this is easily enabled in Settings -> Show advanced settings -> under "Privacy", Content Settings -> choose "Click to play" under Plug-ins.

    Java (and Flash likewise) has never been safe, and it's a shame that click to play is not the default. Additionally, animated ads are often Flash or Java-based, so this also kills distracting movies.

    1. Re:Use click to play by Anonymous Coward · · Score: 0

      Easily circumvented with a JS app that detects any click on the webpage to activate the plugin.

  26. One of many such cases by Anonymous Coward · · Score: 0

    And people still whinge about users installing adblocking software? As far as I'm concerned a computer without adblock (at a hosts file level) is a security risk.

  27. But don't block the ads! by Anonymous Coward · · Score: 0

    We can't get any money to promote our site if we're not infecting every machine that visits!

  28. But does it run on Linux? by mspohr · · Score: 1

    As usual (unfortunately). Both the article and the summary are pathetic examples of journalism which should try to at least inform.
    For instance, it would be useful to know (at a minimum) which OSs, browsers, etc are vulnerable, whether any of the virus detection programs will block or remove the malware and what effects the malware has on systems when they are infected.
    In other words, this article is just "scareware" warning about some unspecified threat to do something bad to somebody and no idea who, what, when or where.

    --
    I don't read your sig. Why are you reading mine?
    1. Re:But does it run on Linux? by asmkm22 · · Score: 2

      Did you even read the articles, or did you just click the first link in the summary and call it a day? The one linking specifically to Fox IT's blog, which is the source of this discovery, goes into great detail about this. They specifically mention the following:

      This exploit kit exploits vulnerabilities in Java and installs a host of different malware including:

      ZeuS
      Andromeda
      Dorkbot/Ngrbot
      Advertisement clicking malware
      Tinba/Zusy
      Necurs

    2. Re:But does it run on Linux? by mspohr · · Score: 2

      But do any of these run on Linux.. or Mac OSX?
      I guess we should just assume that they all run on Windows although the article is silent on this subject.
      Does any antivirus program detect or block any of these?
      What should I do if I think I have been "exposed"?

      Useless articles.

      --
      I don't read your sig. Why are you reading mine?
    3. Re:But does it run on Linux? by asmkm22 · · Score: 1

      None of those malware packages are new. They've been covered numerous times in the past. Google them up yourself if you weren't paying attention for the last 6 years. I certainly don't want to have to read through a bunch of information that I already know because it's not exactly new.

    4. Re:But does it run on Linux? by mspohr · · Score: 0

      It's interesting how all of the news articles just copied the Fox-IT blog post and that post itself doesn't give a clue about the target machines.
      I guess we all should assume that these viruses are all Windows only although it would have been nice of them to be explicit about the target machines.
      I don't have anyone running Windows so I don't keep up on malware.
      I certainly don't expect you to do the research for me although it would have been nice if someone in the Windows world would admit that these are only Windows viruses.
      I guess I can just assume that Linux and OSX are immune (until we get big headlines on Slashdot announcing Linux malware).

      --
      I don't read your sig. Why are you reading mine?
    5. Re:But does it run on Linux? by ShoulderOfOrion · · Score: 1

      I think it's a given that if a virus, worm or whatever could actually infect a Mac or Linux box that would be in the headline, or at least the first paragraph.

  29. Freaking ad networks by Dega704 · · Score: 2, Informative

    Hence why I advise people to install AdBlock on their browsers. The way things have been for the pas few years, it's probably more effective than antivirus software. (Before you flame me, I am speaking tongue-in-cheek. You really should have both.)

  30. I'm confused... by jddeluxe · · Score: 1

    People still visit yahoo's website? How quaint!

  31. Wrong view of security by Sigma+7 · · Score: 1

    reminder that Java has become an Internet security menace."

    The big three browsers can trivially block Java, through something as simple as "click to play", or "always launch plugins from this site". Any browser that auto-executes stuff by default is broken.

    On the other hand, I've had a malware distribution attempt via Javascript. It's certainly designed to attack Chrome, since it wipes the previous page content and URL, replacing it with its own.

    Oh, and a trivial Javascript exploit that browsers took 10+ years to fix.

    while(true) {alert("haha");}

    1. Re:Wrong view of security by Anonymous Coward · · Score: 0

      Any browser that auto-executes stuff by default is broken.

      So, in your opinion all the major browsers are broken as they default to running (embedded or seperatily retrieved) scripts ?

      I'm glad we agree here. :-)

  32. Learn correct grammar... by Anonymous Coward · · Score: 0

    "exploited vulnerabilities in Java and installed malware"

    "exploited vulnerabilities in Java COMMA and installed malware"

    Otherwise it could be taken to mean the the vulnerabilities were also in 'installed malware'. Duh. Americans.

  33. 3rd party malware. by ralphaostrander · · Score: 1

    Adblock plus. Is all you need to know. In settings dont allow some.

  34. This is the perfect example of why adblock plus by ralphaostrander · · Score: 1

    should not default to allow any. Let the use take the risk in allowing do not assume it for me unless your going to pay for my damages.

