madison

Malware delivered by Yahoo, Fox, Google ads

Elinor Mills CNET News | March 22, 2010 1:26 PM PDT

Summary

Malware that exploits holes in popular applications is being delivered by big ad delivery platforms including those run by Yahoo, Fox, and Google.
Malware that exploits holes in popular applications is being delivered by big ad delivery platforms including those run by Yahoo, Fox, and Google, according to Prague-based antivirus firm Avast.

Viruses and other malware were found to be lurking in ads last year on high-profile sites like The New York Times and conservative news aggregator Drudge Report.com, and this year on Drudge, TechCrunch and WhitePages.com. The practice has been dubbed "malvertising."

Now, researchers at Avast are pointing fingers at some large ad delivery platforms including Yahoo's Yield Manager and Fox Audience Network's Fimserve.com, which together cover more than 50 percent of online ads, and to a much smaller degree Google's DoubleClick. In addition, some of the malicious ads ended up on Yahoo and Google sites, Avast claims.

"It's not just the small players but the ad servers connected with Google and Yahoo have been infected and served up bad ads," said Lyle Frink, public relations manager for Avast.

The most compromised ad delivery platforms were Yield Manager and Fimserve, but a number of smaller ad systems, including Myspace, were also found to be delivering malware on a lesser scale, Avast Virus Labs said.

For more of this story, read Malware delivered by Yahoo, Fox, Google ads on CNET News.

Talkback Most Recent of 17 Talkback(s)

  • Beads and trinkets
    Cool new things that pays for the "free" and "open" stuff.

    Seems pretty evil.
    ZDNet Gravatar
    hill60
    22nd Mar 2010
  • There's no doubt. Why doesn't this story get more traction?
    I wonder why this story isn't bigger? There is no doubt in my mind that these ad servers attempt malware delivery on occasion. These ad server companies hide behind their 'agreements' with their paying 'clients' ("we state in our agreement that the client isn't allowed to do bad things"), and don't want to do the work to carefully check what they deliver on behalf of the client. ** I think what they need is a big class action lawsuit to wake them up **
    ZDNet Gravatar
    batpox
    22nd Mar 2010
  • ZDNet Gravatar
    eMJayy
    22nd Mar 2010
  • No Script is nice, but.....
    ....is only a partial solution. Another part of that solution is the Firefox addon Ad Blocker Plus. For example the filter rule:

    http://*.doubleclick.net/*

    block anything and everything from that site.

    I never surf with out Ad Blocker Plus and No Script.
    ZDNet Gravatar
    fatman65535
    23rd Mar 2010
  • RE: Malware delivered by Yahoo, Fox, Google ads
    in Women , Juniors , Accessories , Style Expert: Allbyer.com We're always mindful of fashion that's in it for the long haul - those pieces you grab and go without fail every time, that, like a good friend, just couldn't be more reliable. Though a trendy handbag is a fun choice for, say, an evening out, an everyday bag that meets your everyday needs is a wardrobe must. We're eyeing neutral bags that move from month to month with ease, that suit every possibility with style and that make your life much easier with a host of functional details. Check them out: NIKE SHOX,JORDAN SHOES 1-24,AF,DUNK,SB,PUMA ,R4,NZ,OZ,T1-TL3)$33,HANDBGAS(COACH,L V, DG, ED HARDY)$35TSHIRTS (POLO ,ED HARDY, LACOSTE) $16 Bikini (Ed hardy,polo) $25 http://www.Allbyer.com FREE sHIPPING
    ZDNet Gravatar
    James19862010
    22nd Mar 2010
  • ZDNet Gravatar
    fairportfan
    23rd Mar 2010
  • ZDNet Gravatar
    eggmanbubbagee@...
    22nd Mar 2010
  • Malware delivered by Yahoo, Fox, Google ads
    I wonder if Deviantart.com serves any of these ads. I got two viruses in one day. And these are so hard to point out to the website admins because I don't look at the ad before it slips the virus or malware onto my computer. I don't know if it did it when it was first called or when the page goes to the next ad. And I have no clue where those fake antivirus popups come from.
    ZDNet Gravatar
    Jared Neale
    22nd Mar 2010
  • Adblock plus NoScript
    Does it block 100% of ads 100% of the time? No. But it's a pretty darn effective combination.

