AplusWebMaster
Topic Starter
FYI…
- http://www.theinquirer.net/gb/inquirer/new…ing-web-traffic
16 April 2008 - "GRADUATE STUDENTS at the University of Washington have found that some Internet Service Providers (ISPs) are meddling with the contents of web pages in transit to their subscribers, sometimes in harmful, potentially dangerous ways. Their paper* (pdf), which is to be delivered Wednesday at the Usenix Symposium on Networked Systems Design and Implementation in San Francisco, outlines that about one per cent of the web pages that the researchers tested had been altered during transmission. The authors document some alarming practices by some ISPs. They examined the data flowing to about 50,000 computers and found that certain ISPs were injecting adverts into web pages transmitted on their networks, and that some web browsing and ad-blocking software was creating security vulnerabilities… L'Inq PC World***"
Detecting In-Flight Page Changes with Web Tripwires
* http://www.cs.washington.edu/research/secu…e/nsdi-2008.pdf
"…we provide evidence of surprisingly widespread and diverse changes made to web pages between the server and client. Over 1% of web clients in our study received altered pages, and we show that these changes often have undesirable consequences for web publishers or end users. Such changes include popup blocking scripts inserted by client software, advertisements injected by ISPs, and even malicious code likely inserted by malware using ARP poisoning**. Additionally, we find that changes introduced by client software can inadvertently cause harm, such as introducing cross-site scripting vulnerabilities into most pages a client visits…"
( ** http://en.wikipedia.org/wiki/ARP_spoofing )
*** http://preview.tinyurl.com/6jugz7
April 16, 2008 (PC World)
Also: http://www.techcrunch.com/2007/06/23/real-…ed-advertising/

- http://www.theinquirer.net/gb/inquirer/new…ing-web-traffic
16 April 2008 - "GRADUATE STUDENTS at the University of Washington have found that some Internet Service Providers (ISPs) are meddling with the contents of web pages in transit to their subscribers, sometimes in harmful, potentially dangerous ways. Their paper* (pdf), which is to be delivered Wednesday at the Usenix Symposium on Networked Systems Design and Implementation in San Francisco, outlines that about one per cent of the web pages that the researchers tested had been altered during transmission. The authors document some alarming practices by some ISPs. They examined the data flowing to about 50,000 computers and found that certain ISPs were injecting adverts into web pages transmitted on their networks, and that some web browsing and ad-blocking software was creating security vulnerabilities… L'Inq PC World***"
Detecting In-Flight Page Changes with Web Tripwires
* http://www.cs.washington.edu/research/secu…e/nsdi-2008.pdf
"…we provide evidence of surprisingly widespread and diverse changes made to web pages between the server and client. Over 1% of web clients in our study received altered pages, and we show that these changes often have undesirable consequences for web publishers or end users. Such changes include popup blocking scripts inserted by client software, advertisements injected by ISPs, and even malicious code likely inserted by malware using ARP poisoning**. Additionally, we find that changes introduced by client software can inadvertently cause harm, such as introducing cross-site scripting vulnerabilities into most pages a client visits…"
( ** http://en.wikipedia.org/wiki/ARP_spoofing )
*** http://preview.tinyurl.com/6jugz7
April 16, 2008 (PC World)
Also: http://www.techcrunch.com/2007/06/23/real-…ed-advertising/