Buy An Ad, Own a Browser Botnet
threatpost.com
threatpost.com
When you open up a platform to let people buy ads, there are loads of decisions to be made. The ones around "what content do we let people submit without vetting" are pretty simple. At Perfect Audience, self-service customers can upload static image banners and traffic those. We host them. No JS. No flash. If folks want to traffic those kinds of ads, we have an enterprise support play they can sign up for and we'll help them do that easily.
Letting anyone traffic js or flash files without prior vetting is hugely lazy. I wish they'd named the ad network they bought through so they could be black-balled and barred from the exchanges.
It's so easy to say no to crap advertising, and yet there's always unscrupulous players who say yes to it. There's no excuse. It's all their fault for just not giving a crap.
Edit: Also, when you get access to the ad exchanges, you sign a ton of documents and agree to be responsible for what you traffic in many ways. This network is dropping the ball.
And even if I submit code that is malicious from the start, if it also correctly serves an advert, will you actually notice the extra code if all it's doing is opening a few extra connections?
Maybe you have answers to these questions - I've never worked on an adops side at all, I'm on the buying side, so never had to worry about it.
p.s. Dropped you an email earlier Brad - give me a shout, I really want to try out Perfect Audience!
You can let your advertisers run JavaScript in ads without letting them inject script tags pointing to external URLs. There's no risk in the script changing if you're only hosting inline code they have no access to after review.
How would you do that? That's equivalent to the halting problem. There is an infinite number of ways to assemble code that will execute arbitrary code, which can can assemble code that will execute arbitrary code, which ...
Deleted comment
So the vetting we do is somewhat extreme. We ask you to sign on as an enterprise customer to run ads like that. Making things more official tends to weed people out pretty quickly and leaves us just the well-intending players.
I do want to know what network it is - probably a fly-by-night outfit.
We can allow HTML/JS in our ads because we inspect them and only allow direct references (no external libraries) in-ad.
The safer thing to do, would be to require that the entire payload be delivered together, index.html, with images/js/css etc (uncompressed)... then do the min/merge and inline it all into the html before serving.
So which is it? They generally know whose fault it is, but not whose fault it is (person/team/some developer) is what they probably meant.
"RequestPolicy" on the other hand does work against this. For example, when I visit threatpost.com, it wants to pull in content from the following external domains:
kasperskycontenthub.com
addthis.com
gravatar.com
wordpress.com
google.com
twitter.com
google-analytics.com
cloudfront.net
fonts.googleapis.com
RequestPolicy blocks all of this by default, and the site and content is still perfectly readable.In my browser it takes 39 http requests and 1MB of data transfer to view the page. If I were to disable RequestPolicy however, due to all the extra pointless crap the site wants to load those numbers would increase to 86 requests and 2.3MB.
If you don't want your sites security to depend on a third party, don't allow that third party to run code on it.
http://www.html5rocks.com/en/tutorials/security/sandboxed-if...
Now it may be argued that genuine Rich HTML ads do need javascript, for example, to expand or interact with the page. To me, the solution to this is to limit what sort of javascript is allowed to run. We need an mraid.js for the web, which specifies the subset of javascript that could be run.
I don't think it will happen until there is a major attack. Other than botnets, javascript can mess with cookies, steal data, and do a lot of damage.
This isn't quite as easy to do as you might think however. While the cost might be low to run the ads, typically most RTB ad networks do not actually allow you to use external ad tags that can call arbitrary JS.
That said, some do allow this (like the one the speaker used), and the ones who don't police their JS ad tags are going to be wide awake tonight thinking of how they can.
Edit: I'm thinking more about this and I think it'd be fun to work on if anyone feels the same way.
If you're interested in working on it, there's at least one or two startups trying it at any given time you could try to work with. http://crowdprocess.com/ is relatively new. Many have had the same idea and eventually closed down.
Let's say you pay $5CPM - $5 for every 1000 views. Let's say every viewer stays on the page for a minute, and every viewer is able to provide 10 MHash/s, which I think is pretty generous for a Javascript based miner. That means you get a minute of 10,000Mhash/s for $5. The Mining Factor 100 is currently 0.17 USD/24h@100MHash/s (http://www.bitcoinx.com/profit/). That works out to be about $0.0047 in return for that $5. My numbers are probably off, but I think it's still a couple orders of magnitude from being profitable.
Even if everyone was running a top-of-the-line GPU, and you were able to squeeze 500Mhash/s out of everyone, it'd still just be about $0.24 for every $5 spent.
EDIT: Oooo, others have thought of something similar: http://hackaday.com/2009/03/03/distributed-computing-in-java...
For exactly this kind of issue, we're building an ad tag monitoring solution for publishers (and we're hiring). www.clarityad.com