  35. Browser addons noted = inferior to hosts by Anonymous Coward · · Score: 0

    Hosts do more w/ less (1 file) @ a faster level (ring 0) vs redundant browser addons (slowing up slower ring 3 browsers) via filtering 4 the IP stack (coded in C, loads w/ OS, & 1st net resolver queried w\ 45++ yrs.of optimization):

    ---

    APK Hosts File Engine 9.0++ 32/64-bit:

    http://start64.com/index.php?option=com_content&view=article&id=5851:apk-hosts-file-engine-64bit-version&catid=26:64bit-security-software&Itemid=74

    (Details of hosts' benefits enumerated in link)

    Summary:

    ---

    A. ) Hosts do more than AdBlock ("souled-out" 2 Google/Crippled by default) + Ghostery (Advertiser owned) - "Fox guards henhouse", or Request Policy -> http://yro.slashdot.org/comments.pl?sid=4127345&cid=44701775

    B. ) Hosts add reliability vs. downed or redirected DNS + secure vs. known malicious domains too -> http://tech.slashdot.org/comments.pl?sid=3985079&cid=44310431 w/ less added "moving parts" complexity + room 4 breakdown,

    C. ) Hosts files yield more speed (blocks ads & hardcodes fav sites - faster than remote DNS), security (vs. malicious domains serving mal-content + block spam/phish), reliability (vs. downed or Kaminsky redirect vulnerable DNS, 99% = unpatched vs. it & worst @ ISP level + weak vs FastFlux + DynDNS botnets), & anonymity (vs. dns request logs + DNSBL's).

    ---

    * Addons are more complex + slowup browsers in message passing (use a few concurrently - you'll see) - Addons slowdown SLOWER usermode browsers layering on MORE: I work w/ what you have in kernelmode, via hosts ( A tightly integrated PART of the IP stack itself )

    APK

    P.S.=> * "A fool makes things bigger + more complex: It takes a touch of genius & a lot of courage to move in the opposite direction." - Einstein

    ** "Less is more" = GOOD engineering!

    *** "The premise is, quite simple: Take something designed by nature & reprogram it to make it work FOR the body, rather than against it..." - Dr. Alice Krippen "I AM LEGEND"

    ...apk

    1. Re:Browser addons noted = inferior to hosts by PNutts · · Score: 2

      Why do apk's posts remind me of reading a Dr. Bronner's soap label?

    2. Re:Browser addons noted = inferior to hosts by fractoid · · Score: 1

      Oh man, that stuff. It's like the Time Cube of liquid soap.

      --
      Rampant carbon sequestration destroyed the Dinosaurs' tropical paradise. I'm here to help repair the damage.
  36. Re: "has become" by Anonymous Coward · · Score: 0

    The Ask.com annoyware comes straight from Oracle when you download Java from them. You have to remove the checkmarks or else Oracle will include the Ask.com search bar and change your default search engine to Ask.com.
    It was bad enough when the annoyware came from 3rd parties but now you have to be just as careful about watching for extra downloads from the original software sources.

  37. It's vastly inferior to hosts (see A link inside) by Anonymous Coward · · Score: 0

    Hosts do more w/ less (1 file) @ a faster level (ring 0) vs redundant browser addons (slowing up slower ring 3 browsers) via filtering 4 the IP stack (coded in C, loads w/ OS, & 1st net resolver queried w\ 45++ yrs.of optimization):

    ---

    APK Hosts File Engine 9.0++ 32/64-bit:

    http://start64.com/index.php?option=com_content&view=article&id=5851:apk-hosts-file-engine-64bit-version&catid=26:64bit-security-software&Itemid=74

    (Details of hosts' benefits enumerated in link)

    Summary:

    ---

    A. ) Hosts do more than AdBlock ("souled-out" 2 Google/Crippled by default) + Ghostery (Advertiser owned) - "Fox guards henhouse", or Request Policy -> http://yro.slashdot.org/comments.pl?sid=4127345&cid=44701775

    B. ) Hosts add reliability vs. downed or redirected DNS + secure vs. known malicious domains too -> http://tech.slashdot.org/comments.pl?sid=3985079&cid=44310431 w/ less added "moving parts" complexity + room 4 breakdown,

    C. ) Hosts files yield more speed (blocks ads & hardcodes fav sites - faster than remote DNS), security (vs. malicious domains serving mal-content + block spam/phish), reliability (vs. downed or Kaminsky redirect vulnerable DNS, 99% = unpatched vs. it & worst @ ISP level + weak vs FastFlux + DynDNS botnets), & anonymity (vs. dns request logs + DNSBL's).

    ---

    * Addons are more complex + slowup browsers in message passing (use a few concurrently - you'll see) - Addons slowdown SLOWER usermode browsers layering on MORE: I work w/ what you have in kernelmode, via hosts ( A tightly integrated PART of the IP stack itself )

    APK

    P.S.=> * "A fool makes things bigger + more complex: It takes a touch of genius & a lot of courage to move in the opposite direction." - Einstein

    ** "Less is more" = GOOD engineering!

    *** "The premise is, quite simple: Take something designed by nature & reprogram it to make it work FOR the body, rather than against it..." - Dr. Alice Krippen "I AM LEGEND"

    ...apk

  38. Arguably... by easyTree · · Score: 1

    ...this is their Raison d'être - "advertisments - malware for the brain."

  39. Java? What about Javascript? by cjonslashdot · · Score: 1

    "...reminder that Java has become an Internet security menace."

    Actually, the largest menace is Javascript. That's why so many people use NoScript.

    Any kind of in-browser active code execution will inevitably have security challenges.

  40. Re:It's vastly inferior to hosts (see A link insid by Anonymous Coward · · Score: 0

    I know I'm replying to APK, but... I use both because they serve different purposes. I want to block ads, so I do that at the hosts file level. I also want to stop tracking while still being able to use services that attempt to track me across the web (e.g. Google and Facebook). There's a few ways I do this (partially, I just use a clean browser for a lot of my browsing), but part of it is using RequestPolicy to prevent non-Google sites from accessing Google domains or non-Facebook sites from accessing Facebook domains. (Ghostery sorta does this automatically.)

