An e-commerce website allowed random unvetted files to be loaded on its pages? How could they have been so stupid in the first place?
How a massive campaign of booby-trapped web ads went undetected for too long
Security firm Malwarebytes has published a comprehensive analysis of a recently detected malvertising attack that affected many ad networks and ran uninterrupted for almost three weeks. The tainted ad-slinging scheme affected large and small ad networks alike. What appeared to be legitimate advertisements were used to mask …
COMMENTS
-
Tuesday 15th September 2015 23:39 GMT Steven Raith
So what we're really saying is that if the code for the active parts of adverts hasn't been checked, audited and sanitised, then no-one gets to put up an advertisement more complicated than an animated GIF? No fancy animations, no JS, no pop-ups, no pop-unders. Just a flat image, or an animated image running at no more than 3fps.
As that should really be how it is. Simple as that.
Steven R
-
Wednesday 16th September 2015 07:22 GMT SecretSonOfHG
I agree, it should be as simple as that. However, try to convince marketing folks that their custom built and very expensive product ads in the shape of a carefully crafted Flash animation have exactly the same effectiveness as a static image. Their careers are too invested to even stop and analysing what they are doing.
As (I believe it was) Henry Ford said, 90% of all advertising is useless. The problem is that there is no way to know which part of the whole is the useful 10%
-
-
-
Wednesday 16th September 2015 14:06 GMT Vic
Re: Stop Thief!
you are a thief
Absolutely. These malware-flingers have paid for those domains, and all that software. So by blocking the Angler exploit, you're not just interfering with pixels, you're interfering with business.
Vic.
-
This post has been deleted by its author
-
Wednesday 16th September 2015 06:31 GMT heyrick
Funny, to be reading this after only yesterday reading http://www.theregister.co.uk/2015/09/15/to_read_this_page_please_turn_off_your_ad_blocker/
-
Wednesday 16th September 2015 13:40 GMT paulf
Dear Internet Ad industry
This is why I run ABP on all my machines.
If you want to compare me to a Thief for using ABP, then I compare you to a Newsagent that sends someone round to drain all the fuel out of my car when I buy a paper.
Sincerely
Long term ABP user
PS - Sort out your Malvertising delivery networks (along with less intrusive ads and an end to the stalker like creepy tracking that facilitates delivery of said Malvertising) and I may consider white listing sites