Google-hosted malvertising leads to fake Keepass site that looks genuine
arstechnica.com
arstechnica.com
OF COURSE they were verified by Google. Google verifies identity by accepting money. Give them money, and you're verified.
"Google representatives didn’t immediately respond to an email" Are there real humans at Google who actually answer email? I haven't seen a response from Google in more than a decade. It makes me wonder if all the phishing and spam I'm reporting even does anything.
Honestly, it's time for the world to move on from Google. They haven't been safe to use as a search engine for more than two years.
After clients had been sent to phishing sites by Google's ads, I decided to block these domains on all the networks I administer:
googlesyndication.com
googleadservices.com
googletagservices.com
googletagmanager.com
google-analytics.comWindows has a similar problem: marketing / ads is ruining an otherwise decent product.
But last I checked, +"""search phrase""" works
I do all of my searches in incognito so sadly I don’t know if the options is remembered or not.
Are there real humans at Google who actually answer email?
Google's strategy has always been to focus on the things that scale. Having a human answer a phone or a mail doesn't scale, so no customer service for the users.I think this is also the reason why these ads get through: to detect them they rely for a large part on crowd-sourcing: that "report a problem" link is IMHO one of their main mechanisms to deal with filtering out the bad ones. If more get through then it might indicate that the scale is tipping to the point that crowd-sourcing relies on too few people who go through the effort.
When I try to report mail spam from their network they want me to fill out a form instead of reading the abuse mail they got.
Such a different era.
I'm usually first in line to hate on Google, but I report a lot of phishing to them and, at least when it comes to phishing sites being hosted by Google, they tend to take them down pretty quickly. I never get a response, and I assume that it's all automated, but it's a lot better than many other hosts. If you report a malicious website to namecheap it can remain online for months and, bad as they are, they aren't even the worst out there in terms of poor abuse handling. Google could do better, but they're really pretty good.
That said, this is just another example of why we should all be blocking ads. It keeps us all safer.
It ought to be possible to click on the corner of an ad and get the company number and business address of those responsible for it. "Overseas" adverts originating in different countries should be even more heavily checked, because if they're fraudulent then recourse is much harder even if they're not anonymous.
“Users are first deceived via the Google ad that looks entirely legitimate and then again via a lookalike domain,” Jérôme Segura, head of threat intelligence at security provider Malwarebytes,
Back in 2017, Google Chrome 59 supposedly fixed the Punycode phishing attack. E.g. story: https://www.engadget.com/2017-04-17-google-chrome-phishing-u...
Maybe a dedicated criminal studied the Chromium source code that checks Punycode and noticed a flaw where it would allow 'ķ' in place of 'k' ???
https://www.xn--80ak6aa92e.com/ --> fake "аррӏе.com" triggers phishing warning
https://xn--eepass-vbb.info/ --> fake "ķeepass.info" does not trigger warning
The character ķ (U+0137) is part of the Latin script [2], so I presume the string "ķeepass.info" won't trigger the mixed-script confusable test.
I don't see ķ listed in the "whole script confusable" glyphs [3]. Should ķ be included there? There's a comment in the Greek section of that file to the effect that "variants such as ά, έ, ή, ί" are ignored, so perhaps there is a general rule that accented characters are not considered to be confusables? If so, that makes some sense to me; French users would presumably be a bit disappointed if a domain name containing an é were rendered in the Punycode form, for instance.
[1] https://chromium.googlesource.com/chromium/src/+/main/docs/i...
[2] https://www.compart.com/en/unicode/U+0137
[3] https://source.chromium.org/chromium/chromium/src/+/main:com...
A safer approach would be to only ever show a user the characters they expect to see (and are familiar with), e.g. based on their language setting. Assuming that every language has a finite list of characters used in its written form such a whitelist approach should be possible and much better than playing whack-a-mole with a blacklist for "potentially confusable" characters.
Oof.
