# An idea on how to reduce malware on the SDMB

**URL:** <https://boards.straightdope.com/t/an-idea-on-how-to-reduce-malware-on-the-sdmb/607358>\
**Category:** About This Message Board\
**Created:** [December 25, 2011, 2:06pm UTC](https://boards.straightdope.com/t/an-idea-on-how-to-reduce-malware-on-the-sdmb/607358 "2011-12-25T14:06:30Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![robert\_columbia](https://avatars.discourse-cdn.com/v4/letter/r/e79b87/32.png) [@robert\_columbia](https://boards.straightdope.com/u/robert_columbia)\
**Post date:** [December 25, 2011, 2:06pm UTC](https://boards.straightdope.com/t/an-idea-on-how-to-reduce-malware-on-the-sdmb/607358/1 "2011-12-25T14:06:30Z")

</div>

It seems to be that ads served by the SD are the source of the malware people see on this site, and the SD claims that it is a victim of malicious advertisers. What if the SD insisted that ads be a simple image only, with no dynamic content, and enforce this through technical measures (e.g. a GetAdvertisement(currentUser) method that verifies that the ad that it is returning is a simple image and/or text)?

---

<div class="post-metadata">

**Author:** ![TubaDiva](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tubadiva/32/507_2.png) [@TubaDiva](https://boards.straightdope.com/u/TubaDiva)\
**Post date:** [December 25, 2011, 4:36pm UTC](https://boards.straightdope.com/t/an-idea-on-how-to-reduce-malware-on-the-sdmb/607358/2 "2011-12-25T16:36:31Z")

</div>

Man, of all the days to be asking this. 🙂

I’ve got a Christmas dinner to prepare – and the rest of the staff has family obligations, etc.

We’ll get back to you later. The short answer is that you don’t fully know the situation. I’ll be back tomorrow and we’ll sort this out, hopefully to your satisfaction.

Happy Holidays, everyone.

---

<div class="post-metadata">

**Author:** ![TubaDiva](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tubadiva/32/507_2.png) [@TubaDiva](https://boards.straightdope.com/u/TubaDiva)\
**Post date:** [December 25, 2011, 4:40pm UTC](https://boards.straightdope.com/t/an-idea-on-how-to-reduce-malware-on-the-sdmb/607358/3 "2011-12-25T16:40:13Z")

</div>

Here’s a bit of outside reading:

[http://www.usatoday.com/tech/news/story/2011-10-31/corrupted-ads/51048084/1](http://www.usatoday.com/tech/news/story/2011-10-31/corrupted-ads/51048084/1)

> **[Ten-fold rise in malicious ads bedevils publishers, consumers | The Last...](https://www.lastwatchdog.com/ten-fold-rise-malicious-ads-bedevils-publishers-consumers/)**
>
> By Byron Acohido, USA TODAY, 03Nov2011, P1A The online advertising industry is scrambling to quell a long-standing problem that has taken a turn for the worse: the spread of malicious ads on the Internetâ€™s top commercial websites. Several new...

[http://www.infosecisland.com/blogview/14371-Malvertising-The-Use-of-Malicious-Ads-to-Install-Malware.html](http://www.infosecisland.com/blogview/14371-Malvertising-The-Use-of-Malicious-Ads-to-Install-Malware.html)

It’s a huge problem. It’s not just us. The incidence of these threats is increasing.

---

<div class="post-metadata">

**Author:** ![MeanOldLady](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/meanoldlady/32/10737_2.png) [@MeanOldLady](https://boards.straightdope.com/u/MeanOldLady)\
**Post date:** [December 27, 2011, 12:53am UTC](https://boards.straightdope.com/t/an-idea-on-how-to-reduce-malware-on-the-sdmb/607358/4 "2011-12-27T00:53:27Z")

</div>

> [@TubaDiva](#):
>
> Man, of all the days to be asking this. 🙂
> 
> I’ve got a Christmas dinner to prepare – and the rest of the staff has family obligations, etc.
> 
> We’ll get back to you later. The short answer is that you don’t fully know the situation. I’ll be back tomorrow and we’ll sort this out, hopefully to your satisfaction.
> 
> Happy Holidays, everyone.

As a proud member of the SDMB Malware Recipient Club, I am absolutely dying to know what the full situation is.