  41. interesting bit by Anonymous Coward · · Score: 0

    I first heard about applets ~95ish and thought: WTF?

    CS student says "no problem, they run in the sandbox and stay in your browser unless they're signed as being secure".

    Me: "We'll see".

    Almost 20 years later, applets still aren't secure.

    And CS guy works in infosec.

  42. But what? by Anonymous Coward · · Score: 0

    "I want to stop tracking still being able to use services that attempt to track me across the web (e.g. Google and Facebook)...using RequestPolicy to prevent non-Google sites from accessing Google domains or non-Facebook sites from accessing Facebook domains" - by Anonymous Coward on Sunday January 05, 2014 @07:42PM (#45874475)

    Hosts stop sites accessing google/facebook domains/subdomains + trackers (I do & I ACCESS e,g, gmail all day long) - re-proving HOSTS' superiority (equality there + superiority on NUMEROUS levels by gains in speed, security, reliability & even anonymity) OVER RequestPolicy (limited vs. hosts' nigh ubiquitous versatility).

    Good to see you use hosts (hosts' superior value vs. redundant browser addons on many levels = undeniable)!

    ---

    "Ghostery sorta does this automatically" - by Anonymous Coward on Sunday January 05, 2014 @07:42PM (#45874475)

    Ghostery = ADVERTISER OWNED & technically inferior. I suppose if you were a farmer you'd have a fox guard a henhouse right? Looks it!

    ---

    "I know I'm replying to APK, but" - by Anonymous Coward on Sunday January 05, 2014 @07:42PM (#45874475)

    Per subject: What's that mean? You *trying* to put me down?? IF so You're doing a bad job when I address that from a PURELY valid tech level using your "points" against ya above.

    (Just as I did in the "A" link in my last post you replied to that compared RequestPolicy to hosts' abilities & lost).

    Your tools doing less & worse != "better"!

    ---

    Lastly - When detractors achieve what I have in the art & science of computing (while you were in diapers) they can attempt to "berate me" as peers (& not until) + you lack facts to shoot mine down above + "hiding" behind AC (NerdFest) when you have a reg'd 'luser' acct. here? Please...

    APK

    P.S.=> Read the quote I used from Einstein & understand (hosts = better for less vs. inferior browser addons more weight/complexity IS that) - Thanks for making ME look good & you "not so good"...

    ... apk

  43. Flash is a major resource hog, too by knorthern+knight · · Score: 2

    I don't have Java installed. I run linux, but Java is cross-platform, and I don't fall into the "it can't happen here" camp. Besides, I save a few hundred megabytes of disk space by not installing Java.

    Flash is another issue altogether. I follow one forum that autoruns Flash movie ads on occasion. If you hovered over the ad, it would enable sound too.Firefox used to lock up for a few minutes. Running with system load = 3 or 4, on a 2-core machine is begging for thrashing/near-lockup.

    I now use 2 browsers...
    1) one browser has Flash disabled entirely
    2) the other one I launch when I see a link to Youtube/whatever. When the video finishes, I close it. The taskbar has a mini-version of "top" running. Sometimes, after turning off the Flash browser, I'll watch the system load fall from 1.3 down to 0.3... satisfying.

    --

    I'm not repeating myself
    I'm an X window user; I'm an ex-Windows user
  44. Re: It's vastly inferior to hosts (see A link insi by Anonymous Coward · · Score: 0

    And why should I trust the compilers of hosts lists? They could be easily be redirecting some hosts to malware serving properties while giving you a false sense of security.

    I've been burned by what passed as reputable internet sources a couple of times. The trust issue simply isn't solved by relying in some random internet organization for your hosts files.

  45. happend to me last year by Anonymous Coward · · Score: 0

    Last year, I actually caught one of those fake anti-virus programs while a real anti virus program was running. I don't know which site had the malware script, but it was a website that displayed advertisements. Or maybe I got the malware from a hidden script at one of those freeware/shareware sites.

  46. Downmodder: "Rinse, Lather, & Repeat" by Anonymous Coward · · Score: 0

    Thanks 4 proving my points 2x -> http://tech.slashdot.org/comments.pl?sid=4631643&cid=45872561 & in my post before it you also bogusly downmodded too http://tech.slashdot.org/comments.pl?sid=4631643&cid=45871549

    (With NO valid on topic tech critique to back ya vs. either posts' points)

    ---

    Posted to raise this into view again & my last post was for that too (works EVERY time + QUITE obviously "got a rise" out of ya since it's TRUTH per your further weak downmods of my posts 2x w/ NO "computing-technical" validity disproving my points & backing your downmods).

    * :)

    Verifiable concrete undeniable Truth's like that - an irresistable force on offense (BEST defense) & an immovable object on defense.

    Great stuff. Especially vs. bogusly downmodding effete trolls 'reactions' w/ no validity to 'em!

    (Funniest part? You *seem* to *think* folks're stupid & won't see my posts or your reprehensible b.s. in effete "retaliation" - guess again - & that I believe is WHY you did the bogus unjustified downmod yet again - you KNOW folks see my posts - regardless of your bogus downmods - & you're HELPLESS in validly combatting my points favoring hosts via valid ontopic tech grounds)

    ---

    Imo You MUST be an "advertiser"!

    (I state that since ya certainly + clearly lack technical saavy to disprove my points in favor of custom hosts files versatility & ubiquity on numerous levels (vs. inferior competitors, obviously, because of that) giving users of HOSTS added speed, security, reliability, & even anonymity)

    IF you're a "computing pro", give up. You need more training hands on if you're reduced to such reprehensible tactics - seriously.

    Either way - Keep "reacting", dancing to MY tune - you make ME look good, & yourself, "not so good"...