Take for example, both 糉 and 糭 are valid characters in Chinese. One is a variant of the other. Which one is "canonical" depends on who (i.e. which authority, of which there are many) you ask. And FWIW the language and regional settings don't necessarily give an answer to the canonical representation.
Those characters mean the same thing with or without the specks of dust.
So, what's your solution here?
To be fair, Unicode domains are inherently a huge mess. The thing is that we don't need more armchair experts dreaming up Euro-centric solutions.
Either one or both of the characters you mention are probably part of the script of the users language setting in chinese; if the character is then it should be rendered as unicode and if not as punycode. If the users language has this kind of ambiguity then they are the only ones to judge if the domain name is correct or not, but at least they are familiar with the language and do not see characters they might have never encountered before and/or need to deal with an ambiguity that they shouldn't even have to expect to begin with.
The idea I proposed would still protect someone with a chinese language setting from being tricked by e.g. a cyrillic character in an otherwise ASCII domain name. I don't see how that is euro-centric (apart from ASCII being inherently english-centric), it is an overall improvement over the status quo no matter where you live and what language you speak.
But as someone said, tiny, valid differences are easy to miss anyway, and original URL attacks were replacing similar-looking ASCII graphemes (eg. l for 1), so this will all continue.
That's totally backwards. If the assumption is that users of language X will legitimately visit sites of language Y with sufficient frequency, then all that language-specific filtering makes no sense.
And seeing punycode in URL bar does not mean a site does not work, it's only a suboptimal experience.
Ah, funny. HN renders the ķ as punycode in urls. In the interest of sharing negative results, I leave this here.
Because there's a quick 302 redirect from "ķeepass.info" to "keepass.info" :
Chrome F12 Dev Tools network trace: https://imgur.com/a/vrxjsUV
Whether that redirect was there at the time of the Arstechnica article, I don't know.
EDIT ADD: around 12:57 UTC, the 302 redirect was changed to a Youtube video: https://imgur.com/a/TtLxafP
(Somebody is apparently having fun trolling the internet.)
ICANN lookup trivia says "ķeepass.info" domain was created 3 days ago:
Domain Information
Name: xn--eepass-vbb.info
Internationalized Domain Name: ķeepass.info
Registry Domain ID: a375f89abb384328a10460509f9f99f8-DONUTS
Domain Status:
clientTransferProhibited
addPeriod
Nameservers:
leia.ns.cloudflare.com
sevki.ns.cloudflare.com
Dates
Registry Expiration: 2024-10-16 10:21:45 UTC
Updated: 2023-10-19 11:40:19 UTC
Created: 2023-10-16 10:21:45 UTCThat, and them showing war videos in ads to little kids.
My favorites are the dumb-brick phone charger that "magic defrags your phone", and the micro-ghost pistol.
It seems Google doesn’t want to receive feedback if it affects their bottom line.
I pay, and if they cut me off for helping do their job, I'd be livid. Maybe being a paying customer is the reason they haven't blocked me yet
Maybe I should start reporting them to the securities regulator in my province instead - binary options were banned in Canada a few years ago as they are a haven for scammers and con artists. That might get better results.
That would mean having someone screen the ads. Google would need Foxconn nets for any building where they task people with watching youtube ads.
How is that a difference of 3 keys?
I don't get the impression that their point is much changed by it being 3 keys instead of... 11 by my count (10 if you don't count shift for the capital O).
If they wanted to be part of the solution they'd vet the ads before they're made public. But that doesn't scale, and so people get scammed and society suffers and Google makes more money than it knows what to do with. Pretty fair trade...?
As others have said in one way or another, blocking internet advertising is part of healthy and safe internet usage.
The human-friendly way would be to screen ads before airing them, which means hiring teams to do the screening; have an appropriate legal language in the ad screening section saying that ads may be rejected for "Reasons" which will be explained in the rejection note, and the rejection can be appealed upon which another person will deal with the rejection review process.