---

<div class="post-metadata">

**Author:** ![coolbyrne](https://avatars.discourse-cdn.com/v4/letter/c/bc79bd/32.png) [@coolbyrne](https://boards.straightdope.com/u/coolbyrne)\
**Post date:** [December 27, 2011, 1:49am UTC](https://boards.straightdope.com/t/an-idea-on-how-to-reduce-malware-on-the-sdmb/607358/5 "2011-12-27T01:49:28Z")

</div>

> [@TubaDiva](#):
>
> Here’s a bit of outside reading:
> 
> [http://www.usatoday.com/tech/news/story/2011-10-31/corrupted-ads/51048084/1](http://www.usatoday.com/tech/news/story/2011-10-31/corrupted-ads/51048084/1)
> 
> [Ten-fold rise in malicious ads bedevils publishers, consumers - The Last Watchdog](http://lastwatchdog.com/ten-fold-rise-malicious-ads-bedevils-publishers-consumers/)
> 
> [http://www.infosecisland.com/blogview/14371-Malvertising-The-Use-of-Malicious-Ads-to-Install-Malware.html](http://www.infosecisland.com/blogview/14371-Malvertising-The-Use-of-Malicious-Ads-to-Install-Malware.html)
> 
> It’s a huge problem. It’s not just us. The incidence of these threats is increasing.

But this has been going on here for ages. Time after time, people with actual tech knowledge have given advice on how to curtail the problem, yet the best response to date is to ban IPs?

---

<div class="post-metadata">

**Author:** ![Amblydoper](https://avatars.discourse-cdn.com/v4/letter/a/fbc32d/32.png) [@Amblydoper](https://boards.straightdope.com/u/Amblydoper)\
**Post date:** [December 27, 2011, 2:50am UTC](https://boards.straightdope.com/t/an-idea-on-how-to-reduce-malware-on-the-sdmb/607358/6 "2011-12-27T02:50:22Z")

</div>

Why don’t you switch to an advertising network like The Deck?  
[http://decknetwork.net/](http://decknetwork.net/)

They do single, targeted ads rather then the standard shotgun approach.  
They are proof that advertising doesn’t have to be intruding and excessive.

---

<div class="post-metadata">

**Author:** ![AClockworkMelon](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/aclockworkmelon/32/10803_2.png) [@AClockworkMelon](https://boards.straightdope.com/u/AClockworkMelon)\
**Post date:** [December 27, 2011, 3:17am UTC](https://boards.straightdope.com/t/an-idea-on-how-to-reduce-malware-on-the-sdmb/607358/7 "2011-12-27T03:17:37Z")

</div>

> [@Amblydoper](#):
>
> Why don’t you switch to an advertising network like The Deck?  
> [http://decknetwork.net/](http://decknetwork.net/)
> 
> They do single, targeted ads rather then the standard shotgun approach.  
> They are proof that advertising doesn’t have to be intruding and excessive.

But do they pay as much as the current ad providers? I think that’s the [del]only[/del] primary concern.

---

<div class="post-metadata">

**Author:** ![samclem](https://avatars.discourse-cdn.com/v4/letter/s/a9a28c/32.png) [@samclem](https://boards.straightdope.com/u/samclem)\
**Post date:** [December 27, 2011, 3:32am UTC](https://boards.straightdope.com/t/an-idea-on-how-to-reduce-malware-on-the-sdmb/607358/8 "2011-12-27T03:32:49Z")

</div>

> [@coolbyrne](#):
>
> But this has been going on here for ages. Time after time, people with actual tech knowledge have given advice on how to curtail the problem, yet the best response to date is to ban IPs?

Maybe those people could better spend their time helping the top 500 websites that have the same problems that we have.

Did you even read the articles ?

---

<div class="post-metadata">

**Author:** ![carnivorousplant](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/carnivorousplant/32/3563_2.png) [@carnivorousplant](https://boards.straightdope.com/u/carnivorousplant)\
**Post date:** [December 27, 2011, 4:30am UTC](https://boards.straightdope.com/t/an-idea-on-how-to-reduce-malware-on-the-sdmb/607358/9 "2011-12-27T04:30:14Z")

</div>

Perhaps the SDMB is trying to get the most bang for their buck so that they will stay in business and we can keep posting, you reckon?

---

<div class="post-metadata">

**Author:** ![Guinastasia](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/guinastasia/32/5751_2.png) [@Guinastasia](https://boards.straightdope.com/u/Guinastasia)\
**Post date:** [December 27, 2011, 4:37am UTC](https://boards.straightdope.com/t/an-idea-on-how-to-reduce-malware-on-the-sdmb/607358/10 "2011-12-27T04:37:57Z")

</div>

> [@carnivorousplant](#):
>
> Perhaps the SDMB is trying to get the most bang for their buck so that they will stay in business and we can keep posting, you reckon?

