Malvertising Campaign Hits MSN, NY Times, BBC, AOL
An anonymous reader quotes an article on Help Net Security: In the last couple of days, visitors of a number of highly popular media outlets including the NY Times, the BBC, and Newsweek have been targeted with malicious adverts that attempted to install malware (mostly ransomware, but also various Trojans) on their systems. The websites themselves weren't compromised as the problem was with the ad networks these sites use -- Google, AppNexus, AOL, Rubicon. The ad networks were tricked into serving malicious ads to the visitors.
And then they'll tell us to please unblock them so they can make money on our misfortune.
And this is exactly why we need to run adblockers.
is essential for safety? Got it!
The websites themselves weren't compromised
The ads appeared when I visited those websites, therefore it appears the websites are responsible for spreading the malware.
I mean, this wouldn't happen if ad companies weren't struggling to stay afloat! Think of the execs!
Sure... Maybe... But this is based single reference to a short 5 paragraph "story" on a click-bait site.
If you want news from today, you have to come back tomorrow.
...ad blockers are still bad, m'kay?
I hope you die horribly.
The world's burning. Moped Jesus spotted on I50. Details at 11.
Who use ad and script blocking..
Within the arms of tragedy, there is little comfort in being right.
I've never seen an advert on the BBC site. I've just had a browse to confirm that. Maybe they have some geo-location check in place.
wanna tell me again why it's wrong of me to run an ad-blocker? Try to use bigger words this time, cuz when you use the smaller ones I understand 100% what you're telling me and my Deja-Moo detector goes off.
Deja-Moo - that feeling you've heard this bull before.
And they'll prohibit us use adblockers and access their sites.
Adblocker & related tools should change their marketing from 'helping you to block ads' to 'helping you avoid Malware/trojans etc.'...e.g. they should advertise & promote themselves as a 'security tool'...everything out of their mouths, on their website etc should be focused on that use case. Any time some politician opens their mouth about how adblockers are 'stealing' or 'ruining' some business the makers of adblocking tools should retort with statements about 'helping users security' etc.
Several years ago this happened to the NYT. It was serving malware ads for the entire weekend. That was the point when I went from ambivalent to pro-adblocker. This is why Forbes is dead to me. Used to link to it a lot.
"She's a scientist and a lesbian. She's not going to let it slide." Orphan Black
every one of them
Surely the ad network(s) or the sites themselves can be sued over this?
The websites themselves weren't compromised as the problem was with the ad networks these sites use
If you've configured your site to allow arbitrary content from unknown third-parties, your site is compromised by design. If the mere act of rendering the content that your site is sufficient to get malware, then, yes, your page is compromised. Doesn't matter if the source of the malware was in somebody else's ad service. If that service feeds data directly into your site that you then present to your visitors without any sort of vetting or filtering, then you've allowed that malware to compromise your site.
Take responsibility, show some respect for your viewers, and stop making excuses. Vet your ads. Serve them from your own servers. Make them first-party. Compelling us to turn off ad-blockers to access your content while not taking steps on your end to protect us from malicious content is sloppy, negligent, and shows an utter and complete disregard for your customers.
I used to have a difficult time not using common plugins like Flash or Silverlight, or the likes of Java. But Java was pretty easy to ditch years ago, and I use a Mac and Silverlight is a performance nightmare on a Mac. Flash was the hardest plugin to ditch, but after seeing monthly if not weekly exploits and then patches from Adobe. I realized that nothing is so important that I need to accept the security nightmare called Flash. Even the risk is not totally eliminated if you use blockers because now many do deals with respectable ads so they are allowed. Given these recent attacks are operating on respected sites. One has to assume a user with a ad blocker is not totally immune. The only real prevention is to stop using Flash altogether.
The guy at this site maintains a crazy list of advertisers and malicious site DNS records... then points them all to 0.0.0.0 using host file format. It has served me well for years now.
http://winhelp2002.mvps.org/ho...
It should be "MSN, NY Times, BBC and AOL hit users with Malware".
They are not the victims, their users are.
If anything, MSN, NY Times, BBC and AOL are responsible. They allow unvetted crap on their website. (he, if that goes for movies and music, why not malware ?). If they use anti-adblock technology they are more than responsible, they are accomplices and should be in criminal court.
At times it becomes impossible to browse the web from my phone - it seems like every now and then someone successfully pushes this crap to ad networks, and since 99% of all sites use them it becomes inescapable.
Google et al should be accountable for offering a service delivering malware. And, web publishers, i know this is not exactly your fault but i don't care. There are a good number of sites i'm no longer visiting because either they redirect me to porn sites every time or reject ad blockers, which i use to avoid this situation in the first place. Get your shit together.
I hope you die horribly.
Hey don't bully 12 year olds online!
In the free world the media isn't government run; the government is media run.
Seriously.
Sure, some people can (and do) run for extended periods of time without getting compromised without ad blockers or AV.