    APK

    P.S.=> Now, ya just KNOW that I've just GOTTA say it, don't ya? Here 'tis:

    THIS? This IS just "too, Too, TOO EASY - just '2ez'" & best part is you're MAKING it so for me - thanks!

    ... apk

  47. Re:To the downmodder of my post by TranquilVoid · · Score: 1

    Can you think of any advantages to in-browser ad blockers?

  48. Malwarebytes Anti-Exploit Beta by PNutts · · Score: 2

    A/V doesn't protect against a lot of this stuff. Malwarebytes has a new anti-exploit beta for us Windows folks.

    From the FAQ:

    17- What techniques does MBAE use to detect and block exploits?

    MBAE incorporates multiple exploit detection and blocking techniques at different stages of the typical exploit attack to provide a truly complete solution against all types of current and future exploits.
      Stage 1 Layer: This layer of MBAE incorporates multiple techniques to detect and block exploits during stage 1 of the exploit attack, before the shellcode is allowed to run. In some cases, MBAE detects and prevents exploits before the operating system Data Execution Protection (DEP) protection.
      Stage 2 Layer: This layer of MBAE incorporates multiple memory protection and payload execution techniques which prevent exploits from executing their stage 2 payload, thereby protecting the computer even if operating system protections and stage 1 protection techniques have been bypassed.

  49. That's why I never use IE by bobjr94 · · Score: 1

    Most people running something other than IE with an ad block or script block most likely never would have had any problems. My boss still likes IE for whatever reason, needless to say Im at his computer every month or 2 removing spyware, viruses or a total computer hijacking (pay us 100$ to unlock this pc). Last virus he picked up was from an ad on msn.

    1. Re:That's why I never use IE by cbhacking · · Score: 1

      You can block ads and scripts in IE just fine. Heck, there are even built-in ways to do it, using filter lists from folks like EasyList (better known for their popular AdBlock Plus filter list). No need to download an extension (MS calls them "add-ons" but they are much the same thing) as long as you're using IE9 or newer, but ad-blocking and script-filtering are available at least as far back as IE6. There's also options like blocking using a HOSTS file or similar.

      Your boss's problem isn't that he uses IE, it's that he doesn't know how to use the Web safely at all. Your problem isn't that your boss likes IE (which does actually have some nice features, such as its tab groupings and translation "accelerator") but that you know one safe way to use the Web (which your boss doesn't like) but are apparently not smart enough to find one that he does like (despite the fact that such things certainly exist).

      Using Firefox in its default configuration would be just as vulnerable.

      --
      There's no place I could be, since I've found Serenity...
  50. Trust math & truth then by Anonymous Coward · · Score: 0

    My program protects vs. it: You SEE data YOU control "redirect" for exclusively thru fav sites creation you do to speed access to favs via local valid resolution & avoiding DNS problems + speed hit & surveillance totally. Yours = only ones allowed to NOT have 0.0.0.0 or 127.0.0.1 in front's why @ top of hosts.

    Rest = imported blockers from hosts makers & they're ONLY blockers: Not redirectable faked for malware!

    In fact, it blocks known threats via my program's processing algorithm & data outputs thus (or after since hosts itself's optionally AUTO protected by it).

    Redirect threat's impossible via my program's algorithms & sources + autoguard of hosts if left resident (Otherwise it applies protective attribs @ least)

    Your observation during creation's protection too since you witness it & create topmost favs data ONLY changeable by you - for redirect usefulness to LOCAL resolution speeds & protection vs. DNS redirects/down too.

    My program protects vs.that potential threat perfectly, on many levels. More benefits of that layout & process are below.

    APK

    P.S.=> Favs @ top of hosts = reverse DNS ping verified (in front of you + you created em) speeds their seek/access & you can turn off the faulty w/ big hosts files local DNS clientside cache service in Windows saving CPU cycles, RAM, & I/O wasted on it too - BONUS - & diskcaching hosts (it's a file) = rest for performance.

    (Equals/Exceeds index speed to, iirc, 2-3++ million entries via extrapolating a binary search result)

    I do 20 @ top of hosts for speed + protection & reliability but also for easy verification (visually from my program's GUI immediately as verification witness yourself)

    REST (2,208,392++ here) = blocked - Who CARES how "fast" I get to or thru those - I never INTEND to get to them in the 1st place - They're blockers (vs. myriad threats for all or most all hardware platforms + OS w/ a BSD derived IP stack (hosts IS tightly integrated into TCP/IP itself)... apk

  51. Re: by Anonymous Coward · · Score: 0

    No game I'm aware of has ever had to install VC++.
    Oh, you meant the runtime libraries? In that case, 100% of Linux systems clearly have a similar vulnerability, what with having glibc and all.

  52. malware? Java? Really! by Anonymous Coward · · Score: 0

    Seriously? I am wondering if people remember Microsoft. Look at the amount of malware/spyware caused by IE exploits. Windows, especially.
    look back at all the holes inside Microsoft's IE.
    Stop blaming others for shortcomings, and clean up your own backyard.

    my 2c

  53. Not really by Anonymous Coward · · Score: 0

    1st - I'm NOT in the habit of "helping competition" (1 that's imo @ least, betrayed their users' trust by doing what I just noted in selling out or being a fox in the henhouse owned by those that track users etc.).

    I used to suggest adblock though - not anymore (proof below in the link)...

