Online ad giant Adform was hacked, proving once again why ad blockers are needed (this.weekinsecurity.com)
183 points by speckx 5 hours ago
strictnein 5 hours ago
Probably should just link to the security researcher's post, since it's far more informative:
https://doublepulsar.com/adform-compromised-to-serve-crypto-...
giancarlostoro an hour ago
The bitcoin wallet swap thing that these malware scripts often push, how effective is it? It just seems so niche, if I'm doing stuff with my crypto wallet, I'm more likely to do it from my phone where I wont be copying and pasting to and from a web browser, maybe a webview if anything? I always double check the characters match up anyway... I am just shocked the level of effort for the most niche hack.
harvey9 16 minutes ago
Another comment noted over 100,000 USD passing through an associated wallet. I don't know how much work went into this but my hunch is it has paid off pretty good even compared to legit tech work.
__MatrixMan__ an hour ago
Ads are malware. It's not really surprising when they're found to be bootstrapping other malware.
werds 5 hours ago
Are the crypto addresses known/recorded anywhere? would be interesting to see on the blockchain how much was stolen this way.
strictnein 4 hours ago
The code in question is here: https://pastebin.com/raw/mc7psaNF
It appears to be normal Adform code plus two appended chunks at the end.
Bitcoin: bc1qmplgt0hcg62jc2guz86wn2sms7tqrsulkkrrls
Ethereum: 0xE7983E69df17079ADb0aD7b3458488Cac0dBc573
TRON: TW4AgGnDc2Pk6YAynCtjCKzoKYWPg7nJe (?)
Edit: Activity for those addresses:~$110k bitcoin
https://www.blockchain.com/explorer/addresses/btc/bc1qmplgt0...
~$55k in ETH
https://www.blockchain.com/explorer/addresses/eth/0xE7983E69...
xkcd-sucks 3 hours ago
It's absolutely nuts that there's so much volume of low effort cryptocurrency transfers that replacing clipboard contents with a different wallet address on people not blocking ads on a specific ad network nets anything at all
tamimio 4 hours ago
Ad blockers at dns level too, not just browsers. A lot of people don’t even know how to block them, check your parents or kids (or non technical people in general) phone and you will see how they are riddled with ads. I had a dns blocker installed on my parents phones and in around 6hrs it blocked 10k queries from 3 apps only..
binaryturtle 3 hours ago
I personally also block access by web browsers to non-standard ports (aka not :80 or :443) via an app firewall (Little Snitch here). In this case it would have warned me when the compromised script would have called home to that endpoint on the non-standard port.
Gotta tackle such issues at different places all at once for sure. It's like wearing 5 digital condoms at once. Too bad there's still some leakage somewhere for sure. B)
Cider9986 3 hours ago
DNS level is more secure but less effective because apps and website can serve the essential content on the same domain as the advertisement. It will also become less effective over time.
YouTube does this, so you need to use a browser-based ad blocker.
inigyou 3 hours ago
Let them eat cake. Setting up that ad proxy stuff is a bunch of work that many websites won't do.
functionmouse 5 hours ago
I have a feeling everyone with understanding of the situation or even a vague malaise opening a news article and being bombarded with popups that intercept their attention knows why ad blockers are needed, and any perceived "discourse" to the contrary is one sided, from the ad agencies and media platforms that largely and subversively direct the narrative.
It's getting harder by the day to tell sentiment apart from narrative.
ksenzee 5 hours ago
"You will be annoyed" and "you will be served malware" are two different classes of need. The first is enough to get me running Firefox/uBlock Origin on my own devices. The second is what got me to run it at work.
amelius 4 hours ago
Nobody wants ads (*) but somehow they are never banned.
Makes you wonder, are we living in a democracy or not?
(*) shown at inconvenient moments and tracking the user; yellow pages were fine
RajT88 3 hours ago
I do not recall ever hearing of an organized effort to ban ads. These days, good luck getting bipartisan agreement, especially with all the dark money in politics being legalized and normalized.
That said... The modern internet is built off many free services paid for by people who buy stuff from ads. It is hard to imagine a world without ads - many sites and services would disappear. Hosting costs money.
