<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0" xmlns:s="http://www.techrepublic.com/search" xmlns:dc="http://purl.org/dc/elements/1.1/"  xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
    <title><![CDATA[Discussion on Malvertising: Adverts that bite ]]></title>
    <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909]]></link>
    <atom:link rel="hub" type="application/rss+xml" href="http://pubsubhubbub.appspot.com/" />
    <atom:link rel="self" type="application/rss+xml" href="http://www.techrepublic.com/forum/discussions/102-345909/rss" />

    <description><![CDATA[]]></description>
    <language>en-us</language>
    <lastBuildDate>2013-06-19T00:53:52-07:00</lastBuildDate>
             

    <item>
        <title><![CDATA[Some further reading ...]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3469945]]></link>
        <description><![CDATA[here for those interested, regarding the &quot;business model&quot; of these criminal malware syndicates ...http://www.internetsecuritydb.com/2011/07/fake-anti-virus-software-new-business.html]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3469945]]></guid>
        <dc:creator><![CDATA[MadHatter1]]></dc:creator>
        <pubDate>Sun, 10 Jul 2011 18:12:45 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Until you mentioned it, yes.]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467757]]></link>
        <description><![CDATA[That's really social engineering, I guess.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467757]]></guid>
        <dc:creator><![CDATA[AnsuGisalas]]></dc:creator>
        <pubDate>Mon, 04 Jul 2011 04:36:03 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Something like PSI could work...]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467763]]></link>
        <description><![CDATA[Verifying the hashes from a list of bonafide provider sites.Doesn't protect when the provider is cracked and the hashes fixed, but that's a big bad anyway.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467763]]></guid>
        <dc:creator><![CDATA[AnsuGisalas]]></dc:creator>
        <pubDate>Mon, 04 Jul 2011 04:27:29 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Missed my point, Grandan]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467623]]></link>
        <description><![CDATA[I was attempting to point out that people responsible for the ad service missed the extra &quot;f&quot;: &quot;Well, attackers registered the domain AdShufffle.com and conned the advertising networks into using their malicious banner ads instead of the correct ones from AdShuffle.com. &quot;I purposely exaggerated the &quot;f&quot; in order to point that out.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467623]]></guid>
        <dc:creator><![CDATA[Michael Kassner]]></dc:creator>
        <pubDate>Sun, 03 Jul 2011 05:39:13 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Noted]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467591]]></link>
        <description><![CDATA[And that's all I'm going to say.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467591]]></guid>
        <dc:creator><![CDATA[santeewelding]]></dc:creator>
        <pubDate>Sat, 02 Jul 2011 18:59:58 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Atrocious Spelling.]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467590]]></link>
        <description><![CDATA[OopsI wonder if you made the same mistake. Notice anything different in how AdShufffle is spelled? This may be another thread however I really hate it when Journalists especially incorrectly spell words.  In this instance after Adshuffle is spelled: should correctly be -  Spelt not Spelled, every one appears to use this nowadays, why? My punctuation is bad (shameful Teacher) but the miss-spelling of words is an outrage to people trying to educate us!Even the BBC in England use this and it just grates - Am I correct or wrong?  sorry.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467590]]></guid>
        <dc:creator><![CDATA[grandan@...]]></dc:creator>
        <pubDate>Sat, 02 Jul 2011 18:41:29 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[I'll say]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467405]]></link>
        <description><![CDATA[That hurts thinking about it. Hey, Ansu. Did the extra &quot;f&quot; get by you?]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467405]]></guid>
        <dc:creator><![CDATA[Michael Kassner]]></dc:creator>
        <pubDate>Fri, 01 Jul 2011 14:01:15 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Chain of custody]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467404]]></link>
        <description><![CDATA[Will have to be put in place. Up until now it has been a trust thing. And, that's not working too well.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467404]]></guid>
        <dc:creator><![CDATA[Michael Kassner]]></dc:creator>
        <pubDate>Fri, 01 Jul 2011 13:59:53 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[A light kneecapping...]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467298]]></link>
        <description><![CDATA[never hurt anyone.Ok, I lie...]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467298]]></guid>
        <dc:creator><![CDATA[AnsuGisalas]]></dc:creator>
        <pubDate>Fri, 01 Jul 2011 07:12:16 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Thanks, Col]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467272]]></link>
        <description><![CDATA[I have been trying to find out the details about the slip up. So far, I am not having much luck.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467272]]></guid>
        <dc:creator><![CDATA[Michael Kassner]]></dc:creator>
        <pubDate>Fri, 01 Jul 2011 05:36:25 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Dis-intersted people will always have problems like that.]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467159]]></link>
        <description><![CDATA[There isn't a solution. Heck, enterprise networks with legally licenses copies of Windows still get infected with Conficker. Idiots still accidentally start forest fires. What can you do?True, though, it doesn't matter if you allow legitimate, trusted scripts if the malware is coming through those legitimate channels. AdBlock Plus either blocks ads from published lists, and/or your selections. Neither is likely to help immediately unless a malvertising list is published, kept current, and covers all malvertising methods and all individual instances.Then again, cars were a luxury, once.And yet, network and content owners need to do a better job on their end. They still commit terrible, awful, basic errors in their sites and services.Are VMs or sandboxes deeply confusing luxuries? Operating systems and computers were, once.OS vendors are responsible as well, when the malware is using ridiculous flaws for which patches aren't provided, especially when the general architecture of an OS is terrible to begin with.Quite the pickle, really.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467159]]></guid>
