Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

8/1/2013
10:19 AM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Creating Browser-Based Botnets Through Online Ad Networks

Researchers demonstrate how ads invoking JavaScript on viewers' browsers en masse could create untraceable networks to wreak DDoS damage

LAS VEGAS -- BLACK HAT USA -- For several years security researchers and black hat hackers have fine-tuned methods of manipulating the eccentricities and vulnerabilities of the way browsers work to make user machines visit certain sites, download illegal content, and even carry out attacks like SQL injection without the user knowing it. However, these attacks have always been thought of as invoking one-off behavior that wouldn't scale well enough to leverage for something like a distributed denial-of-service attack (DDoS). But yesterday at Black Hat USA, a pair of researchers showed it is possible to maneuver browsers on a massive scale through online advertising.

Click here for more of Dark Reading's Black Hat articles.

In a demo at their session, WhiteHat Security researchers Jeremiah Grossman, CTO and founder, and Matt Johansen, manager of the firm's threat research center, showed it's possible to essentially create a hard-to-trace browser botnet that can easily trigger DDoS with a minimal investment in a fake online ad. As they explained, networks that serve up advertisements on ad-supported sites across the Internet frequently allow their advertisers to run arbitrary JavaScript on browsers displaying their ads. Using JavaScript to make hundreds of thousands or millions of advertising viewers connect at once to a particular target site could quickly create enough connections to take down most sites on the Web.

"The Web runs on advertising -- that's how all these websites are paid for," Grossman said. "So the reach of these advertising networks is phenomenal."

In their demonstration, Grossman and Johansen purchased $20 worth of advertising impressions through an unnamed advertising network and placed an innocuous-looking ad with a call to automatically load an external site where they could change their JavaScript payload on the fly.

"The hardest part of all this research was the approval process. Not for the reasons you'd think -- they happened to not be very good at reading JavaScript, or even caring about JavaScript. What they actually cared about was that the ad looked pretty and worked like an ad," Johansen said. "But anytime we wanted to tweak something, like change a URL, it had to go through reapproval. So instead of putting the code directly in the ad, we just put script source and sourced it out to a file on our side."

The researchers stood up an Apache server on AWS to crash it in front of the audience within a few seconds of targeting their script-running browsers toward it.

"This whole time we did not hack anybody. We just used the way the Web works and took down our own service," Johansen said. "We stayed completely on the legal side here. But you can kind of get an idea of how this could get fun if you didn't."

Not only could malicious hackers do much more damage with more malicious code, but "there's no particular reason why the bad guys couldn't use a stolen credit card" to carry out this kind of attack, Grossman said.

According to Johansen, the advantage to an attacker of using this method is its disappearing footprint.

"So why not just do a traditional denial-of-service attack? It's not persistent. It goes away," he says. "There's no trace of this -- we put the money in the machine, the JavaScript gets served up, and then it goes away. And it's very, very easy." Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
A Realistic Threat Model for the Masses
Lysa Myers, Security Researcher, ESET,  10/9/2019
USB Drive Security Still Lags
Dark Reading Staff 10/9/2019
Virginia a Hot Spot For Cybersecurity Jobs
Jai Vijayan, Contributing Writer,  10/9/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-17612
PUBLISHED: 2019-10-15
An issue was discovered in 74CMS v5.2.8. There is a SQL Injection generated by the _list method in the Common/Controller/BackendController.class.php file via the index.php?m=Admin&c=Ad&a=category sort parameter.
CVE-2019-17613
PUBLISHED: 2019-10-15
qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature to supply PHP code to be evaluated. Alternatively, the attacker can access admin/index.php?lfj=jfadmin&action=addjf via CSRF, as demonstrated by a payload in...
CVE-2019-17395
PUBLISHED: 2019-10-15
In the Rapid Gator application 0.7.1 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
CVE-2019-17602
PUBLISHED: 2019-10-15
An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated.
CVE-2019-17394
PUBLISHED: 2019-10-15
In the Seesaw Parent and Family application 6.2.5 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.