I could see a dystopia without ads where a government provides free hosting for citizens. That quickly becomes "thought police" when an authoritarian leading head of state comes in. If we pretend like that will not happen, I think we would have a much more wonderful internet.
amelius 3 hours ago
pavel_lishin an hour ago
Marsymars 2 hours ago
functionmouse 3 hours ago
inigyou 3 hours ago
nashashmi 3 hours ago
Websites being hacked does not necessitate ad block. It necessitates better browser security. The title here is fallacious. I say this in all fairness as someone who uses adblock extensively, where I don't even like cookies being held by ad companies.
helterskelter 2 hours ago
A secure browser that loads an ad doesn't prevent you from being surveilled. Tor mitigates this to a large degree but doesn't entirely eliminate it. The only real solution is to block ads altogether.
This is a silly distinction anyway. Blocking ads is an obvious first step to improving browser security.
voxleone 3 hours ago
>>Websites being hacked does not necessitate ad block
Their users do.
worldthruword 3 hours ago
CrowdStrike Outage means we need better Windows.
jiveturkey 34 minutes ago
indeed. the post may as well be, javascript must be disabled.
TZubiri 36 minutes ago
until the adblockers are hacked
shevy-java 3 hours ago
The sad thing is that we need adblockers in the first place.
Granted, even in the 1990s there were ads; I remember blinking banners and what not. But often the underlying website was still fine as such.
Fast forward some years. Now if you look at e. g. medium.com but many other websites, you are CONSTANTLY bombarded with pointless pop-ups, slide-ins, and pester-naggers. No I do use ublock origin (it works on thorium by default) so I only get very few ads, but many websites just pursue a strategy to piss off visitors. I do not understand this. If you want anyone to read your content, do not pester them at all. Nowadays when a slide-in appears that sneaks through ublock origin, I don't even let ublock origin block it, I just insta-close that tab. Cookie accept banners fall into the similar category, though some add-ons help with that.
IG_Semmelweiss 11 minutes ago
>>> Nowadays when a slide-in appears that sneaks through ublock origin
Does that really happen ? I don't know what this is
Note: I have Ublock set with no JS permissions by default, so maybe that's why i never see a slide-in menace ?
dylan604 an hour ago
> Granted, even in the 1990s there were ads;
the ads in the 90s were served by the same server of the site you were browsing. those ads were images. today's ads are from 3rd party servers running arbitrary JS code that the server of the site you are browsing knows nothing about how it works. ads from the 90s while possibly obnoxious and annoying were not able to be malicious as ads from today.
dabbz 3 hours ago
My least favorite ones are the ones that fit in the rails to the left and right of the content that scroll with you. You can't click anywhere without an accidental ad click. Using any device without ublock reminds me just how much better life is with it...
datakan 2 hours ago
I read an article a while ago about some scientist who decided that he wanted to go around investigating a certain species of leech that lives inside a hippo's butt, like attached directly to the colon. He suggested that, as big as the hippo is, it probably wasn't really all that aware that the leeches are even in its butt, but that's where the leech likes to be because there's a good source of blood there for the leech to feed on.
Now, the scientist is probably right, the hippo probably goes its whole life not really knowing that it has all these leeches in its butt. It might feel a little pain in the butt, but the hippo probably isn't concerned with why that pain is there, much less how or even if it can get rid of it, it's just something that the hippo has always lived with. The hippo accepts that one of the facts of daily life is that you just need to live with some pain in your butt.
Now, imagine (and believe me, this is a hypothetical), if the hippo let someone root around inside its butt and remove every one of the leeches, and even stop any others from attaching. It might take a day or two to get used to and get back to normal, but the hippo would wake up one day and realize that it no longer has a pain in its butt. It can still do everything it used to do, it can frolic in the water, it can roam around and find the tender little pieces of grass, it can do that thing where it poops and swishes its tail around to spread it all over its neighbors, and it realizes that it can do all of those things it likes without having that pain in its butt.