It's not a difficult problem, but it gets in the way of making money hand over fist.
While that case is unrelated, if someone prescreens the ads without having the required context, (let's be real here, it would be reviewed by someone in Philippines or India, not USA) they are likely to block stuff they do not understand but told to err on the side of the caution - which is what you presumably want to avoid the cases as in this title.
> the rejection can be appealed upon which another person will deal with the rejection review process
It still requires someone to have context about what you are running an advert on. Still hard to find, still not as reliable, and would either end up blocking many legit ads, or passing some objectionable ads. It does not just hurt their bottomline, but the bottomline of every good faith advertiser on the network.
I agree that just reporting post seeing the ad is a poor feedback mechanism. Maybe some sort of AI. They do verify advertisers though as they say. Maybe that should be more stringent.
Please keep in mind that ads are messages that visitors never subscribed for. The only party that loses here is the advertiser, and I couldn't care less. In fact, the problem with advertising is that the customers are the advertisers, ads networks being biased to act in their favor, visitors being just the resources being sold.
Same issue from a year ago, looks to be the same prexix on the domain name as well.
https://www.bleepingcomputer.com/news/security/google-ad-for...
* misleading ads
* spam phone callers
* counterfeit products on Amazon and the like
Everything seems to be built to make me 100% reachable by any crook out there, yet I can't reach these companies enabling this through any means at all.
I had never imagined dark mode as a security enhancement :)
The only place punycode really gets used are spam domains in practice. Even most Cyrillic and Asian domains don't use punycode.
I get the concept of punycode and it is impressive technically but for domains it's just been a massive phishing headache.
As a practical step browsers should ask the user whether they want to allow URLs in a certain language the first time a non-ASCII character is entered. With just one or a couple of languages allowed, the attack surface would be drastically reduced for most users.
The only single character ones in ASCII with noticable issues are 0/O and I/l/1 (this is also why on latin alphabet gift cards, you'll often see these characters omitted entirely). The other homograph attacks on ASCII are mostly font kerning dependent (and even the two I mentioned can still be made distinct from each other in fonts).
I'm not dunking on Unicode here to be clear, Unicode is awesome. That said, bolting Unicode into unique identifiers humans are meant to read is a bad idea because of the homographs. Again; just look at how non-latin alphabet countries generally (don't) work with Unicode in things like usernames.
> As a practical step browsers should ask the user whether they want to allow URLs in a certain language the first time a non-ASCII character is entered.
This would probably help on top of the usual algorithmic blocklists that Firefox and Chrome already use (which largely rely on trying to match what sets of Unicode are used in a domain name to pick between Unicode and punycode rendering).
No, humans are far too well-trained in "just say yes and forget it". The browser should loudly flag any non-ASCII name (maybe there's a buried-deep option somewhere, to less-loudly flag it), or else it should do a bit of OCR and pop up a "DANGER - Look-Alike Domain Name..." warning.
No OCR needed.
For all of these accented cases where no mixing of scripts occurs, browsers could simply decompose to Unicode Canonical (Decomposed) Normal Form, and flag any accented letters (eg. render them in red in the URL bar).
For instance right not asahi.com is taken by 朝日 (Asahi shibun, the newspaper), thus the Asahi town (旭) cannot use it. Mind you, the town could take asahi-town.co.jp or something like that, but there is other Asahi towns and places with different writings (including 旭日, 朝陽、浅緋 etc.)
Wanting all of them to have some random ascii diversification is madness, and we're only talking about Japanese places, when the Chinese character space overlaps. (The question of whether these domains are actually registered is I think a chicken and egg problem, and I have a hard time imagining the above conflict space will get a nice resolution inside the ascii alphabet)
Western ascii domains being ripe for scam is an issue, throwing the baby with the bath water would still be problematic.
