Showing posts with label Advertising. Show all posts
Showing posts with label Advertising. Show all posts

Wednesday, 4 November 2015

MacUpdate.com Provides Downloads Of Adware


A download site where Mac users can download software shows offered all kinds of apps like Skype, Firefox and 1Password to provide adware. The adware is in an installer. It is includes a "wrapper" that other apps in addition to the required software.

Users can be allowed to see the user agreement, but will ignore most users, says Thomas Reed of anti-malware company Malwarebytes. If it is for the "Quick" system chosen by the user in addition to the software you also get a browser extension and the browser settings are adjusted. According to Reed let many adware installers today see this behavior.

MacUpdate also the wrapper would install a program called MacBooster. Reed says that other download sites such as Download.com and Softonic exhibit this kind of behavior and Mac experts therefore advise you to avoid these types of websites. Mac users are therefore advised only apps from the Mac App Store, or the official website to download from the supplier, and to avoid external download sites.

Wednesday, 17 June 2015

Infected Ads On Popular Dutch Websites


Besides the Telegraaf recent days more popular Dutch websites infected with malware ads appeared that visitors were trying to infect. It also involves volkskrant.nl , trouw.nl , parool.nl and dumpert.nl , reports the Dutch security company SurfRight .

Yesterday it was announced that several major websites was an active advertising campaign which focused specifically on the Dutch internet users. The ads would be June 11, the websites have appeared. Besides Dutch websites the ads were also Dutch visitors theguardian.com , huffingtonpost.com , lemonde.fr and elle.com shown. According SurfRight contain ads malicious code that uses known vulnerabilities in Adobe Flash Player.

If users have installed the latest version of Adobe Flash Player they run no risk. The installed version of Flash Player can on this page to be viewed. Is there a vulnerable Flash Player version on the computer and the attack successfully, the Bedep Trojan is installed.

This Trojan for Windows can install additional malware, but what the final load is still unknown. The advertising platform for displaying the ads late charge that the infected ads in question have since been removed, so says security researcher Yonathan Klijnsma Fox-IT.

Wednesday, 3 June 2015

SourceForge Stopped Bundling Adware



The popular site for open source SourceForge has stopped bundling adware with projects that are not managed, so the website will know. Recently, the site "simply refusing offers from third parties" decided in a small number to join unmanaged SourceForge projects.

It would be to pass a test, but after criticism from the media and users decided to turn it back. Website Ars Technica recently reported how the setup of the graphical editing tool GIMP for Windows adware was provided. The creators of GIMP would have the project eighteen months ago abandoned and SourceForge not use more as a download location. SourceForge continued to offer the download, only includes an installer containing advertisements and tried to install any other software.

Several other projects were hosted on SourceForge ever were air adware installer, such as VLC, Firefox, Drupal and many other tools. Although the administrators of the software no longer maintained through SourceForge, the software was still available via the website. Removing an open source project on SourceForge would namely very difficult to be. As for bundling adware will only take place through an "opt-in" of developers that are still active on the website.

Saturday, 23 May 2015

Firefox Goes Ads Based On Behavioral Show


Firefox, this summer ads based on the user's surfing habits show. The browser will then when you open a new tab "Suggested Tiles" show. These are ads that are based on the user's browsing habits. This would be taken into account with the users of privacy. To make the ads relevant to a limited amount of data sent to Mozilla there.


Since then analyzed and shared with partners from Mozilla. According to the developer, the browser via Suggested Tiles possible to display relevant ads that users' privacy is respected and he or she maintains control over the data. "We believe that users should be able to easily understand what content is promoted, who it is and why they see it," said Mozilla's Darren Herman .

"It is the user who is the owner of the profile. Only a Firefox user can change its own surf history," he notes. Additionally, users can opt out of Suggested Tiles through two mouse clicks. According to Herman, the advertising function will ensure that advertisers with millions of Firefox users to get in touch. Suggested Tiles will soon be added to the beta version of Firefox and end up somewhere this summer in the final version of Firefox. This feature will first be rolled out among American Firefox users.

Wednesday, 11 March 2015

Zero-day Attack Infected Thousands Flash Users


An attack campaign in late January and early February took place and two zero-day vulnerabilities in Adobe Flash Player made ​​use has infected thousands Flash Users. To attack the leak with Flash User made ​​the cyber criminals use of contaminated ads.

Once a website showed an infected ad, visitors could get infected that had installed Flash Player. In this case the Bedep malware installed on computers. Bedep is a backdoor that gives attackers full control over the computer. While the malware was announced on the attack early this year, the first copies were observed in November last year.

Anti-virus company Trend Micro has identified more than 7,600 victims who were infected with Bedep. The malware does not only make use of vulnerabilities in software, which would also piggyback other software. Most Bedep victims, however, are the result of the zero-day attacks in late January and early February, according to Trend Micro. It is said to be more than half of all infections. Once active Bedep used infected computers to commit fraud and ad click and install additional malware.

Monday, 2 March 2015

Mozilla Removes Superfish Certificate From Firefox

Mozilla Firefox

For Firefox users against Man-in-the-middle attacks to protect Mozilla has decided to remove the Superfish certificate from the browser, but only when users first have the controversial program their computers have been removed. Superfish installed on computers a root certificate that could intercept SSL traffic and then inject ads.

However, the adware found to contain a vulnerability whereby users could be attacked. Several parties, including Lenovo, came with removal tools to remove both Superfish Superfish if the installed certificate. Some of these tools do not remove remove the Superfish certificate from Firefox, allowing these users are still at risk of being attacked.

To ensure that these users are still safe Mozilla started rolling out a hotfix . This hotfix checks whether Superfish is removed and then remove the Superfish certificate from Firefox. If Superfish namely still on the computer and Mozilla would remove the certificate from Firefox, users would no longer be able to visit HTTPS sites. The browser developer advises users therefore to the removal instructions to follow Lenovo, which both the software and the certificate can be removed manually

Sunday, 1 March 2015

EFF: Install New Computer Ever Again

EFF

If you buy a new computer that must first install all over again, because the software that comes standard is not to be trusted. That secures the American civil rights movement EFF. Following are programs like Superfish and PrivDog who intercepted the SSL traffic of users to inject ads and thus users exposed themselves to all kinds of risks.

This week it was announced that next Superfish, standard on some Lenovo notebooks shipped, other programs intercepting SSL traffic. One of these programs was PrivDog . A vulnerability in certain versions of PrivDog caused the software each certificate which replaced the Internet came and intercepted by a self-signed certificate. Even though it was about certificates that were not valid in the first place.

The Decentralized SSL Observatory of the EFF, which gathers information from the HTTPS Everywhere plugin for Firefox, has collected more than 17,000 different certificates PrivDog users. "Each of these licenses may be an attack. Unfortunately there is no way to know this for sure" says Joseph Bonneau of the Electronic Frontier Foundation (EFF).

"So what have we learned from this Lenovo / Superfish / Komodia / PrivDog debacle? For users, we have learned that the software is pre-installed on your computer can not be trusted, which means that reinstalling a clean operating system standard now procedure must be if someone has bought a new computer, " said Bonneau. The main lesson, he says, for software companies, which must stop intercepting SSL traffic of their users.

Tuesday, 17 February 2015

Cookies Have Life Of 7985 Years



Cookies that websites place on the computers of visitors may 7985 last year, according to international research that was conducted in the Netherlands ( pdf ). The 59 sites were surveyed Dutch total 2089 cookies behind. Dutch media sites on average put most cookies per visitor 42.2. Webshops follow with 25.9 cookies. Dutch websites scoring average this.

It is mainly British media sites (83.1 cookies), French media sites (73.8 cookies) and Danish media sites (75.3 cookies) protruding. The study also specified where cookies come from. In the case of the Dutch sites, there were 607 of the 2089 cookies originating from the visited website. The remaining 1482 cookies were placed by third parties such as advertisers and trackers. Netherlands ends with this agent in the moot.

Websites can also specify if the cookies expire. Two Danish and one British website have their cookies on 31/12/9999 expired. Ie about 7985 years. In total, 15 sites were found to place cookies with a lifespan of over 100 years. The average lifespan of a cookie that is placed by the visited website is 14.34 years. Cookies are not counted over 100 years, then the researchers at two years out.

In the case of cookies from third parties, there was a French website that a third party cookie left behind that 7985 year went along. A total of 15 third parties were found placed 27 cookies with a life of more than 68 years. The average lifespan of any "third party" cookies thus amounts to 1.77 years. Cookies are more than 68 years are not included, the average life is 1.33 years. Most third-party cookies come from Doubleclick.net , which was found on 213 web sites and placed 247 cookies.

"Setting a long expiration date for a cookie does not only mean that the device's usefulness will survive, but the person using it at the time. Although the life of a cookie on a device depends on the purpose for which it was placed, it is difficult for an expiration date in the year 9999 to justify, " says Simon Rice of the UK Information Commissioner's Office.

Monday, 9 February 2015

EDRi Facebook Users Advises AdBlocker


European civil rights organization EDRi has advised Facebook users because of the new privacy policy on the social networking site to Adblock Plus or Ghostery use. These are two browser extensions that Internet users can protect themselves against online tracking.

The new privacy policy, Facebook users collect information from all over the internet and the website and exchanging information with other components such as Instagram. Facebook gives users should have the ability to stop the tracking, but the suggested method is as EDRi very cumbersome and also not the only way.

There is a much simpler option, according to the civil rights organization: installing Adblock Plus or Ghostery. Both plug-ins block not only trackers, but also advertisements. Some websites block therefore users Adblock Plus or give erroneous warnings . According to some experts can ad blocking major consequences have for websites.

