Creating Browser-Based Botnets Through Online Ad Networks
LAS VEGAS -- BLACK HAT USA -- For several years security researchers and black hat hackers have fine-tuned methods of manipulating the eccentricities and vulnerabilities of the way browsers work to make user machines visit certain sites, download illegal content, and even carry out attacks like SQL injection without the user knowing it. However, these attacks have always been thought of as invoking one-off behavior that wouldn't scale well enough to leverage for something like a distributed denial-of-service attack (DDoS). But yesterday at Black Hat USA, a pair of researchers showed it is possible to maneuver browsers on a massive scale through online advertising.
|Click here for more of Dark Reading's Black Hat articles.|
More Security Insights
White PapersMore >>
- Agile Service Desk: Keeping Pace or Getting out Paced by New Technology?
- Inside Threats: Is Your Company at Risk?
"The Web runs on advertising -- that's how all these websites are paid for," Grossman said. "So the reach of these advertising networks is phenomenal."
The researchers stood up an Apache server on AWS to crash it in front of the audience within a few seconds of targeting their script-running browsers toward it.
"This whole time we did not hack anybody. We just used the way the Web works and took down our own service," Johansen said. "We stayed completely on the legal side here. But you can kind of get an idea of how this could get fun if you didn't."
Not only could malicious hackers do much more damage with more malicious code, but "there's no particular reason why the bad guys couldn't use a stolen credit card" to carry out this kind of attack, Grossman said.
According to Johansen, the advantage to an attacker of using this method is its disappearing footprint.