Alert: Large Scale Web Ad Poisoning!

 

From Techtalk at PCPitstop: Weather.com and Drudge Report (to name just two) sites with millions of visitors were serving up ads with CryptoWall ransomeware, or infected adware on PCs.

“Once an ad network is subverted, hundreds of millions of poisoned ads are displayed in real-time. Many of these ads initiate a drive-by attack without the user having to do anything. The attack does a few redirects, kicks in a U.S. and Canada-focused Exploit Kit which checks for vulnerabilities (usually in Flash) and infects the workstation literally in seconds.” – PCPitstop

So what should you do?

So here are a few things you can do about this.

First, disable Adobe Flash on your computer - or at least set the Adobe Flash plug-in to "click-to-play" mode - which blocks the automatic infections.

Second, keep up-to-date with all the security patches and install them as soon as they come out.

Third, download and install Ad Blocker plug-ins for your browser, these prevent the ads from being displayed in your browser to start with. These ad blockers are getting very popular, hundreds of millions of people use them

In a network, you could decide for two things:
1) Get rid of Flash all together, we see this happen a lot, or

2) deploy ad blockers using group policy, here is a forum post at the AdBlockPlus site where it is explained how this can be done. I use Adblock Plus in Chrome and am a happy camper. Link: https://adblockplus.org/forum/viewtopic.php?t=29880

NoScripts is also good, but honestly…it’s time to kiss Adobe Flash goodbye, as I’ve said before.

*My thanks to teddybearcholla for sending me this!

 

Source:

http://blog.knowbe4.com/scam-of-the-week-massive-webad-poisoning

52,253 views 14 replies
Reply #1 Top

Nice to know that my paranoia has put me ahead of the curve. I do all of the above. Thanks Seth and teddybearcholla for the warning.

Reply #2 Top

I would ask if there is a replacement for flash?

 

There are several sites I use that require it.

Reply #3 Top

Green Lantern comes to mind...

Edge (no, not the browser) - http://www.geek.com/news/adobe-release-their-own-html5-flash-replacement-app-called-edge-1408181/

Mozilla has "Shumway" in Firefox: http://www.neowin.net/news/adobe-flash-player-replacement-shumway-lands-in-firefox-27

 

Reply #4 Top

Quoting DrJBHL, reply 3

Green Lantern comes to mind...
End of DrJBHL's quote

Never saw it, heard it was good.

 

Thanks, Doc.

Reply #5 Top

Ah, that Egde seems to be a dev tool. Not gonna help me.

 

Also, seems that Adobe Flash is embedded in IE on Windows 8.1.

 

How do we get around that?

Reply #6 Top

What about Firefox with Shumway? 

A huge problem is that devs keep developing apps using Flash...what can I say? Give the latest FF a try?

Reply #7 Top

I couldn't find the green lantern thingy...except as a flashlight app.  

Reply #8 Top

Lol, Barb...it was a reference to the super hero...Jim asked for "instead of Flash"...

+1 Loading…
Reply #9 Top

Quoting DrJBHL, reply 6

What about Firefox with Shumway? 

A huge problem is that devs keep developing apps using Flash...what can I say? Give the latest FF a try?
End of DrJBHL's quote

I'm afraid even on Windows 10, I prefer IE.

 

FF, Chrome, and the rest, nah, I'll pass.

Reply #10 Top

Flashblock in FF even blocks YouTube vids which appear to be HTML5.  Others seeing that?

Reply #11 Top

Quoting DrJBHL, reply 8

it was a reference to the super hero...Jim asked for "instead of Flash"...
End of DrJBHL's quote




Reply #12 Top

Quoting DrJBHL, reply 8

Lol, Barb...it was a reference to the super hero...Jim asked for "instead of Flash"...
End of DrJBHL's quote
....   Well you just never know, do you!! :sun:

Reply #13 Top

Adobe Flash Player is not in my browsers...IE and Chrome (default)

Reply #14 Top

Quoting DrJBHL, reply 8

Lol, Barb...it was a reference to the super hero...Jim
End of DrJBHL's quote

 

WOW!! You think I'm, wait.......  X|

 

I thought you said stupor hero. Oopsie!   :(