Wednesday, 4 February 2015

Durka Malicious App: Apps On Google Play Store Infect Millions With Adware


Researchers have found several apps on Google Play that occur as games, but found to contain a million times and downloaded in reality adware. Some of the apps, including the card game Durka, activate the existing adware only after 30 days.

The adware ensures that when users unlock their device, they get a warning that their device is infected or outdated or full porn state. Then you will be asked to take action. If users are being redirected to come dubious apps and app stores herein secretly send text messages or collect all sorts of personal information. In some cases, users refer to security apps on Google Play.

Anti-virus company Avast thinks the adware distributors get paid for generating traffic to the apps and app stores. "Most people will not find out the cause of the problem and will have to deal with every time ads as they unlock their device," says analyst Filip Chytry. He thinks that most people end up trusting the solution offered, which can lead to more unwanted apps or costs. Besides Durka also involves an IQ test app and an app on the history of Russia. The apps are downloaded together between 5 million and 10 million times.

Hashes:

BDFBF9DE49E71331FFDFD04839B2B0810802F8C8BB9BE93B5A7E370958762836 

Monday, 2 February 2015

AdBlock Plus Would Allow Ads By Google, Microsoft And Amazon


Adblock Plus, by far the most popular browser extension that exists, would ads from Google, Microsoft and Amazon no longer hold back. According to a report in the Financial Times the company would pay the developer of the extension to allow their ads.

Adblock Plus claims to be downloaded over 300 million times. Some 20 million Firefox users and more than 10 million users use Chrome extension. Adblock Plus is also available for other browsers. According to research of Page Fair would be the impact of these and other ad blockers are increasingly felt by websites. Users can easily block ads in this way, allowing websites to lose revenue.

The Financial Times says that Google, Amazon, Microsoft and advertising company Taboola the developer of Adblock Plus paid to whitelist their ads. For example, ads are as in Microsoft's Bing search engine is shown. For this, the developer would be 30% of the ad revenue have asked where the companies agreed upon. Developer EYEO also states that will be transmitted only acceptable advertisements. Google and Amazon, however, want to give response to the Financial Times, while Microsoft has announced that it always gives users a choice when it comes to advertising.

Thursday, 22 January 2015

Facebook Will Warn Users Of Hoaxes


Facebook has introduced a measure to allow users henceforth be warned of hoaxes in their news.According to the social networking site users would have asked for his show fewer messages hoaxes.Facebook regularly false or misleading news spread, which may or may not point to scam sites.

Facebook Hoax Feature
Recently, Facebook has added an option allowing users to report these types of hoaxes. It works the same way as reporting spam and according to Facebook would hoaxes and misleading news reported 2.5 times more than other news. These reports from users are now used by Facebook to let other users know that the messages that they want to share is probably a hoax.

In this way, users would spread the messages slower, which should reduce the number of hoaxes. Facebook is certainly not going to attempt to remove posts and says that it is also about control messages to determine their accuracy. According to Facebook's most publishers on Facebook will therefore none of the update notice, except for a small group which regularly publishes hoaxes and scams.

Friday, 16 January 2015

Google Adsense Used For Malicious Ads


Cybercriminals have used Google Adsense to display ads on all sorts of malicious websites that visitors to these sites for several scam sites by sent. Numerous webmasters complained about the ads that ensured that visitors were redirected automatically.

The scam sites where visitors ended up offered all kinds of products to lose weight, aging combat, combat skin problems or improve IQ. The websites looked like blogs and magazines with so-called scientific studies and research on the products, complemented by all kinds of false responses from people who supposedly had tried the products.

The problem with the malicious ads would play since mid-December, but was last Friday, January 9th widely felt. On the Google AdSense forum, more than 180 responses from angry webmasters inside. Webmasters who use Google Adsense on their websites and see how visitors were redirected by the malicious ads.

On January 10, Google would have solved the problem. According to security firm Sucuri used the attackers behind the attack two legitimate AdSense campaigns, they probably via guessed or stolen credentials managed to hijack. However, it is not excluded that the scammers Adsense accounts have created yourself and initially did occur that it was legitimate campaigns.
Code

Researcher Denis Sinegubko of Sucuri is wondering why Google allows advertisers may use this type of potentially dangerous code. "I realize that Google advertisers flexibility in managing their campaigns and the use of scripts will give their own pages. And I realize that at the first check these scripts did nothing malicious, and is only misbehaved after they were approved. But there would have to be more in control of third-party scripts. "

Sinegubko further notes that nobody likes ads, but they are indispensable for many websites. "I will not tell you to remove all ads from your site," he says to webmasters. "But I ask you to think about the safety and reputation effects that may have bad ads for your site. Consider each script from a third party that you place on your website as a potential threat. Especially those scripts that others who do not knows, allow you to place content on your site. "