    Once the old "IE7 Pro" addon for IE no longer really worked in IE8 the same way it used to, I switched to FF full time.
    ZDNet Gravatar
    ZStoner
    22nd Mar 2010
  • What's ironic is...
    ...the last time I visited the "IE Pro" forums, it was full of spammers who spammed the forums full of junk for Viagra, drugs and the like.

    The IE Pro developers abandoned IE Pro support and updates about a year ago. So much for that.

    Once the old "IE7 Pro" addon for IE no longer really worked in IE8 the same way it used to, I switched to FF full time.
    ZDNet Gravatar
    still not nice
    23rd Mar 2010
  • Eh?
    The IE Pro developers abandoned IE Pro support and updates about a year ago. So much for that.


    From http://www.ie7pro.com/

    IE7Pro 2.4.8 has been released on Mar 22,2010
    ZDNet Gravatar
    Hallowed are the Ori
    24th Mar 2010
  • LOL - Well speak of the devil...
    Gee, day before yesterday, too... lol... grin

    Hanging on by their fingernails.

    Of course their forum is still tanked...

    http://forum.ie7pro.com/viewforum.php?id=4
    ZDNet Gravatar
    still not nice
    24th Mar 2010
  • RE: Malware delivered by Yahoo, Fox, Google ads
    I ranted about this at this story a couple weeks ago on Arstechnica where they were trying to defend Ads on websites.

    arstechnica.com/business/news/2010/03/why-ad-blocking-is-devastating-to-the-sites-you-love

    I dont have issues with Ads. Sites need to make money. I do have issue with the security hole that is flash and all the damn ad providers who pay no attention to the content they are delivering. I directly blame these Ad aggregators.
    ZDNet Gravatar
    jimk_z
    23rd Mar 2010
  • Ad blocking
    This is why I block ads at my proxy server. I occasionally run into problems--I quit using CheckFree because pages would not load correctly unless I allowed their ads--but I hardly ever see malware any more.
    ZDNet Gravatar
    cburkitt2
    23rd Mar 2010
  • RE: Malware delivered by Yahoo, Fox, Google ads
    gee. this is news? Just fire up currports and watch
    when one of these sites downloads. Torrents of
    connections open, then more and then MORE... and
    *your* site is one of the worst. AND THEN THERE IS
    HOTMAIL. If I use my passport on hotmail then it
    redirects to ninemsn, then I am hacked. A toy for the
    local MS crew and their mad billionaire puppetmaster
    and his stooges. And if I use my router to stop
    backwash connections, oooooh they don't like it. Some
    of them reset my router - thats how I know who the
    baddies are - block their IP's and they reset my
    router. Twice in one hour one time. Heh - so much for
    stealth and light finguhs. And then there is the
    CONSTANT dns hijacking. AAARgggh - the internet is an
    idiots and stooges playground, why? because the BIG
    BOYS DONT LIKE FREE - they want their pound of flesh
    and will do anything to get it - even betray their own
    countries and countrymen.

    traitors

    its about time we had some properly engineered reviews
    of routers and OS's instead of the payola brochureware
    foist upon us by lazy inept stooge journo's - get off
    your asses and work - properly assess and report
    security issues with hardware and software. Get DNS
    changed to secure DNS. MAKE MS REWRITE WINDOWS INTO A
    SECURE OS instead of just bloat it out with dwm.exe
    for a bit of shiny chromey fluff. Keep the bastards
    honest.

    Come on, get some balls and WORK you scumbag 'journos'
    and effect some real change instead of letting a blog
    or talkback do your job - you GUTLESS WONDERS
    ZDNet Gravatar
    walkerjian@...
    23rd Mar 2010

Talkback - Tell Us What You Think

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity