Forum Moderators: phranque

Message Too Old, No Replies

Fake Malware Alerts Becoming More Common

         

engine

3:14 pm on Mar 10, 2010 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Are fake malware alerts becoming more common. You know the sort, they pop up looking like a common dialog, such as Windows alert, indicating malware or trojan detected. If you're not careful, i'm sure there's a payload by clicking the wrong button.

I've seen this happen on a number of well known sites, including a site in a SERPs record on google (that site is now gone from the index).

Now, it seems that the Drudge Report is included in this.

[news.cnet.com...] Drudge denied that his site was infecting visitors, however it's likely that the malware is coming from ads delivered by a third-party ad network and not the site itself.

The two most high profile sites I can think of serve ads. Is this the new way to deliver payloads? If it is, it must be costing money, unless the scammers have compromised the ad network.

What's your view? Are we now set to have to battle malware ad phishing? This is all becoming too tedious for words.

lammert

12:24 pm on Mar 11, 2010 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I have had this happening on one site in November 2005 when the freebee stats counter I used was bought by an ad company. They changed the JavaScript stats code in such a way that it loaded a popup ad to each visitor. They carefully had programmed it to show only one ad per month to each visitor. This caused every new visitor to see the popup ad as soon as they hit my site, but I as a site owner saw it only once and thought that it was caused by one of the other browser windows I had opened at that time. Only when the media started to write about this deceptive popup serving campaign I realized that my site had been a victim and I immediately removed the stats counter.

Because of this incident I now only use JavaScript utilities hosted on my own servers, or from reputable companies like Google and Yahoo. I only serve third party ads with fixed links to banners and landing pages, no dynamic loading anymore for me.