Newsletter:

Skip Navigation LinksHome > News > Security > Users fall for web ad virus stunt

Users fall for web ad virus stunt

21 May 2007 01:58PM
Tags: fall | web | ad | virus | stunt

'Get your PC infected here' gets 400 hits.

Belgian IT security professional Didier Stevens has conducted an interesting social experiment after purchasing the domain name drive-by-download.info

Stevens created an advertisement on Google AdWords offering users the chance to infect their PC with malware simply by clicking on a link.

The ad stated: 'Is your PC virus-free? Get it infected here!'. The ad was displayed 259,723 times and 409 people clicked on the link.

The site contains no malware, but security experts warned that similar methods are used by hackers to get users to visit sites containing viruses and malware that infect the user's machine.

Stevens ran the ad for six months for around US$23, which means that it cost only six cents per click or per potentially compromised machine.

"I designed my ad to make it suspect, but even then it was accepted by Google without problem and I got no complaints to date, and many users clicked on it," Stevens wrote on his blog.

"Now you may think that they were all stupid Windows users, but there is no way to know what motivated them to click on my ad. I did not submit them to an IQ test."

Lenny Zeltser, a security consultant at Gemini Systems, said: "Perhaps there is no need for attackers to create advanced redirection chains or elaborate deception schemes. As Stevens's experiment confirmed, people will click on anything." 

Google has since disapproved and removed the ad, stating that it violates AdWords editorial guidelines.

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch





Product Reviews

Star Rating
The AdventNet Manage-Engine Password Manager Pro provides a complete system for password management in one...
Star Rating
The Cyber-Ark Enterprise Password Vault, or EPV, is a high-end password management powerhouse.
Star Rating
The Hitachi ID-Archive sets its focus on password randomisation.
Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Unified Communications Podcast Centre

TopTopics
(4849) -  broadband
(4746) -  telstra
(4707) -  nbn
(4329) -  internet
(4004) -  iinet
(3977) -  copyright
(3977) -  afact
(3675) -  servers
(3675) -  mipi
(2847) -  internode
(2420) -  network
(2186) -  microsoft
(1561) -  data
(1516) -  software
(1366) -  centre