By giving their visitors malware?

---

<div class="post-metadata">

**Author:** ![carnivorousplant](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/carnivorousplant/32/3563_2.png) [@carnivorousplant](https://boards.straightdope.com/u/carnivorousplant)\
**Post date:** [December 27, 2011, 4:45am UTC](https://boards.straightdope.com/t/an-idea-on-how-to-reduce-malware-on-the-sdmb/607358/11 "2011-12-27T04:45:35Z")

</div>

> [@Guinastasia](#):
>
> By giving their visitors malware?

If more folks paid, they may be able to afford better.

Am I sucking up enough, Twicks? 🙂

---

<div class="post-metadata">

**Author:** ![splatterpunk](https://avatars.discourse-cdn.com/v4/letter/s/3be4f8/32.png) [@splatterpunk](https://boards.straightdope.com/u/splatterpunk)\
**Post date:** [December 27, 2011, 6:14am UTC](https://boards.straightdope.com/t/an-idea-on-how-to-reduce-malware-on-the-sdmb/607358/12 "2011-12-27T06:14:53Z")

</div>

> [@carnivorousplant](#):
>
> If more folks paid, they may be able to afford better.
> 
> Am I sucking up enough, Twicks? 🙂

No. Keep at it; you might convince someone.

---

<div class="post-metadata">

**Author:** ![Senegoid](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/senegoid/32/6606_2.png) [@Senegoid](https://boards.straightdope.com/u/Senegoid)\
**Post date:** [December 27, 2011, 9:36am UTC](https://boards.straightdope.com/t/an-idea-on-how-to-reduce-malware-on-the-sdmb/607358/13 "2011-12-27T09:36:37Z")

</div>

I don’t get infected, mainly because I use Linux I think, and I NEVER click on ads, and I rarely enable JavaScript. I also don’t have Flash, or any Flash-equivalent (that I know of) installed here, or at least, it isn’t enabled.

I am wondering this: Do infections happen when a user views a SDMB page with a mal-ad in it? Or does it only happen when a user actually clicks on the ad? I sure don’t see much advertising on SDMB even though I’m a “guest” user, and what little I do see looks like simple plain-text stuff.

TubaDiva, does SDMB get paid simply for displaying ads? Or do you get paid when your users click on those ads and the advertiser sees SDMB is the referrer? Maybe you make your money even if your users all run Ad-Block, or maybe you only make some money when users actually see and click the ads? Depending on which is the case, I think it could make a lot of difference what strategy and importance SDMB assigns to the problem.

---

<div class="post-metadata">

**Author:** ![Skywatcher](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/skywatcher/32/254_2.png) [@Skywatcher](https://boards.straightdope.com/u/Skywatcher)\
**Post date:** [December 27, 2011, 1:31pm UTC](https://boards.straightdope.com/t/an-idea-on-how-to-reduce-malware-on-the-sdmb/607358/14 "2011-12-27T13:31:26Z")

</div>

> [@Senegoid](#):
>
> I am wondering this: Do infections happen when a user views a SDMB page with a mal-ad in it? Or does it only happen when a user actually clicks on the ad? I sure don’t see much advertising on SDMB even though I’m a “guest” user, and what little I do see looks like simple plain-text stuff.

Malware can get in without clicking on any ad, yes. AV Protection 2011, for example, apparently propregates by altering a page’s code and is able to install itself without triggering a “are you sure you want this to modify your system” prompt.

---

<div class="post-metadata">

**Author:** ![Gagundathar](https://avatars.discourse-cdn.com/v4/letter/g/a183cd/32.png) [@Gagundathar](https://boards.straightdope.com/u/Gagundathar)\
**Post date:** [December 27, 2011, 1:36pm UTC](https://boards.straightdope.com/t/an-idea-on-how-to-reduce-malware-on-the-sdmb/607358/15 "2011-12-27T13:36:06Z")

</div>

> [@Lute Skywatcher](#):
>
> Malware can get in without clicking on any ad, yes. AV Protection 2011, for example, apparently propregates by altering a page’s code and is able to install itself without triggering a “are you sure you want this to modify your system” prompt.

WAT? There is a program called ‘AV Protection 2011’ that is actually a blankety-blank VIRUS?

