<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Spyware Sucks : Vulnerabilities, viruses and exploits, safety and privacy on the Internet</title><link>http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/safety+and+privacy+on+the+Internet/default.aspx</link><description>Tags: Vulnerabilities, viruses and exploits, safety and privacy on the Internet</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Malvertizing at variety.com?</title><link>http://msmvps.com/blogs/spywaresucks/archive/2008/12/10/1656334.aspx</link><pubDate>Wed, 10 Dec 2008 00:34:58 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1656334</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1656334</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/12/10/1656334.aspx#comments</comments><description>&lt;p&gt;Cite: &lt;a title="http://www.google.com/support/forum/p/Webmasters/thread?tid=612707351ed6b298&amp;amp;hl=en" target="_blank" href="http://www.google.com/support/forum/p/Webmasters/thread?tid=612707351ed6b298&amp;amp;hl=en"&gt;http://www.google.com/support/forum/p/Webmasters/thread?tid=612707351ed6b298&amp;amp;hl=en&lt;/a&gt;&lt;/p&gt; &lt;p&gt;I disagree with the theory being espoused by some in that thread (that the site is hacked and/or htaccess has been manipulated).&amp;nbsp; This is because:&lt;/p&gt; &lt;ol&gt; &lt;li&gt;the thread author is complaining that the redirects are occurring as he browses the site&lt;/li&gt; &lt;li&gt;it is not affecting anybody else who has posted to the thread&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;Such symptoms lead me to believe that there is malvertizing being displayed somewhere on the site - I agree with jwp_var.&amp;nbsp; It is interesting that the behavior only seems to affect Firefox...&lt;/p&gt; &lt;p&gt;The complained of URL, proweb-info.com/soft.php?aid=075676&amp;amp;d=1&amp;amp;product=XPA&amp;amp;refer=dc77b3921 is definitely bad, leading the victim to the fraudware site advancedproscan.com. &lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1656334" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/safety+and+privacy+on+the+Internet/default.aspx">safety and privacy on the Internet</category></item><item><title>ALERT: treat all content from Olympic Media (olympicmedia.net) with extreme caution</title><link>http://msmvps.com/blogs/spywaresucks/archive/2008/12/10/1656329.aspx</link><pubDate>Tue, 09 Dec 2008 23:16:09 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1656329</guid><dc:creator>sandi</dc:creator><slash:comments>1</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1656329</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/12/10/1656329.aspx#comments</comments><description>&lt;p&gt;Olympic Media has been caught distributing malvertizing ... again (&lt;a target="_blank" href="http://www.bluetack.co.uk/forums/index.php?showtopic=18064&amp;amp;st=180#"&gt;thanks to Kimberley for the heads up&lt;/a&gt;).&lt;/p&gt; &lt;p&gt;Why do I say again? &lt;a target="_blank" href="http://msmvps.com/blogs/spywaresucks/archive/2008/08/07/1643854.aspx#1649660"&gt;Because a usatoday representative posted to my blog back in September claiming that Olympic Media had sold them a malvertizement&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;Anyway, back to present day.&amp;nbsp; This time Olympic Media are distributing a cyberipod malvert. &lt;/p&gt; &lt;p&gt;Adopstools results - you will see that it is not even one of the newer style, difficult to detect adverts:&lt;br /&gt;&lt;a title="http://www.adopstools.com/index.asp?page=quicklink&amp;amp;id=o0CVw0KNmEe0g8sv" target="_blank" href="http://www.adopstools.com/index.asp?page=quicklink&amp;amp;id=o0CVw0KNmEe0g8sv"&gt;http://www.adopstools.com/index.asp?page=quicklink&amp;amp;id=o0CVw0KNmEe0g8sv&lt;/a&gt;&lt;/p&gt; &lt;p&gt;When the advert is run, it reaches out to two domains - freegreenstats.com and statisticsmanager.com.&lt;/p&gt; &lt;p&gt;statisticsmanager.com drops a cookie for adnetserver.com before leading us to onlinestatsmanager.com.&amp;nbsp; From there we end up at online-info-clicks.com, is which the first URL that exposes the victim to fraudware.&amp;nbsp; online-info-clicks.com redirects the victim to anti-virus-live-scan.com.&lt;/p&gt; &lt;p&gt;The advert also uses _url within its code (which means it can change its behavior depending on where it is run from), and runs timezone checks (again, as a way to control the advert&amp;#39;s behavior).&lt;/p&gt; &lt;p&gt;So, what does the various domains tell us?&amp;nbsp; Kimberley has done already done the hard work so I shall refer you to her &lt;a target="_blank" href="http://www.bluetack.co.uk/forums/index.php?showtopic=18064&amp;amp;st=180#"&gt;report&lt;/a&gt;.&amp;nbsp; You&amp;#39;ll note that she draws a connection between Olympic Media and a known bad actor, Atlantmedia.&lt;/p&gt; &lt;p&gt;Also, you&amp;#39;ll see that another malvert was discovered on MSN (&lt;a target="_blank" href="http://www.bluetack.co.uk/forums/index.php?showtopic=18064&amp;amp;st=180#"&gt;this time the Encarta site&lt;/a&gt;).&amp;nbsp; Thankfully, that advert has been pulled from circulation.&lt;/p&gt; &lt;p&gt;BTW, note the spelling mistakes on the Olympic Media home page... &amp;quot;dvertising&amp;quot; instead of &amp;quot;advertising&amp;quot; appears twice.&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;img style="border-right-width:0px;margin:0px 25px 25px 0px;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.ALERTtreatallconte.netwithextremecaution_5F00_A485/image_5F00_8c20f741_2D00_5e2a_2D00_49b3_2D00_8295_2D00_b40187527857.png" width="170" height="640" /&gt;&lt;img style="border-right-width:0px;margin:0px 25px 25px 0px;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.ALERTtreatallconte.netwithextremecaution_5F00_A485/image_5F00_8ea89409_2D00_5a41_2D00_4e2a_2D00_8ebc_2D00_9f620408025b.png" width="679" height="536" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1656329" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/safety+and+privacy+on+the+Internet/default.aspx">safety and privacy on the Internet</category></item></channel></rss>