        <dc:creator><![CDATA[seanferd]]></dc:creator>
        <pubDate>Thu, 30 Jun 2011 15:49:10 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Guilty as Charged I saw it]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467146]]></link>
        <description><![CDATA[But thought it was a Typo and ignored it.Col]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467146]]></guid>
        <dc:creator><![CDATA[HAL 9000]]></dc:creator>
        <pubDate>Thu, 30 Jun 2011 15:26:32 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[You can]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467145]]></link>
        <description><![CDATA[send Guido, nevertheless.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467145]]></guid>
        <dc:creator><![CDATA[seanferd]]></dc:creator>
        <pubDate>Thu, 30 Jun 2011 15:23:45 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Oh, oh, oh. Thanks.]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467161]]></link>
        <description><![CDATA[It isn't Adobe code, so I'm not so scared.Personally, though, I don't want my browser displaying PDFs at all. I went to battle to get that to stop years ago, ended up dumping Adobe for Foxit, and IE for SeaMonkey. (Well, not the first time I dumped IE, to be honest.)Better be able to turn that off. And the js better be accessible as a js file that I can remove. Even better if SM does not incorporate that bit of FF code, but SM seems to be on that path of swallowing the FF codebase whole.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467161]]></guid>
        <dc:creator><![CDATA[seanferd]]></dc:creator>
        <pubDate>Thu, 30 Jun 2011 15:22:39 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[I have heard good things about it]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467077]]></link>
        <description><![CDATA[I wish all banks had something similar. It has to help. In my neck of the woods, there aren't any banks supporting it, at least that I know of.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467077]]></guid>
        <dc:creator><![CDATA[Michael Kassner]]></dc:creator>
        <pubDate>Thu, 30 Jun 2011 12:09:08 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Rapport is unobtrusive]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467070]]></link>
        <description><![CDATA[I haven't noticed it working but from the Banks' view they are confident that it evades any software key loggers and man-in-the-middle attacks. I am sure it wouldn't stop any hardware key loggers but as I don't do banking from public PCs I am not concerned. My slight concerns without it would be rogue techies at the phone exchange or at a street junction box, where they could target particular lines.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3467070]]></guid>
        <dc:creator><![CDATA[GreyTech]]></dc:creator>
        <pubDate>Thu, 30 Jun 2011 11:16:16 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Good plan, GreyTech]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3466664]]></link>
        <description><![CDATA[I have written about Rapport, but haven't much feed back about it. What's your take on it?]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3466664]]></guid>
        <dc:creator><![CDATA[Michael Kassner]]></dc:creator>
        <pubDate>Wed, 29 Jun 2011 08:57:55 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[keep up to date and block all that's not necessary]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3466618]]></link>
        <description><![CDATA[I use Secunia's PSI to check I am keeping up to date, Firefox with NoScript,Flash block, Ghostery  and Foxit in safe mode for pdfs, I also use WOT although it is sometimes a pain as it does report a few as bad when they are in fact it is a sub-domains of a free multi-web server. In NoScript I mark all the ad servers as untrusted and it doesn't take long for all my regular sites to get marked as 'allowed'. Using Comodo's DNS servers shows up a few baddies.I have never been hit with a drive-by and have noticed a few baddies being blocked. I also use Sunbelt Software's Vipre for anti-virus and anti-spyware with a hardware firewall in my router and Comodo's firewall on all my home network PCs most of which do not have any browsers. Every month or so I run Malwarebytes to check nothing has crept in. Except for the occasional tracking cookie nothing has got in so far.I check every time I install something new, that all the tick boxes are what &quot;I&quot; want not necessarily the defaults. Windows 7 UAC is set to its highest level. I favour banks that use Rapport. I also backup automatically and keep really important stuff off-site encrypted with Truecrypt. Passwords on non-trivial sites are all different and strong. I always check all my bank statements match my own system.Is it enough, hopefully.Vigilance it the watchword. (or is it paranoia!)]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3466618]]></guid>
        <dc:creator><![CDATA[GreyTech]]></dc:creator>
        <pubDate>Wed, 29 Jun 2011 07:50:28 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[So, how many saw the extra &amp;quot;f&amp;quot; right away?]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3466543]]></link>
        <description><![CDATA[Be honest.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3466543]]></guid>
        <dc:creator><![CDATA[Michael Kassner]]></dc:creator>
        <pubDate>Wed, 29 Jun 2011 05:45:13 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[I think so, Sean. But]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3466556]]></link>
        <description><![CDATA[I also think of legacy sites and dis-interested people having to deal with NoScript. In reality, if good sites can have malvertising, how does one know which sites are indeed okay?]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-345909-3466556]]></guid>
        <dc:creator><![CDATA[Michael Kassner]]></dc:creator>
        <pubDate>Wed, 29 Jun 2011 05:44:32 -0700</pubDate>
    </item>
    </channel>
</rss>

