Vulnerabilities / Threats
9/23/2009
04:55 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

Google Urges Cooperation Against Bad Ads, Malware

A malicious ad surfaced in Google search results just as Google called for a more concerted industry effort against such scams.

As if to underscore its call for greater industry cooperation to fight malicious online ads and content, Google allowed a scam ad to appear briefly atop search results on Tuesday for the term "Firefox."

The sponsored link purported to take Google searchers to the official Firefox Web site, but in fact took them to a different domain, firefox.mozilla-now.com, according to Sophos, a computer security company.

Google appears to have removed the ad as a violation of the company's advertising policies.

A company spokesperson declined to comment on the Firefox ad in question, but acknowledged that the company does look for and remove ads that violate its policies.

"Google's advertising policy requires that the Web site address displayed in the ad must match the domain of the landing page for that ad in order to ensure that users clearly understand the destination Web site being advertised," the spokesperson said in an e-mailed statement. "We use a combination of manual and automated processes to detect and enforce these policies."

But the incident underscores the problem that Google and other online companies face in trying to thwart malicious advertising, or malvertising.

Malicious ads have also been spotted this year at nytimes.com. eweek.com, mlb.com, and foxnews.com, among other Web sites and such incidents are becoming more common.

ScanSafe, a security company, on Wednesday said that a large scale malvertising attack had hit popular Web sites, including drudgereport.com, horoscope.com and lyrics.com, over the weekend.

The company said that the ads were delivered by the several advertising networks, including DoubleClick, YieldManager and FastClick.

On Wednesday at the Virus Bulletin conference in Geneva, Switzerland, Eric Davis, head of Google's anti-malvertising team, part of the company's broader anti-malware team, urged ISPs and security companies to work together to fight malicious ads and content. He pointed to the Australian government's Australian Internet Security Initiative, a program to help ISPs identify hijacked PCs (bots) and regain control over them, as an example of cooperative security.

Along those lines, Google earlier this year introduced a custom service engine for conducting background research on online advertisers. In June, the company launched anti-malvertising.com as a home for its custom search engine and as a resource for those fighting malvertising.

Last week, Microsoft, in order to obtain enough information from ISPs to go after the cyber criminals placing malicious ads, filed five lawsuits to halt malvertising through its Ad Exchange.

In a blog post, Microsoft associate general counsel Tim Cranton warned that abuse of online advertising represents a serious threat to the free services available to consumers and businesses.

Such warnings have been heard for years. In late 2007, SANS Internet Storm Center handler William Salusky characterized malicious advertising as "a growing problem that has the potential to effectively place every Internet user at risk."

In its 2009 media predictions, global consulting firm Deloitte warned that malvertising is spreading. "By taking advantage of poor quality control mechanisms for some advertising networks and placing advertisements on trusted sites, the incidence of malvertising is likely to increase in 2009," the firm predicted.

Deloitte's report called for greater education about the threat among Web site publishers and their employees, possible code reviews for advertisements, and the development of tools to automate the screening of third-party advertisements.

Update: Added information from ScanSafe.


Experience both highlights from our InformationWeek conference as well as exclusive content presented in a unique virtual environment that allows you to personally connect with C-level executives. It happens Sept. 23, 2009. Find out more and register.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7407
Published: 2014-10-22
Cross-site request forgery (CSRF) vulnerability in the MRBS module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2014-3675
Published: 2014-10-22
Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet.

CVE-2014-3676
Published: 2014-10-22
Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related to the "tftp:// DHCPv6 boot option."

CVE-2014-3677
Published: 2014-10-22
Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.

CVE-2014-4448
Published: 2014-10-22
House Arrest in Apple iOS before 8.1 relies on the hardware UID for its encryption key, which makes it easier for physically proximate attackers to obtain sensitive information from a Documents directory by obtaining this UID.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.