Now, maybe the leeches could talk. Maybe the leeches talk to the hippos and they say things like, listen, hippo, my life cycle depends on you letting me get into your butt when you're in the water. I need to drink your blood and drop out some eggs, so that other leeches can be born and start the cycle all over again. It's not really a big price you pay, I mean sure, there's a little pain in your butt, but I need you to do this. If you want to get in the water, it's just something you have to deal with. It's the price of admission. If you get in the water without letting me in your butt, it's like you're stealing the water.
I bet that the hippo would hear that, and would still want to continue going about its day without any pain in its butt. I don't think the hippo would feel very sorry for the butt leech. Sure, maybe the butt leech contributes to the aquatic ecosystem, maybe its eggs or the dead leeches get eaten by other things and fertilize the grass that the hippo likes to eat. But, if the leeches weren't there, the grass would just find other nutrients. Even though the leech is trying to argue that it's a necessary part of this ecosystem, it's actually just a pain in the butt. In reality, despite what it tells everyone else, the major beneficiary of anything that the butt leech does is the actual butt leech.
Anyway, I just had a thought that advertisers kind of sound like hippo butt leeches.
flerchin an hour ago
This is internet gold and makes me believe in people again.
FLeXMurphy 2 hours ago
>god-i-wish-that-were-me.jpg
flerchin an hour ago
>If you want anyone to read your content
Reading the content is really not necessary, but the business is predicated on selling ads.
Batman8675309 2 hours ago
FYI Thorium is updated once every 3 months or so. Not exactly the safest thing in the world.
cyanclouds 3 hours ago
Finance and Media = annoying ass industries
Think of a typical news site with millions of ads flying in as you try to read - they are the causers of this shit ad world
Look what happened to YouTube after the news showed up there.
Look at the clusterfuck that is housing and banking.
Compare how any other vertical is ran by the main players vs Finance and Media - the two most shittily ran industries in the West.
jimt1234 3 hours ago
Browsers should not have access to the clipboard.
afarah1 2 hours ago
You can disable it on Firefox by setting dom.event.clipboardevents.enabled to false. I haven't had any issues with it.
Someone shared the code in the comments, it uses 'copy' and 'cut' event listeners, so disabling this setting would have prevented the exploit regardless of an adblock.
inigyou 3 hours ago
It's you versus Google on that one. Who will win?
shevy-java 3 hours ago
Well, it's not just him.
It's Google versus Mankind.
Mankind will eventually prevail against Evil. Google pissed off too many people now, you only need to look at reddit's degoogle subreddit.
still_grokking 2 hours ago
inigyou 3 hours ago
tgv 3 hours ago
Nor USB devices, nor the screen size, nor ... They can access way too many parts of the OS. But almost nobody cares, as long as they have their shiny feeds and videos.
schaefer 3 hours ago
What?
If copy and paste is disabled in my default browser that would be something like 80% of my total of my total use cases for the clipboard in the first place.
tpoacher 2 hours ago
They're not saying your manual copy/pasting from a browser window onto your clipboard shouldn't be possible; they're saying the browser itself shouldn't allow this functionality to be scriptable internally.
The former is a system event, not a browser one.
This is similar to how on google docs if you try to copy via the edit menu, it pops up to say use Ctrl-C instead.
Honestly, I too am surprised a JavaScript plugin was able to access and alter the system clipboard in the first place too.
shevy-java 3 hours ago
That depends. For my local use I want to access everything.
For external situations I agree. No clue why browsers started to sniff after people. I blame Google for that.
WarmWash 2 hours ago
The discussion around Ad blocking is, while definitely a needed discussion, is so rife with confusion, dishonesty and and self-serving ideology that we are going to kill the internet while being absolutely 100% sure that never giving compensation for value did not do any damage or play any part in making the internet suck.
horsawlarway 2 hours ago
Oh give it a rest.
You want to talk about killing a system... look at all the perverse incentives that pop up when companies are allowed to sell user attention instead of decent services and products.
If the modern social media internet dies because of ad-blockers... good damn riddance.
mikestew 2 hours ago
… or play any part in making the internet suck.
Right, it’s the ad-blocking that’s making the internet suck. You’re going to hurt your lower back carrying that much water.