    However: to answer your question, see subject. Not really, other than for "defense-in-depth"/"layered-security" which I do 'espouse' in a security guide for Windows I wrote up 1997-2008-> http://www.bing.com/search?q=%22HOW+TO+SECURE+Windows+2000%2FXP%22&qs=n&form=QBLH&pq=%22how+to+secure+windows+2000%2Fxp%22&sc=1-31&sp=-1&sk=&cvid=076184f3eb324595b50361c6f7a08236

    * HOWEVER: That's before AdBlock was crippled by default & 'souled-out', & Ghostery being advertiser owned etc. as noted in the post of mine you replied to....

    APK

    P.S.=> Still - the fact remains I stand by my words & challenge ANYONE to disprove them in my post you replied to (that was bogusly downmodded by trolls who obviously, based on the results here, cannot disprove my points on hosts' value in giving users of them added speed, security, reliability, & even anonymity + their superiority on MANY GROUNDS there vs. AdBlock/Ghostery/Request Policy etc. - et al noted there)...

    ... apk

  54. Yes, really by cbhacking · · Score: 4, Informative

    With all due respect, his post was a lot more insightful than yours. You don't appear to know what you're talking about.

    First of all, "deployed the same way" as in "deployed using an HTML <object> or <applet> element that instructs the browser to download and execute the code". The Microsoft Visual C++ redistributable runtime does not include any such mechanism for deploying C++ code. For that matter, not all Java runtime installations do either.

    Second, just what do you think ActiveX is programmed in? Hint: it's not its own language. It's a packaging system for COM classes, which are almost without exclusion written in C++, and it *is* possible to deploy and run it in the browser in much the same way as Java applets (object tags). Unlike Java, they run with basically no sandbox but instead require considerable amounts of confirmation before they download. The idea is that they are powerful but unsafe, so only use the ones that you trust. Unfortunately, a number of pre-installed ActiveX controls on Windows have security vulnerabilities in them, so an attacker who finds a way to exploit one of those pre-installed ones doesn't need to get the user to download anything. Hence the way that modern versions of IE require the user to confirm before running an ActiveX control that they've not previously indicated that they trust (and also give you an ability to disable ActiveX completely or only enable it on a site-by-site basis).

    I don't care for the Java installer any more than you do, but the security issues with Java applets have literally nothing to do with the language. The only way you could say Java itself is at fault is if you were to argue that Java shouldn't have any OS bindings at all (that is, no ability to access the file system, no ability to create processes, no ability to open network sockets, etc.). This is essentially the situation with JavaScript, of course; while the Java applet sandbox tries to *restrict* the use of functionality like I just mentioned, the JavaScript runtime (as found in browsers) simply lacks APIs to access such risky features. Even there, though, that's not a characteristic of the JavaScript *language* but merely of the sandboxed runtime used to execute JS in the browser. Other uses of JS, ranging from Windows Script Host to Node.JS, are perfectly capable of doing such things.

    --
    There's no place I could be, since I've found Serenity...
  55. Yahoo SUX anyway! by Anonymous Coward · · Score: 0

    Yahoo, with the new e-mail format, is malware in itself!

  56. AdBlock = Inferior + 'Souled-Out' by Anonymous Coward · · Score: 0

    Hosts do more w/ less (1 file) @ a faster level (ring 0) vs redundant browser addons (slowing up slower ring 3 browsers) via filtering 4 the IP stack (coded in C, loads w/ OS, & 1st net resolver queried w\ 45++ yrs.of optimization):

    ---

    APK Hosts File Engine 9.0++ 32/64-bit:

    http://start64.com/index.php?option=com_content&view=article&id=5851:apk-hosts-file-engine-64bit-version&catid=26:64bit-security-software&Itemid=74

    (Details of hosts' benefits enumerated in link)

    Summary:

    ---

    A. ) Hosts do more than AdBlock ("souled-out" 2 Google/Crippled by default) + Ghostery (Advertiser owned) - "Fox guards henhouse", or Request Policy -> http://yro.slashdot.org/comments.pl?sid=4127345&cid=44701775

    B. ) Hosts add reliability vs. downed or redirected DNS + secure vs. known malicious domains too -> http://tech.slashdot.org/comments.pl?sid=3985079&cid=44310431 w/ less added "moving parts" complexity + room 4 breakdown,

    C. ) Hosts files yield more speed (blocks ads & hardcodes fav sites - faster than remote DNS), security (vs. malicious domains serving mal-content + block spam/phish), reliability (vs. downed or Kaminsky redirect vulnerable DNS, 99% = unpatched vs. it & worst @ ISP level + weak vs FastFlux + DynDNS botnets), & anonymity (vs. dns request logs + DNSBL's).

    ---

    * Addons are more complex + slowup browsers in message passing (use a few concurrently - you'll see) - Addons slowdown SLOWER usermode browsers layering on MORE: I work w/ what you have in kernelmode, via hosts ( A tightly integrated PART of the IP stack itself )

    APK

    P.S.=> * "A fool makes things bigger + more complex: It takes a touch of genius & a lot of courage to move in the opposite direction." - Einstein

    ** "Less is more" = GOOD engineering!

    *** "The premise is, quite simple: Take something designed by nature & reprogram it to make it work FOR the body, rather than against it..." - Dr. Alice Krippen "I AM LEGEND"

    ...apk

  57. Ghostery & AdBlock = Inferior + 'Souled-Out' by Anonymous Coward · · Score: 0

    Hosts do more w/ less (1 file) @ a faster level (ring 0) vs redundant browser addons (slowing up slower ring 3 browsers) via filtering 4 the IP stack (coded in C, loads w/ OS, & 1st net resolver queried w\ 45++ yrs.of optimization):

    ---

    APK Hosts File Engine 9.0++ 32/64-bit:

    http://start64.com/index.php?option=com_content&view=article&id=5851:apk-hosts-file-engine-64bit-version&catid=26:64bit-security-software&Itemid=74

