Skip to content

Biting the hand that feeds IT

The Register ®

Security:


Related Whitepapers

Comments on ‘Rogue ads infiltrate Expedia and Rhapsody’

When legit sites attack

Published Wednesday 30th January 2008 21:53 GMT

« Back to article page

Ways and Means of Protection 

By Morely Dotes
Posted Wednesday 30th January 2008 22:38 GMT

"If you've got a good suggestion for ways users of other browsers can protect themselves, please leave a comment"

1. Don't use Internet Explorer on the Internet. Seriously. Microsoft has integrated it into the OS, so if IE is compromised, your compute is compromised.

2. Go to http://mvps.org, search for "hosts" and install the hosts file provided by MVPS. It won't stop your browser from running scripts, but it *will* stop your computer from accessing thousands of known malicious Web sites.

3. Boycott any site that permits shockwave or flash advertising banners. That's simply irresponsible site management.

Install Firefox with Adblock plugin 

By Tim
Posted Wednesday 30th January 2008 23:07 GMT

Installing the hosts file will help quite a bit, but to be safe, install Firefox and the Adblock plugin

Pointless 

By Will Godfrey
Posted Wednesday 30th January 2008 23:37 GMT
Stop

All the people on here have either already been hit with the cluestick, or are the ones wielding it.

boycott what eh? 

By Anonymous Coward
Posted Wednesday 30th January 2008 23:39 GMT
Linux

"3. Boycott any site that permits shockwave or flash advertising banners. That's simply irresponsible site management."

You're suggesting we boycott ELReg then. OK so those are The Register's own ads for that symposium thing, but they are flash.

Re: Ways and Means of Protection 

By Anonymous Coward
Posted Wednesday 30th January 2008 23:42 GMT
Stop

Regarding your third point, from memory El Reg servers up said Flash banners (I've been using AdBlockerPlus for some time now....).

Practice as you preach? ;-)

Ha! 

By Brent Gardner
Posted Thursday 31st January 2008 00:13 GMT
Happy

1) Your an arsehole if you run any AV program, much less installed from an advert on a website. AV is dead technology, and they can't keep up with the tide of new malware.

2) Disabling flash is a valid alternative. Flash was always crap used mostly for adverts.

3) F*ck adblock. Just edit your hosts file to block *.doubleclick.com and *.doubleclick.co.uk and you will removed 99% of ads from IE or Firefox.

let me see 

By Pete
Posted Thursday 31st January 2008 00:27 GMT
Happy

I got one of these today actually. it served up a very convincing dialog box that look just like any other Windows XP dialog, telling me that to view content on the site I need to download and run setup.exe

Problem

This dialog box looked nothing like the standard dialog boxes Mandriva Linux produces, so I could immediately see it was fake, and even if I had tried to run the program, I doubt it would have infected me.

When I am forced to use Windows XP I turn off the fancy graphics, luddite that I am, so even using windows I would have noticed the difference.

Obviously apart from the fact I would not have been so stupid to install something from a popup anyway, there are huge advantages to running an OS that is not Windows.

I know, cliche linux fanboy post, but it did have to be said.

@Brent Gardner 

By TrishaD
Posted Thursday 31st January 2008 09:11 GMT

'Your an arsehole if you run any AV program, much less installed from an advert on a website. AV is dead technology, and they can't keep up with the tide of new malware'

So major corporations with access to the internet ALL spend a great deal of money each year on nothing at all?

Sorry - but this is an entirely unhelpful comment fairly typical of the 'I'm a smart technician and anyone non-technical is an utter cretin' sort of mentality that blights these comments pages...

If I buy a car I have no expectation that I should have to do anything more arduous than fill it up with gas and take it for a service every six months or so. The internet is not some propellor heads' playground, its a tool used by millions of non-technical people every day to go about their business and have fun.

Telling them NOT to buy AV products is really not helpful....

admuncher 

By robert
Posted Thursday 31st January 2008 11:02 GMT

although its commercial software Admuncher is really good. Parses all the html before it gets displayed and removes all banners, adverts, popups etc etc a lot better than adblock, and also removes ads from messenger etc.

Think it cost me about a tenner, had it since 2002 and best bit of software ive bought in a while. I signed up for theyre partnership thing too.

http://scotland.admuncher.com

Advert Blocking 

By A J Stiles
Posted Thursday 31st January 2008 12:19 GMT
Linux

Frankly, I'm surprised that broadband resellers are not offering advert-blocking as a premium service. For an extra tenner or so a month, you would get all known advertisement-farm servers blocked by a transparent proxy server; and access to a page where you can upload the URLs of sites still displaying adverts despite the ISP's best efforts (this probably would require human intervention; but so does staffing a help desk, and the rôles could be combined: when not answering the phone, help desk personnel can be checking out advert servers).

@TrishaD

"So major corporations with access to the internet ALL spend a great deal of money each year on nothing at all?" -- YES. They are paying for Windows, for crying out loud, when there are superior alternatives available for the taking. Anti-virus software only exists at all because of the way Windows works. Windows never used to have such a thing as privilege separation; so historically, programmers have assumed and expected that every user would be privileged. This causes a lot of legacy applications to break if run as a non-privileged user. And the idea that nobody else is ever going to see the Source Code has led to some incredibly sloppy programming (_vide_ OpenOffice.org 1.x for a particularly egregious example of this).

Windows apologists will gleefully rush in here to point out that there are threats against which unix-style privilege separation or access to Source Code won't protect you. To which I can only say: That is true, but neither will anti-virus software, so what's your point again?

Getting the ads taken down 

By Anonymous Coward
Posted Thursday 31st January 2008 14:51 GMT

Now I've visited one particular, reasonably well-known and reputatable, site in the past year which has several times tried to force WinFixer (dubiousware) on me. I have not yet been able to be taken seriously by the site owners when I report it. They just tell me I must be mistaken. Theirs was the only site affected, and the spurious error could even be (mostly) reproduced by clearing cache and revisting them a few times.

If sites running bad ads won't heed warnings from well-meaning site visitors, these things will remain visible for longer.

PS. I have about 8 entries in my hosts file which block 90% of all ads I find annoying. How anyone can actually read an article without being distracted by the aeroplane or rocket flying past in the adjacent ad, I don't know. I can't block the Flash/ads at work, but have pestered our IT folks about it.

@ A J Styles 

By TrishaD
Posted Thursday 31st January 2008 16:45 GMT

My point is that the majority of large organisations who deploy AV dont suffer from virus attacks.

The same way that the vast majority of home Windows users who deploy AV dont suffer from virus attacks.

Yes, AV is reactive. But saying that it doesnt work is crass. In my opinion, of course.....

mainstream destinations that include [ ... ] Blick 

By Anonymous Coward
Posted Thursday 31st January 2008 18:38 GMT
Coat

"Blick"? Never heard of it. Is that some kind of South African website?

Yes, I'll get my coat. Sorry to be such a boer.

whitepaper title

Server Consolidation and Containment

This paper discusses how consolidation and containment solutions with a virtual infrastructure meet the challenges of server sprawl and underutilization..
whitepaper title

Making Green IT a Reality

Customer Perspectives on the Impact of Storage Vendor Decisions on Power, Cooling, & Space in Enterprise Data Centers.

Top 20 storiesAll The Week’s HeadlinesArchiveSearch