Jump to content

Info Only - Google Ads


chrisinth

Recommended Posts

As the title says, this is information only and not a complaint.

This morning when I opened ThaiVisa, my Internet Security (Norton) kicked in with a malware alert. I recognize this as a false positive, however it appears that Google have become more aggressive with their analytic 'spiders' or whatever technology is flavor of the day now. First time Norton has picked this up (set to ignore now anyway).

This was using IE 11, Chrome doesn't alert, but I am using Ad Blocker with Chrome and it still shows between 4 and 11 ad blocks on the TV pages.

The main reason I mention this is because of the spate of complaints about ads on the site. Even I have had my browser (s) freeze while changing pages, and always on a google related link. Not sure if TV can do anything about that though.

post-76988-0-98199300-1424393908_thumb.j

post-76988-0-20348900-1424393927_thumb.j

post-76988-0-64018000-1424393941_thumb.j

Edit: I left the destination address in the snapshots as it isn't showing a global IP address.

Edited by chrisinth
Link to comment
Share on other sites

Normally, malvertising is spawned by 3rd-party advertisers who furnish legitimate graphic+code based adverts from an off-site server then switch them out for malicious ones later.

Very unlikely the issue originated with Google, but somewhere along the way from them to you their "Analytics.js" JavaScript code was intercepted, modified, then delivered on to you as if nothing happened.

All it takes is injecting two short lines of javascript code into any javascript delivered to a webpage -- and if accepted, the browser caches that code and the attacker can now own your browser activity for the life of that cached code (until you force its erasure by clearing browser cache).

The latest attack vector for this scheme is via Proxy Services, as they are in the perfect position to play the "Man" for the Man-in-the-middle scheme/attack.

While you may not be using proxy service for your system, many ISP's use them, and they get 'owned' from time to time.

Don't forget to wipe the cache on all of your browsers.

Started by phazey, Yesterday, 21:02
Link to comment
Share on other sites

  • 3 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.






×
×
  • Create New...