In the end, it's just a matter of time before they're infested.
And yes, compromises on large ad networks like Google may be somewhat rare. But that doesn't help me when a website using their network gives me a drive-by install of Locky or or something that totally hoses all my (or my company's) data.
As such, there is NO negotiation about ad blocking. It's happening. PERIOD.
Until the entire ad industry formulates an acceptable ad policy that people can live with, that DOESN'T pose a danger to its users, ad blocking will continue.
Now content providers are free to take their ball and go home. I don't much give a shit. If given a choice between having my personal and company data destroyed/stolen and watching every content provider on the Internet crash and burn due to lack of ad revenue? Let the fuckers crash and burn!
Chas - The one, the only.
THANK GOD!!!
May the circle be unbroken.
Our suspicions grew further when de-obfuscation of the script revealed that it tries to enumerate the following list of security products and tools in order to filter out security researchers and users with protections that would prevent exploitation ... If the code doesn't find any of these programs, it continues with the flow and appends an iframe to the body of the html that leads to Angler EK landing page."
So, if I understand this properly, if the Javascript code finds these files, it doesn't serve up the malware landing page. So, if I understand it properly, adware networks, along with any other site's Javascript code, can see what files I have on my PC? WTF--can I shut off that ability? I can see no justifiable reason why any Internet site, short of one or two I might whitelist, would need to be able to access such info...
Windows 3.1x calc: 3.11 - 3.10 = 0.00
I guess I'll have to turn off Adblock and NoScript so I can take advantage of this wonderful opportunity to get my free malware.
Just cruising through this digital world at 33 1/3 rpm...
I hope you die horribly.
Why? I don't like what they have to say and, as is known, I'm even part black. It neither bothers me nor does it make me wish death (or even horrific death) on them. There's lots of things that people say and do that I don't particularly like. I don't have to like everything.
If we eliminate things we don't like then, eventually, there will come a time when you're in the group of people that is disliked. You don't think morality stops with just what you want, do you? I can assure you, there are people who don't like the things you say - and want you to die, horribly. If we could all just get a little bit past that sort of thinking, the world might actually be a nicer place - even though we'd still have people trolling like the AC that you responded to.
Hell, as I said, I'm part black and I'm not even the least bit offended by them. No, the word nigger does not offend me - even when used as a pejorative. Hell, if anything, I'm more unhappy (but not wanting them to die horribly) when it is used in a non-pejorative way.
I don't get why you'd want someone to be dead just because you don't like what they are saying. That literally makes no sense to me. None. I've tried to suss it out and reason my way to understanding but humans confuse me. Yeah, they're idiots. Oh well... The world is full of idiots. I can't imagine why I'd want anyone to die horribly. To me, that would make me equally horrible.
Shit, I agree with the death penalty (just be honest about it) and I still don't want them to die horribly. No, I want it to be as painless as possible. I'm not really sure what that has to do with it but it seemed salient so I figured I'd add it. It's right up there with wanting people to be raped and beaten in prison or hoping they never get out of jail. No, I hope they get better and they're in jail as punishment and not for additional punishment.
Seriously, explain your reasoning/logic to me - if you can. I've asked others before (in very similar circumstances) and (ironically) gotten replies like, "Fuck you faggot." Yup... From the same person I've asked to explain. So far, not one has ever been able to explain how they reasoned themselves into holding and voicing such a position. It's not like you're the first person to express such views. Others do advocate for censoring them, that's a little more logical than wanting them to die. Others often express a desire to be the person who physically harms the individual, that's even less logical.
"So long and thanks for all the fish."
Long ago I saw a story about a CEO who admitted cheerfully that half his advertising budget was wasted. He just never knew which half. I couldn't help wondering how he knew that it wasn't all wasted.
Perhaps people like the average slashdotter find it hard to understand why advertising works. After all, we tend to be well educated and inclined to focus on facts and logic. (We like to think...) But surely it suggests a very disparaging view of the average consumer to think they would be powerfully influenced by ads. There is a small subset which are useful: those that tell you about something you want, can afford, and would actually like to buy. But most of them are aimed at making us buy stuff we don't need, don't even really want, and can't afford.
So what would be the effect of completely abolishing advertising? (Just as a thought experiment: we can think about how to do it another day). A lot of people might stop buying things they don't really need or want, so sales would go down somewhat. But wouldn't that turn resources free to be used making things we do want and need? Surely Douglas Adams can't have been wrong.
In a world where kind, decent people see fit to create and maintain FOSS, and give us all the Web as a free gift, why should it be used to earn money from conning people?
I am sure that there are many other solipsists out there.
This so called "article" from spam-site HelpNet is based on these 3 reports.... which actually make more sense than their copy-pasted article: http://blog.trendmicro.com/trendlabs-security-intelligence/malvertising-campaign-in-us-leads-to-angler-exploit-kitbedep/
https://www.trustwave.com/Resources/SpiderLabs-Blog/Angler-Takes-Malvertising-to-New-Heights/
https://blog.malwarebytes.org/malvertising-2/2016/03/large-angler-malvertising-campaign-hits-top-publishers/
Next time, replace their link with ArsTechnica, maybe we can get some decent reporting around here.
Why not hope the little shitstain dies as soon as possible? Nobody is saying to go out and kill them, but the world would be a nicer place as soon as they were dead.
It's just a fact.
Enjoy your malware and your ransom. But hey, you don't get Windows 10 right?
For those infected who say they turn off Windows Update with a smile all I can say is told you so!
http://saveie6.com/
How am I supposed to track physical clicks and charge for them if I download everything? Entire systems would have to be rewritten for this metric.
but I stick with google's ad program. It doesn't pay much (more than enough to cover the hosting costs and buy a little hardware now and then for testing/development. What can I say, having kids means I don't get to spend paycheck money on hobbies anymore :( ) but in all that time I haven't had my site taken down when users report I've been serving them malware for week...
Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
Comment removed based on user account deletion
This is why I run an ad-blocker, simple. The HTTP protocol has been abused so badily, what started as an amazing step for computer science decades ago, has been ruined by ad companies who themselves dish out malware / crapware. Someone asked me a while back how to browse online safely... I told them to not go online.
If contributory copyright infringement is something you get in trouble for as a hoster, then this has got to be worse. I think anyone who got infected should be able to bring a class action using CFAA, RICO or the PATRIOT Act. I.e. use some of those badly thought out laws to make a point or two and a buck.
Can addons do 16 things hosts do 4 speed, security & reliability (+ more efficiently)?
1.) Protect vs. bad sites (past ads)
2.) Protect vs. fastflux botnets + stop C&C talk
3.) Protect vs. dynamic dns botnets + stop C&C talk
4.) Protect vs. DGA botnets + stop C&C talk
5.) Protect vs. downed DNS (reliability)
6.) Protect vs. DNS redirect poisoning
7.) Protect vs. trackers
8.) Protect vs. spam
9.) Protect vs. phish
10.) Protect vs. caps
11.) Get past dns blocks
12.) Avoid dnsrequest logs
13.) Speed up surfing (adblock & hardcodes)
14.) Works on anything webbound multiplatform.
15.) EZ datacontrol
16.) Block ads more efficiently
Answer's NO on addons doing it well or @ ALL + hosts = on devices natively - not illogically inefficiently "Bolting on 'MoAr'".
(Ads on same site = rare: Advertisers don't trust webmaster click counts)
Addons = blockable by ClarityRay/BlockIQ by native browser methods: Untrue for hosts (part of IP stack).
APK
APK Hosts File Engine 9.0++ SR-4 32/64-bit http://www.bing.com/search?q=%...
* Less power/cpu/ram+ IO use vs. local DNS servers + addons w/ less security issues vs. DNS + routers. Less complex vs firewalls (needing layered filtering drivers - hosts don't + firewalls block less used IP addresses, hosts block more used host-domain names) complimenting 'em. Antivirus = reactive. Hosts = proactive, blocking infection BEFORE you get it. Gets its data from 10 reputable security community sites.
APK
P.S. - Hosts get you more speed (hardcodes + adblocks) & faster vs. addons, security (vs. bad sites/dns security issues), reliability (vs. downed/poisoned dns), & anonymity (dns requestlogs/trackers) vs. other "so-called -solutions'" w/ what you natively have. Unlike Adblock/UBlock/Ghostery, hosts != blockable by ClarityRay/BlockIQ... apk
Advertisement is a huge waste of resources:
Companies spend a part of their profits to spread subjective (i.e. false) information.
This is paid for in the end by the consumers themselves, as the advertising budget is paid from the profits.
So we as consumers pay, to get annoyed, to get our time wasted, and to get false information.
Advertisement is a plague of humanity, I'll do everything to shield myself from it.
APK Hosts File Engine 9.0++ SR-4 32/64-bit http://www.bing.com/search?q=%...
* Less power/cpu/ram+ IO use vs. local DNS servers + addons w/ less security issues vs. DNS + routers. Less complex vs firewalls (needing layered filtering drivers - hosts don't + firewalls block less used IP addresses, hosts block more used host-domain names) complimenting 'em. Antivirus = reactive. Hosts = proactive, blocking infection BEFORE you get it. Gets its data from 10 reputable security community sites.
APK
P.S. - Hosts get you more speed (hardcodes + adblocks) & faster vs. addons, security (vs. bad sites/dns security issues), reliability (vs. downed/poisoned dns), & anonymity (dns requestlogs/trackers) vs. other "so-called -solutions'" w/ what you natively have. Unlike Adblock/UBlock/Ghostery, hosts != blockable by ClarityRay/BlockIQ... apk