Latest Comments
"it's good one "
by khanbhai | Nov 22, 2008 9:00 PM
 
"when i login to face book it tells me i am cookies enabled what does this mean"
by celeste | Nov 21, 2008 5:15 PM
 
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"Umm. no. The 6.5 product is mounting the offline VM image and performing a scan for patch ..."
by eric | Nov 20, 2008 8:15 AM
Web

Malicious ads infect Expedia and Rhapsody

  • Email a Friend
  • Print Page
Malicious ads infect Expedia and Rhapsody
By Shaun Nichols
Feb 1, 2008 9:35 AM
Tags: "Expedia" | "Rhapsody" | "malware" | "flash | malware" |
Security firm Trend Micro said that the ads appeared as Flash media-format files on the sites.

Users clicking on the ads were redirected to malicious sites which then attempted to install a rogue anti-spyware application.

A spokesperson for Rhapsody owner RealNetworks said that it had first received reports of the ads on 20 January.

The company conducted its own investigation and the malicious files had been removed by 24 January.

The malicious Expedia ads, which advertised a music download service, were disclosed on 28 January by Australian spyware researcher Sandi Hardmeir, who notified the company immediately.

An Expedia spokesperson said that the ads have been removed, and that the company is investigating how long they were online.

Ad firm DoubleClick fell victim to a similar attack late last year which resulted in malicious ads appearing on official sites belonging to Major League Baseball, National Hockey League and The Economist.

"This provides yet another method for cyber-criminals to effectively spread malicious code and earn illicit profits at the same time," wrote Trend Micro researcher Bernadette Irinco on a company blog.

"There is no doubt that cyber-criminals will continue with their 'malvertising' campaigns, targeting more and more popular sites to 'advertise' their malware."

Ad networks have long been locked in a struggle with the purveyors of malicious software.

Malware dealers often use bait-and-switch tactics, presenting the network with a legitimate ad which is later replaced with a malicious file.

Copyright © 2008 vnunet.com

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Vulnerabilities & Exploits Whitepapers