• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Google DoubleClick Caught Serving Malicious Ad

CommanderFrank

Cat Can't Scratch It
Joined
May 9, 2000
Messages
75,399
A malicious online ad is being distributed through Doubleclick according to Armorize, a web security company. The malware is exploiting three key vulnerabilities generally found on unpatched computers.

It’s not known how many machines may have been infected by the malicious ad or how man web sites have displayed it. Huang says the infections appear to have begun no earlier than Dec. 4.
 
I just went to the "armorize.com" website.... then when I hit their blog my antivirus blocked a trojan. What a "web security" company they are.

Anyways, I wanted to see if I was infected. Based on test: MSE, NOD, etc never found it..... the 2 programs that did are avast and some unheard of "VIPRE" antivirus.

Check your systems guys......
 
armorizesucksafatone.png
 
I cleaned some "persistent" malware from my sister's computer this week. It was called HDD Drive or something like this. It was redirecting her executables, removed her icons from the desk, false proxies in Firefox etc. Malwarebytes in safe mode and then loaded MSE seemed to take care of the problem.

Liquid Cool
 
And this is why many of your customers block your ads.

I have no objection to ads; however, I do object to those ads running JavaScript (because it can be so easily abused by malicious and/or tracking ads). Theoretically noscript allows me to block their scripts without blocking the ads themselves; however, on this site, and many others JavaScript is used to load the ads; therefore, blocking the scripts prevents ads from loading - effectively blocking them. As a result there is no way to allow the ads without also allowing their scripts.
 
the 2 programs that did are avast and some unheard of "VIPRE" antivirus.

Check your systems guys......

VIPRE is actually pretty decent, and has a name in the AV world. SunBelt software makes it, also put out (bought the company that made) Kerio firewall.
 
And this is why many of your customers block your ads.

I have no objection to ads; however, I do object to those ads running JavaScript (because it can be so easily abused by malicious and/or tracking ads). Theoretically noscript allows me to block their scripts without blocking the ads themselves; however, on this site, and many others JavaScript is used to load the ads; therefore, blocking the scripts prevents ads from loading - effectively blocking them. As a result there is no way to allow the ads without also allowing their scripts.

That's been my complaint with most ads as well. You shouldn't need to allow javascript to see ads. There should also be a special type of safe Flash file format for advertisers using Flash ads. Maybe where scripting isn't allowed in the Flash plugin.
 
VIPRE is actually pretty decent, and has a name in the AV world. SunBelt software makes it, also put out (bought the company that made) Kerio firewall.

Ahh, I know someone that actually works there. They're based in Clearwater.
 
no script is good.
but i always web browse in a sandbox so i usually disable no script. there's almost zero reason to browse the web without a sandbox.
 
Ouch. I used to work for them. Did they change procedures? Because when a client sends in an ad, i pretty much take it apart and re-code it line by line to work with the tracking system (I even have to redraw some of the graphics the clients sent because of size restrictions). How the hell does a trojan get through???
 
Ouch. I used to work for them. Did they change procedures? Because when a client sends in an ad, i pretty much take it apart and re-code it line by line to work with the tracking system (I even have to redraw some of the graphics the clients sent because of size restrictions). How the hell does a trojan get through???

by exploiting the ad server.
 
Is this really news? Hasn't this been the major avenue used for malware for the last several years? I remember an article about MLB.com that had an ad infecting people, and it only did it at certain times of the day. Apparently, the buyer of the ad was allowed to update something, like for price changes and promotions, but that was enough to insert a link to a bad website and hijack the browser.

I've been a proponent of noscript ever since I found it. When there was a disagreement between it and Adblock, I thought about it, and dropped Adblock. I figured that it was short-sighted and selfish to just block ALL ads, but I certainly did not want scripting allowed to run from untrustworthy sites. Blocking scripting removes all that was annoying about ads anyway. I get no pop-outs, sounds, or videos in my ads. I often tell people who ask be about some web-ad thing, "I don't surf your internet, I don't see that."

90-95% of all browser vulnerabilities I read about take advantage of scripting, usually an advertiser. Advertisers like Doubleclick need to just stop using scripting completely. It is really amazing how many major flaws and zero-day exploits are just incapable of running when promiscuous scripting has been blocked.

I trust scripting run from hardocp servers, but all the ads are from elsewhere, and I don't see them since they require scripting. I did donate since I wanted to show support for my favorite site, so at least I cannot be called a hypocrite like so many others that just block ads completely.

So, if you just use Adblock, ask yourself why, and would noscript be a better add-in to use. Adblock is a blacklist, noscript is a white list, it needs no updated list of sites.
 
I use no script as well, and only allow trusted sites. I find it hilarious that sometimes one page will have 10-15 different domains trying to runs scripts on my machine. I consider it very rude for webmasters to do this.
 
Back
Top