Why do these things even exist? Who makes money off of them?  
:mad:

---

<div class="post-metadata">

**Author:** ![Skywatcher](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/skywatcher/32/254_2.png) [@Skywatcher](https://boards.straightdope.com/u/Skywatcher)\
**Post date:** [December 27, 2011, 3:07pm UTC](https://boards.straightdope.com/t/an-idea-on-how-to-reduce-malware-on-the-sdmb/607358/16 "2011-12-27T15:07:11Z")

</div>

> [@Gagundathar](#):
>
> WAT? There is a program called ‘AV Protection 2011’ that is actually a blankety-blank VIRUS?

Technically malware but, yeah. Got hit by it myself while visiting a Tropes page.

> [@](#):
>
> Why do these things even exist? Who makes money off of them?  
> :mad:

It’s one of those things that generate false virus reports and try to get people pay to “remove” the “viruses”. A similar thing was hanging around the SDMB a while back.

---

<div class="post-metadata">

**Author:** ![TubaDiva](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tubadiva/32/507_2.png) [@TubaDiva](https://boards.straightdope.com/u/TubaDiva)\
**Post date:** [December 27, 2011, 3:07pm UTC](https://boards.straightdope.com/t/an-idea-on-how-to-reduce-malware-on-the-sdmb/607358/17 "2011-12-27T15:07:49Z")

</div>

> [@Gagundathar](#):
>
> WAT? There is a program called ‘AV Protection 2011’ that is actually a blankety-blank VIRUS?
> 
> Why do these things even exist? Who makes money off of them?  
> :mad:

The Mob, apparently.

“Organized crime gangs have streamlined the process of sneaking viral ads into the distribution system run by advertising networks, causing billions of tainted ad impressions to appear on the top 500 websites over the past 12 months, say technologists and security researchers.”

[http://www.usatoday.com/tech/news/story/2011-10-31/corrupted-ads/51048084/1?AID=4992781&PID=4169914&SID=cyz5awegb3h2](http://www.usatoday.com/tech/news/story/2011-10-31/corrupted-ads/51048084/1?AID=4992781&PID=4169914&SID=cyz5awegb3h2)

---

<div class="post-metadata">

**Author:** ![SCSimmons](https://avatars.discourse-cdn.com/v4/letter/s/e495f1/32.png) [@SCSimmons](https://boards.straightdope.com/u/SCSimmons)\
**Post date:** [December 27, 2011, 3:34pm UTC](https://boards.straightdope.com/t/an-idea-on-how-to-reduce-malware-on-the-sdmb/607358/18 "2011-12-27T15:34:16Z")

</div>

> [@Gagundathar](#):
>
> WAT? There is a program called ‘AV Protection 2011’ that is actually a blankety-blank VIRUS?

What, you expected that virus writers would call their programs stuff like ‘nastytrojan.exe’?

---

<div class="post-metadata">

**Author:** ![coolbyrne](https://avatars.discourse-cdn.com/v4/letter/c/bc79bd/32.png) [@coolbyrne](https://boards.straightdope.com/u/coolbyrne)\
**Post date:** [December 27, 2011, 6:09pm UTC](https://boards.straightdope.com/t/an-idea-on-how-to-reduce-malware-on-the-sdmb/607358/19 "2011-12-27T18:09:45Z")

</div>

> [@samclem](#):
>
> Maybe those people could better spend their time helping the top 500 websites that have the same problems that we have.
> 
> Did you even read the articles ?

I don’t care about the 500 other websites that have the same problem. I visit this site. If I visit any of those other 500 websites and have an issue with them doing nothing more than banning IPs after people have given suggestion after suggestion on how to fix the issue, then I’ll bring up the same complaint I’ve brought up here. Until then, what is THIS board going to do to curtail the problem THIS board is having?

---

<div class="post-metadata">

**Author:** ![Guinastasia](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/guinastasia/32/5751_2.png) [@Guinastasia](https://boards.straightdope.com/u/Guinastasia)\
**Post date:** [December 27, 2011, 8:17pm UTC](https://boards.straightdope.com/t/an-idea-on-how-to-reduce-malware-on-the-sdmb/607358/20 "2011-12-27T20:17:12Z")

</div>

> [@Gagundathar](#):
>
> WAT? There is a program called ‘AV Protection 2011’ that is actually a blankety-blank VIRUS?
> 
> Why do these things even exist? Who makes money off of them?  
> :mad:

It’s called “scare ware”. Pretty nasty. I got hit with one a year ago.

[Next page](https://boards.straightdope.com/t/an-idea-on-how-to-reduce-malware-on-the-sdmb/607358.md?page=2)