    (Details of hosts' benefits enumerated in link)

    Summary:

    ---

    A. ) Hosts do more than AdBlock ("souled-out" 2 Google/Crippled by default) + Ghostery (Advertiser owned) - "Fox guards henhouse", or Request Policy -> http://yro.slashdot.org/comments.pl?sid=4127345&cid=44701775

    B. ) Hosts add reliability vs. downed or redirected DNS + secure vs. known malicious domains too -> http://tech.slashdot.org/comments.pl?sid=3985079&cid=44310431 w/ less added "moving parts" complexity + room 4 breakdown,

    C. ) Hosts files yield more speed (blocks ads & hardcodes fav sites - faster than remote DNS), security (vs. malicious domains serving mal-content + block spam/phish), reliability (vs. downed or Kaminsky redirect vulnerable DNS, 99% = unpatched vs. it & worst @ ISP level + weak vs FastFlux + DynDNS botnets), & anonymity (vs. dns request logs + DNSBL's).

    ---

    Addons are more complex + slowup browsers in message passing (use a few concurrently - you'll see) - Addons slowdown SLOWER usermode browsers layering on MORE: I work w/ what you have in kernelmode, via hosts ( A tightly integrated PART of the IP stack itself )

    APK

    P.S.=> * "A fool makes things bigger + more complex: It takes a touch of genius & a lot of courage to move in the opposite direction." - Einstein

    ** "Less is more" = GOOD engineering!

    *** "The premise is, quite simple: Take something designed by nature & reprogram it to make it work FOR the body, rather than against it..." - Dr. Alice Krippen "I AM LEGEND"

    ...apk

  58. Reminder: AdBlock = Inferior + 'Souled-Out' by Anonymous Coward · · Score: 0

    Hosts do more w/ less (1 file) @ a faster level (ring 0) vs redundant browser addons (slowing up slower ring 3 browsers) via filtering 4 the IP stack (coded in C, loads w/ OS, & 1st net resolver queried w\ 45++ yrs.of optimization):

    ---

    APK Hosts File Engine 9.0++ 32/64-bit:

    http://start64.com/index.php?option=com_content&view=article&id=5851:apk-hosts-file-engine-64bit-version&catid=26:64bit-security-software&Itemid=74

    (Details of hosts' benefits enumerated in link)

    Summary:

    ---

    A. ) Hosts do more than AdBlock ("souled-out" 2 Google/Crippled by default) + Ghostery (Advertiser owned) - "Fox guards henhouse", or Request Policy -> http://yro.slashdot.org/comments.pl?sid=4127345&cid=44701775

    B. ) Hosts add reliability vs. downed or redirected DNS + secure vs. known malicious domains too -> http://tech.slashdot.org/comments.pl?sid=3985079&cid=44310431 w/ less added "moving parts" complexity + room 4 breakdown,

    C. ) Hosts files yield more speed (blocks ads & hardcodes fav sites - faster than remote DNS), security (vs. malicious domains serving mal-content + block spam/phish), reliability (vs. downed or Kaminsky redirect vulnerable DNS, 99% = unpatched vs. it & worst @ ISP level + weak vs FastFlux + DynDNS botnets), & anonymity (vs. dns request logs + DNSBL's).

    ---

    Addons are more complex + slowup browsers in message passing (use a few concurrently - you'll see) - Addons slowdown SLOWER usermode browsers layering on MORE: I work w/ what you have in kernelmode, via hosts ( A tightly integrated PART of the IP stack itself )

    APK

    P.S.=> * "A fool makes things bigger + more complex: It takes a touch of genius & a lot of courage to move in the opposite direction." - Einstein

    ** "Less is more" = GOOD engineering!

    *** "The premise is, quite simple: Take something designed by nature & reprogram it to make it work FOR the body, rather than against it..." - Dr. Alice Krippen "I AM LEGEND"

    ...apk

  59. Well said (& agreed WITH a difference) by Anonymous Coward · · Score: 0

    However - regarding your "weapon-of-choice" vs. mine? Well - you know -> http://tech.slashdot.org/comments.pl?sid=4631643&cid=45882675

    * Are we "switching gears" from DNS now on your end? I think not, but you're more pointing out adblock for your customers ONLY from what you wrote.

    (However - it's "Almost All Ads Blocked now" by default & just can't hold a candle to my fav's 12-20 abilties & features it has, that AdBlock doesn't, & in added security, speed, reliability, + even anonymity (to an extent vs. DNS logs etc.) - & it's why I use it: Nigh Ubiquitous versatility vs. Intentionally crippled & 'souled-out' so-called functionality after being paid off to do so by Google)

    Lastly - you're making your "weapon-of-choice" sound like a 'magical woobie' (what you called mine iirc, in fact)... & per that "heated discussion" of ours from your own words? There ISN'T one...

    Well ok, fine: Agaiin though - yours doesn't DO nearly as much in terms of added speed, security, reliability, & even anonymity... not by a LONG shot. I.E. (in the end)? There IS a "better woobie" (lol, my fav) & on MANY levels.

    APK

    P.S.=> Still liked what you said though - I've literally SEEN the exact SAME but I apply a different tool with a LOT more good capabilities & can point you to 1 guy that LITERALLY got 200++ "viruses" a month, month in & month out, year-by-year if you like & he'll tell you (by email, mail me, you have my email address & conversations we've had too there for reply easily - I can have HIM email that testimony your way, however based on YOUR findings now? I don't *think* I even need to)

    E.G. - He's seen the SAME results you have & hasn't gotten THAT since he applied my "weapon-of-choice" (custom hosts) for YEARS as long as he uses it & keeps it current - so, what you've discovered? I've literally SEEN for years now & can prove it, IF you wish via that email... apk

    1. Re:Well said (& agreed WITH a difference) by hairyfeet · · Score: 1

      The only problem I have with using HOSTS is that it requires updating to be of use and when it comes to customers? If I did my job right hopefully I won't be seeing them again for years. With ABP and Privdog I don't have to worry about "will they update the thing" as it is done automatically with the latest version every time they launch the browser.

