4 ms·
Google has served malicious ads at least as far back as last spring: https://www.reddit.com/r/sysadmin/comments/6rm5ig/alert_fullscreen_scam_sites_have_started
by stinky613 9y ago
Google has served malicious ads at least as far back as last spring:
https://www.reddit.com/r/sysadmin/comments/6rm5ig/alert_fullscreen_scam_sites_have_started/ https://www.reddit.com/r/sysadmin/comments/6rm5ig/alert_full...
https://news.ycombinator.com/item?id=14140756 https://news.ycombinator.com/item?id=14140756
- tripzilch 9y agoCool, thanks :) But I'm actually even more interested since when Google started allowing 3rd party javascript, because the moment when it first got exploited maliciously was just a matter of time. I mean I seriously want to read Google's announcement of this "feature", because I'm honestly scratching my head "wtf were they thinking??". Just so I got this right: You can buy a particular type of ads on Google's ad-platform, that will appear on sites and things depending on your target criteria. AFAIK you used to be able control these aspects of the ad: The text shown if it's a text ad, a picture if it's a banner ad, where the ad should link to, and probably a few cosmetic details. Any tracking cookies and analysis would be done either by generic Google Ads javascript (the results of which you can query in your Ads dashboard/control panel) and by whatever additional tracking javascript you set up yourself on the destination site the ad links to. But apparently, at some point, advertisers got the ability to run their own (3rd party) javascript that will get executed on any site that displays your ad. I'm assuming they use a clever subdomain/iframe trick so that the security context of the JS is just that one domain and doesn't UXSS the world. And sure let's assume this is perfectly watertight. If it wasn't we would be talking about worse stuff than crypto-miners. Then still this script is apparently not prohibited from doing whatever calculations (for mining or whatever), accessing whichever browser fingerprinting variables, mouse tracking and whatnot, you can load and execute remote scripts based on this fingerprinting and easily sidestep any of Google's scrutiny whether your script is up to no good. Not that they do this "because it doesn't scale", but it would be useless any way. And then, this script is able to ex-filtrate all this tracking or mining data. I'm aware that disallowing these abilities strictly and securely is just not really possible in JS, there's too many strange ways to access objects and functions, weird tricks, etc. Did I get this right so far? Because I'm really a bit with my jaw on the floor, how the hell did they approve this and not realize it's a landmine? I'm nearly certain that it must be possible to do other nasty tricks besides consuming 80% CPU for inefficient crypto-mining. If it's that many people (by now let's call them zombie nodes or a botnet, which is what Google Ads apparently gives you) all running your code, you can also use them to DDoS a site. But if you're just a dick, you can also attack the people themselves. Most browsers have the cross-domain security down tight, but nearly all of them have multiple "vulnerabilities" that DoS the browser itself, make it unresponsive, make it crash (yeah multiple tabs, even if they have their own threads) or even make the whole system (yeah outside the browser) unstable, unresponsive or crashy. Maybe not your tweaked/bolted down Linux system, but the average user's mildly clogged up Win10, easy. Can these scripts also track and log keypresses or is that somehow separated because of cross-domain / iframe protection? (it's been a while since I got real deep into JS security) Because that would be a vulnerability. So. Many. Possibilities. For. Fuckery.