While I can see an argument for expecting to find whatever brand you think most relevant at BRAND.com(mercial), first-come-first-served is as fair as we can realistically get to (with some protections against misrepresentations and squatting).
Note that I am not against IDNs: I just think your argument is flawed in their support.
Again, Unicode is what allows all languages to be written out, and the fact similar-looking-URL issue is more present (it's present with ASCII too) is not a slight against Unicode and IDNs: we just need to solve for it.
It would be similar to mail.com, mel.com, meil.com, mehl.com, melle.com and all other variations that sound roughly the same getting all mapped to meɪl.com
We could live in a world where all words are written phonetically, but we don't. Expanding that courtesy to non alphabetical languages would be a pragmatic and sane approach.
Though I think there's nothing wrong with punycode with dedicated first-level domains. like кремль.рф (does not exist, but I'm too lazy to find one).
Lots of people might want to register their name, or the name of their city, etc. These all sound like valid use cases. You could say that anything beyond ascii is of questionable use, but non-English natives will always digress.
The reality is that Unicode is great for communication in say, text messages but terrible for identifiers. People in non-latin countries know this; there's a reason that there's only six countries (from what I can tell) that went with punycode TLDs while there are many more countries with unique alphabets and most of those punycode TLDs see very limited use to begin with. (The most popular being the one used by the Russian Federation, which is also the only entity to forbid using non-cyrillic characters in it's domain names).
Facebook already does this for political ads, so it is doable.
They are not going to do it unless a government makes them do it, or if the legal liability risk is too great.
Little xenophobic?
If you tried to run a fake, malware-laden website in a Western country you would eventually be shut down and prosecuted.
These scams mostly fester in nations with weaker institutions, not just Eastern Europe but also China and India. Their authorities are simply not interested in preventing this kind of unlawful activity.
I don't know if they catch small fish as in this example, it just isn't in the news. The bigger fish happens to be in the news, like shutting down international scam call center - 2 in LV, 1 in LT. Video from police cam if anyone wants to see smashing windows: https://www.vp.gov.lv/lv/jaunums/verieniga-starptautiska-ope...
We are also being educated in many places including schools, government institutions, posters, jobs etc about the risks, about how scammers work and stuff like that.
https://krebsonsecurity.com/2021/05/try-this-one-weird-trick...
> In Russia, for example, authorities there generally will not initiate a cybercrime investigation against one of their own unless a company or individual within the country’s borders files an official complaint as a victim.
Okay, the term is used in geographical context and not geopolitical.
International cooperation for mutual profit.
[0] https://www.cloudflare.com/learning/ssl/what-is-an-ssl-certi...
edit: As someone mentioned further down, it’s an about:config setting for network.IDN_show_punycode
But if you operate .COM or .INFO or .FREE-MONEY or whatever, your goal isn't to help anybody it's to obtain the most money possible without anybody senior going to jail. Crooks want to pay you money to help them target victims? Yes please.
So in practice the browser vendors have to cook up heuristics to try to guess whether the IDN is a trick and in this case I'd guess Chrome's heuristic didn't consider this a problem whereas Mozilla's did. I believe Mozilla were so exasperated by the IDN abuses at these registries they may have just switched off IDN rendering for the entire registries affected which is thorough.
Disappointingly .info is whitelisted, if it wasn't (like .com) then Firefox would use Punycode here instead. Perhaps Mozilla should re-consider the decision for info, or, perhaps they have and they decided that .info is doing enough (though clearly not in this case) to say that on balance it's acceptable.
EDIT: FF Android 118.2.0 with Privacy Badger and uBlock Origin.
That is weird. I don’t have mobile debugging set up, or I’d try and figure out what’s going on there.
Character substitutions like ķeepass or ƙeepass or keypass are at least possible to spot if you know the name of the product, but not the full URL.