      That said I've found a way to go one better than HOSTS, at least for me and my customers, remember how I ran my own DNS? Well I don't have to do that now that Comodo offers their secure DNS for free and with Dragon and IceDragon I can have the browser and ONLY the browser run through their secure DNS. This way anything like games or Steam can hook up directly while the biggest attack vector, the browser, is filtered. Its nice, again auto updating, and best of all for me its a "set and forget" so once set I don't have to ever touch it again and in point of fact since making ads verbotten the only infections I see now are social engineering (Yuo want teh tittiez? Run "Iz_Not_Viruz_Iz_Codex" to see teh hot tittiez!) or when they get "toolbarred" because they refuse to read EULAs. All the actual bugs? Gone, zip zero zilch nada squat.

      --
      ACs don't waste your time replying, your posts are never seen by me.
  60. Ghostery/AdBlock = Inferior + 'Souled-Out' by Anonymous Coward · · Score: 0

    Hosts do more w/ less (1 file) @ a faster level (ring 0) vs redundant browser addons (slowing up slower ring 3 browsers) via filtering 4 the IP stack (coded in C, loads w/ OS, & 1st net resolver queried w\ 45++ yrs.of optimization):

    ---

    APK Hosts File Engine 9.0++ 32/64-bit:

    http://start64.com/index.php?option=com_content&view=article&id=5851:apk-hosts-file-engine-64bit-version&catid=26:64bit-security-software&Itemid=74

    (Details of hosts' benefits enumerated in link)

    Summary:

    ---

    A. ) Hosts do more than AdBlock ("souled-out" 2 Google/Crippled by default) + Ghostery (Advertiser owned) - "Fox guards henhouse", or Request Policy -> http://yro.slashdot.org/comments.pl?sid=4127345&cid=44701775

    B. ) Hosts add reliability vs. downed or redirected DNS + secure vs. known malicious domains too -> http://tech.slashdot.org/comments.pl?sid=3985079&cid=44310431 w/ less added "moving parts" complexity + room 4 breakdown,

    C. ) Hosts files yield more speed (blocks ads & hardcodes fav sites - faster than remote DNS), security (vs. malicious domains serving mal-content + block spam/phish), reliability (vs. downed or Kaminsky redirect vulnerable DNS, 99% = unpatched vs. it & worst @ ISP level + weak vs FastFlux + DynDNS botnets), & anonymity (vs. dns request logs + DNSBL's).

    ---

    * Addons are more complex + slowup browsers in message passing (use a few concurrently - you'll see) - Addons slowdown SLOWER usermode browsers layering on MORE: I work w/ what you have in kernelmode, via hosts ( A tightly integrated PART of the IP stack itself )

    APK

    P.S.=> * "A fool makes things bigger + more complex: It takes a touch of genius & a lot of courage to move in the opposite direction." - Einstein

    ** "Less is more" = GOOD engineering!

    *** "The premise is, quite simple: Take something designed by nature & reprogram it to make it work FOR the body, rather than against it..." - Dr. Alice Krippen "I AM LEGEND"

    ...apk

    1. Re:Ghostery/AdBlock = Inferior + 'Souled-Out' by Anonymous Coward · · Score: 0

      net resolver queried w\ 45++ yrs.of optimization

      Oh, do fuck off, you blithering moron. (Not a personal attack, since you really are a blithering moron, you blithering moron.)

      And now you can try to have fun writing yet another hilarious response, that nobody will care one iota about. Go ahead.

  61. AdBlock = Inferior + 'Souled-Out' by Anonymous Coward · · Score: 0

    Hosts do more w/ less (1 file) @ a faster level (ring 0) vs redundant browser addons (slowing up slower ring 3 browsers) via filtering 4 the IP stack (coded in C, loads w/ OS, & 1st net resolver queried w\ 45++ yrs.of optimization):

    ---

    APK Hosts File Engine 9.0++ 32/64-bit:

    http://start64.com/index.php?option=com_content&view=article&id=5851:apk-hosts-file-engine-64bit-version&catid=26:64bit-security-software&Itemid=74

    (Details of hosts' benefits enumerated in link)

    Summary:

    ---

    A. ) Hosts do more than AdBlock ("souled-out" 2 Google/Crippled by default) + Ghostery (Advertiser owned) - "Fox guards henhouse", or Request Policy -> http://yro.slashdot.org/comments.pl?sid=4127345&cid=44701775

    B. ) Hosts add reliability vs. downed or redirected DNS + secure vs. known malicious domains too -> http://tech.slashdot.org/comments.pl?sid=3985079&cid=44310431 w/ less added "moving parts" complexity + room 4 breakdown,

    C. ) Hosts files yield more speed (blocks ads & hardcodes fav sites - faster than remote DNS), security (vs. malicious domains serving mal-content + block spam/phish), reliability (vs. downed or Kaminsky redirect vulnerable DNS, 99% = unpatched vs. it & worst @ ISP level + weak vs FastFlux + DynDNS botnets), & anonymity (vs. dns request logs + DNSBL's).

