This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

ISP ad-injection... In-Flight Page Changes w/ Web Tripwires

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.theinquirer.net/gb/inquirer/new…ing-web-traffic
16 April 2008 - "GRADUATE STUDENTS at the University of Washington have found that some Internet Service Providers (ISPs) are meddling with the contents of web pages in transit to their subscribers, sometimes in harmful, potentially dangerous ways. Their paper* (pdf), which is to be delivered Wednesday at the Usenix Symposium on Networked Systems Design and Implementation in San Francisco, outlines that about one per cent of the web pages that the researchers tested had been altered during transmission. The authors document some alarming practices by some ISPs. They examined the data flowing to about 50,000 computers and found that certain ISPs were injecting adverts into web pages transmitted on their networks, and that some web browsing and ad-blocking software was creating security vulnerabilities… L'Inq PC World***"

Detecting In-Flight Page Changes with Web Tripwires
* http://www.cs.washington.edu/research/secu…e/nsdi-2008.pdf
"…we provide evidence of surprisingly widespread and diverse changes made to web pages between the server and client. Over 1% of web clients in our study received altered pages, and we show that these changes often have undesirable consequences for web publishers or end users. Such changes include popup blocking scripts inserted by client software, advertisements injected by ISPs, and even malicious code likely inserted by malware using ARP poisoning**. Additionally, we find that changes introduced by client software can inadvertently cause harm, such as introducing cross-site scripting vulnerabilities into most pages a client visits…"
( ** http://en.wikipedia.org/wiki/ARP_spoofing )

*** http://preview.tinyurl.com/6jugz7
April 16, 2008 (PC World)

Also: http://www.techcrunch.com/2007/06/23/real-…ed-advertising/

:ph34r:
"Timing" is everything…

- http://www.reuters.com/article/technologyN…0080416?sp=true
Apr 16, 2008 - "Two consumer groups asked the Federal Trade Commission on Tuesday to create a "do not track list" that would allow computer users to bar advertisers from collecting information about them. The Consumer Federation of America and the Consumers Union also urged the FTC to bar collection of health information and other sensitive data by companies that do business on the Internet unless a consumer consents. The call echoed those of other privacy advocates who filed statements with the FTC on Internet companies' use of "behavioral advertising." That is the practice of tracking a computer user's activities online, including Web searches and sites visited, to target advertisements to the individual consumer… In comments to the FTC on online behavioral advertising, advertisers made clear a strong preference for self-regulation rather than government dictates on how personal data are collected, what disclosures are made to computer users and how long the information is stored. Consumer groups said on Tuesday they were skeptical of self-regulation…"

:(
FYI…

ISP typo pimping…
- http://www.theregister.co.uk/2008/04/20/ka…emo_at_toorcon/
20 April 2008 - "…Once upon a time, mistyped domain names resulted in a browser returning a simple DNS lookup error (not a 404 error, as incorrectly reported in an earlier version of this story) that said the address didn't exist. Then ISPs realized they could make money by returning a failure notice that included banner ads and other content. This ad injection is done through the magic of the domain name system. As a result, browsers get fooled into thinking a request for qww .microsoft .com is a legitimate address that's controlled by the same network responsible for www .microsoft .com. "Guys, anything goes wrong on that subdomain [and] it is an element of the parent," Kaminsky said. "It can access cookies, it can do other things. Normally a subdomain is trusted by the parent. Not this time"… (Slides of the research, which was developed jointly by IOActive researchers Kaminsky and Jason Larsen, are available here*.) Pages that ISPs return for non-existent pages, for example fake.theregister.co.uk, are able to circumvent the so-called same origin policy, which prevents cookies and other types of content set by one domain from being accessed or manipulated by a different address…"
* http://www.doxpara.com/DMK_Neut_toor.ppt

- http://blog.wired.com/27bstroke6/2008/04/i…error-page.html
April 19, 2008 - "…DNS expert Paul Vixie, who is the president of the nonprofit Internet Systems Consortium, says the problem Kaminisky found isn't with the core internet protocols, which he could fix, but instead is a "problem exacerbated by inappropriate monetization of certain DNS features"…"

:oops: <_<