But there are many ways to create lookalike domains that don't change the product name: https://keepass.org https://keepass.net https://keepass.info https://keepass.cx https://keepassxc.org https://keepass-info.net https://keepass-manager.com
Which of these is the correct one? (It's https://keepassxc.org of course, but just looking at the URL won't tell you that.)
The root cause is downloading software you see advertised on Google even though that does not in any way establish trustworthiness.
This obscures how dramatically worse the situation is if you can't even trust display names. Does the ubuntu.com link on wikipedia lead to an ubuntu.com, or something entirely unrelated? Does a script you're reviewing actually pull images from debian.org, or somewhere else?
At some point you have no choice but to trust what they pixels on your screen are telling you.
Also, while I can agree that url are "security-critical", the same applies to email or even just names, and we definitely need Unicode for those.
Those of them who want to accept the security risk that comes with that should have the option to turn it on, but it shouldn't be on by default for the rest of us.
Maybe restricting those characters to the relevant top level domains? At least you'd notice you're on ķeepass[.]lv
They can install a browser plugin to convert punycode to their alphabet if they care so much for using it in URLs. There is no need to inflict this on peoples with safe alphabets. Alternately, highlight non-safe-ASCII-subset characters in a different color, as VS Code does.
Attackers exploit this by first using a genuine domain to get the ad approved, and then altering the info after the campaign starts. I saw a similar attack like this on twitter a month or so ago.
The first one is that Google Ads allow you to show an arbitrary URL below your ad without you showing that you own it.
The second one is allowing the URL shown to be different from where you send the users.
But I would like to see an option to render URLs as Punycode, and not their original form.
https://www.bleepingcomputer.com/news/security/google-ad-for...
1. Always type in URLs manually when downloading critical software to bypass the potential risks from ads.
2. Make use of browser plugins that identify malicious websites or unverified SSL/TLS certificates.
3. Before making any downloads, inspect the TLS certificate of the website by clicking on the padlock icon next to the URL bar. Look for inconsistencies like a different company name or issue date.
Maybe also 4. use a package manager?
> (so 0. Use an adblocker)
Also it's easier to ignore them than manually entering urls with a typo leading you to some other unsafe domain
This is the time for typosquatters to strike :(
Ads in search result are looking close enough to regular search result for people to just trust it and click.
And my guess is, absolutely nothing will be done, accountability wise, in either case.
Effectively you want Google to be the law enforcement corporation and not your government thus massively expanding their power and reach.
Why would you want that? (And that also goes for people who want Apple to replace their government at law enforcement).
If someone were to stand outside holding a big banner advertising something malicious/illegal they'll be in legal trouble pretty quickly, which I think is fair.
Why shouldn't Google be held to the same standard?
For the most part, you would not. While it is not protected by the first amendment in the US to advertise illegal products, it is also not particularly restricted in most of the US.
To whit: If you hold up a big banner saying "fentanyl sale - 30 cents per gram", you would not have committed a crime or an actionable legal tort in most places.
The thing that is actionable everywhere is deceptive/fraudulent/misleading advertising.
That seems to be much more appropriate approach to prevent this kind of crime. Why is US so incompetent at punishing scammers as a country?
Google is a company that nets 60 billion $ a year in profits. They can afford hiring a few thousand people to manually vet ads before they go out, and they should.
What do you think the number of different ads being displayed is, given how much each ad costs?
Estimates suggest it's about 30 billion ad impressions per day to earn that.
If each distinct ad gets 1000 impressions, that's 10 billion ads to review per year.
Let's be super generous, and assume it's 10k impressions, leaving us with 1 billion ads to review.
Let's further assume it's 1 minute per ad to review them, because people are super good at it. This will take 694440 person/days to review.
So to even give a 24 hour turnaround time, they'd have to hire 694,000 people.
If they pay them 65k each (yearly minimum wage in california), that's 45 billion a year.
This again, assumes we have ads with lots of impressions, it's only a minute per ad, and that we are okay with 24 hour turnaround time. Otherwise, it costs more.