    ---

    * Addons are more complex + slowup browsers in message passing (use a few concurrently - you'll see) - Addons slowdown SLOWER usermode browsers layering on MORE: I work w/ what you have in kernelmode, via hosts ( A tightly integrated PART of the IP stack itself )

    APK

    P.S.=> * "A fool makes things bigger + more complex: It takes a touch of genius & a lot of courage to move in the opposite direction." - Einstein

    ** "Less is more" = GOOD engineering!

    *** "The premise is, quite simple: Take something designed by nature & reprogram it to make it work FOR the body, rather than against it..." - Dr. Alice Krippen "I AM LEGEND"

    ...apk

  62. "Why have you intercepted me?" by Anonymous Coward · · Score: 0

    "Where in hell is APK when you need him?" - by fast turtle (1118037) on Sunday January 05, 2014 @10:19PM (#45875419)

    Quoting the Mysterious Mr. Gary 7 from StarTrek TOS "Assignment Earth" episode in my subject-line above!

    Lazy fucking bum." - by fast turtle (1118037) on Sunday January 05, 2014 @10:19PM (#45875419)

    So - Here I am -> http://start64.com/index.php?option=com_content&view=article&id=5851:apk-hosts-file-engine-64bit-version&catid=26:64bit-security-software&Itemid=74

    * Since you asked... & THAT ought to show that I haven't been a 'lazy bum' regarding the subject you brought up!

    (I *truly* think you'll LOVE that one, by "yours truly", & it's there available in BOTH 32-bit + 64-bit versions - For custom hosts file creation...)

    APK

    P.S.=> Enjoy - especially since you felt hosts aren't perfect "by a long shot", albeit with GOOD points from you by example too... However, THAT will make them as perfect as is possible via data for hosts files from a dozen reliable & reputable sources in the security community... apk

  63. You certainly seem to care by Anonymous Coward · · Score: 0

    Quit projecting your OWN issues (being a moron): See subject, you project THAT too, lol...

    * :)

    (I mean, what - do you "stalk" ALL of my posts? What's the matter - not enough "mod points" to down-moderate them anymore?? Yes - THAT truly appears to be the case: You're ALL "out of ammo"... I love it!)

    How pitiful can you BE, posting DAYS AFTER this post was put up, only to have me smack you down yet again?

    APK

    P.S.=> Get this thru your head: The trolling "likes of you" can't stop me (fact) & yes - It's very apparent you're 1 of 3 types of people:

    1.) Malware maker or botnet master
    2.) Advertiser
    3.) Maker of an INFERIOR competitor to my app

    Take your pick & either way? You FAIL (you know it, I know it, & so does anybody else with 1/2 a brain - just based on your illogical off-topic effete "retaliation/reaction")... your fav. color MUST be "transparent", since I see RIGHT thru you, with ease...

    ... apk

  64. Ya quit drinkin/smokin what's in that bottle by Anonymous Coward · · Score: 0

    You wouldn't have that problem (or being an offtopic troll either)

    * :)

    (What I find VERY NICE is the fact you had to go "off topic" & be a troll...)

    APK

    P.S.=> Why? It proves that you don't have anything that can disprove what I write up in favor of custom hosts files vs. "the competition" (limited & inferior) that favors hosts in abilities in added speed, security, reliability, & even anonymity to an extent, that those competitors just can't even SCRATCH... I love it!

    ... apk

  65. Does Chrome have a proper NoScript equivalent? by drobety · · Score: 1

    HTTP Switchboard. This puts to rest all the false claims out there that Chrome doesn't have the proper API to block scripts. This thing does what NoScript, Request Policy and AdBlock do all together, plus it has nice privacy enhancing options.

  66. So does AdBlock (EZList for example) by Anonymous Coward · · Score: 0

    "With ABP and Privdog I don't have to worry about "will they update the thing" as it is done automatically with the latest version every time they launch the browser." - by hairyfeet (841228) on Thursday January 09, 2014 @06:17AM (#45905359)

    Updating hosts = easy w/ my app (has timed scheduler) -> http://start64.com/index.php?option=com_content&view=article&id=5851:apk-hosts-file-engine-64bit-version&catid=26:64bit-security-software&Itemid=74

    ---

    "I've found a way to go one better than HOSTS" - by hairyfeet (841228) on Thursday January 09, 2014 @06:17AM (#45905359)

    AdBlock doesn't block ALL ads by default anymore & AdBlock can't do @ least 12 things hosts can -> http://yro.slashdot.org/comments.pl?sid=4127345&cid=44684319 for better speed, security, reliability vs. DNS issues, & even anonymity.

    ---

    * Plus, users get all the things for added speed, security, reliability vs. DNS faults, & even anonymity hosts provide, that browser addons don't do (without slowing up the browser itself in usermode/ring 3/rpl 3 since hosts run as a filter for the IP stack in kernelmode/ring 0/rpl 0 - faster).

    ONLY good I have to say about addons is they promote "layered-security"/"defense-in-depth" in combo w\ hosts - but not anymore (almost all ads blocked by default).

    E.G.-> I used to suggest AdBlock in security guides I authored 1997-2008 for Windows users -> http://www.bing.com/search?q=%22HOW+TO+SECURE+Windows+2000%2FXP%22&qs=n&form=QBLH&pq=%22how+to+secure+windows+2000%2Fxp%22&sc=1-31&sp=-1&sk=&cvid=076184f3eb324595b50361c6f7a08236

    APK

    P.S.=> To each his own: NEVER THOUGHT you'd 'drop' your own DNS (but dns is loaded with issues, & yes, ones hosts DO shore up & overcome) & you're doing what I do (OpenDNS here) + they do eat CPU, RAM, & other forms of I/O that other solutions, don't (hosts)... apk