It's really easy for people to play the "company makes x, they can afford y" game, but without real data it's sort of magical thinking.
I doubt humans could easily keep up with the review load here, at scale, at any reasonable cost/living wage.
If Google cannot handle legit business then it should manage their resources better.
Advertising malware is not legit business.
"We are so profitable and big" is not excuse for it.
It is reason why they earn so much money, they do not care if criminals advertise malware.
Now banks must spend awful lot of money to fight money laundering. Maybe it is time to force Google to take some responsibility.
Sure. I"m pointing out this simple sort of "they can easily afford to do x" is usually nonsense.
I haven't commented at all on what the result should be (not allowed to do it or whatever), simply that the math that it would be simple to fix is wrong.
If we are going to argue about things in a useful way, we should avoid random assertions without data that don't really advance the argument, especially when they are trivially wrong?
If Google cannot handle their ad business, when there are too many customers, then stop taking new customers.
Very simple.
But taking money from criminals is very profitable and that is the reason.
Edit: Checked DannyBee profile: "I manage developer workflow tools and services at Google"
That explains why he is defending Google's scammy behaviours.
This sort of dismissal based on who you work for is both childish, and unproductive to a real discussion. Similar to the "most fanboyish thing ever" comment, which, honestly, if telling someone their totally unsourced math and claim is wrong, by providing data and real math, is the most fanboyish thing you've ever seen, then i think you are very lucky in what you see ;)
Beyond that, i'll repeat what I said - i simply pointed out the assertion and math is wrong. That is all. You are the one claiming i am defending anything, beyond that, at all. I was very careful about not defending anything, and in fact said i'm open to all sorts of views about what to do about it.
Maybe you should re-read what i wrote, and point out any point where i did anything but show that the claim made was wrong, and the math was wrong?
If it is true, then Google execs should be in jail right now.
And proves point again that Google does not care about filtering content and it is profitable to accept money from criminals.
Ofcourse if your paycheck depends of criminals money then it is very dumb to share that profit to hire more people to fight malware content.
In my country there are many Google scam ads which feature local celebrities/doctors, but it is impossible to remove those ads, because Google never removes them. Zero response from Google. Even Police cannot help because nobody from Google responses.
So I guess it is intentional to spread those spam ads.
Even if users report those ads, Google 99% of time never takes an action to remove spam ads.
With few thousand people you can remove those reported ads...
And if it leads to less, but higher quality ads in the end, even better.
[1] https://dejure.org/dienste/vernetzung/rechtsprechung?Gericht...
That is all.
We should decide what to do about it based on correct data and sane assumptions, not random assertions that are off by orders of magnitude and backed by no data.
It's kinda bizarre how many here whine about not trusting Google and then just want to give them police powers.
Google doesn't have to do this because they are anticompetitive.
The root problem here is that Google shouldn't be in this position where we are talking about them acting as law enforcement, and a business getting banned by Google is akin to getting ejected from society.
about:config -> network.IDN_show_punycode = false
2) In advertisements, Google shouldn't allow the advertiser to modify the domain that is displayed. Really, why do they even do this?
3) IDN shouldn't be enabled by default.
Because advertisers usually want to send links to a tracker site of their own first so that they can verify if their numbers match up with what Google reports.
No one trusts anyone in the advertising space, and for good reasons. Advertising has always been a space filled to the brim with crooks and fraudsters.
If I ever work at a cubicle, I will hang this sentence on a large frame over my desk, then stay silent and stare every time someone comes and complains about my ad blockers.
I am waaay past that now.
See previously, gilimp and https://fxtwitter.com/ericlaw/status/1712531148356661494.
There used to be a time where it was moral to whitelist trusted websites to give them ad revenue. That time is far gone.
Stories like this are a stark reminder to use a good adblocker (uBlock Origin) everywhere on every site all the time.
To reuse an overused analogy, adblockers are like condoms for the web.