Notices
Reply

Thread: Drive by install

 
Tools Search
  #1  
Old January 29th, 2005, 05:18 PM
ABW Founder
Join Date: January 18th, 2005
Location: New York
Posts: 21,651
Send a message via AIM to Haiko de Poel, Jr.
Responsible marketing and distrubution this isn't!
Attached Images
File Type: gif SAHS.gif (91.2 KB, 123 views)
__________________
Continued Success,

Haiko
The secret of success is constancy of purpose ~ Disraeli

Last edited by Haiko de Poel, Jr.; February 8th, 2005 at 05:28 PM. Reason: Edited Title per - http://forum.abestweb.com/showpost.php?p=408180&postcount=11
  #2  
Old January 31st, 2005, 03:49 PM
Full Member
Join Date: January 18th, 2005
Posts: 473
Good find. Lots more where this came from, of course. Look especially closely at sites targeting children -- who are perhaps more likely to be tricked into pressing YES.

It's also troubling to see VeriSign standing by and letting this happen -- issuing (and failing to revoke) certs used for these misleading installations. I'm working on an article about this aspect of the ActiveX/drive-by problem.
  #3  
Old February 2nd, 2005, 09:20 PM
Internet Cowboy
Join Date: January 18th, 2005
Posts: 4,677
I have gotten this before as well. If your browser takes more than a few seconds to get to any given address, it redirects to their web site. Was fairly easy to get rid of though, had to delete it from the registry.
__________________

Join ABW to remove this sponsored message.
  #4  
Old February 2nd, 2005, 09:28 PM
Resident Genius and Staunch Capitalist
Join Date: January 18th, 2005
Location: Florida
Posts: 12,827
Quote:
Originally Posted by scohaz
Was fairly easy to get rid of though, had to delete it from the registry.
Messing with the registry doesn't sound like something most people would find "easy..."
__________________
There is no knowledge that is not power. ~Hemingway
Digital Scales
  #5  
Old February 2nd, 2005, 09:52 PM
2005 Linkshare Golden Link Award Winner 
Join Date: January 18th, 2005
Location: St Clair Shores MI.
Posts: 17,373
Does this count as an example of an Adult Adwhore (SAHS) paying some freebee pervert to sucker punch a 6 year old.
__________________
Webmaster's... Mike and Charlie

"What have you done today to put real value into a referral click...from a shoppers viewpoint!"
  #6  
Old February 2nd, 2005, 09:56 PM
Full Member
Join Date: January 18th, 2005
Posts: 473
I just posted a new article specifically on the subject of this deceptive method of installation. I've provided some particularly outrageous examples -- for example, an ActiveX signed by a company purportedly called "Click yes to continue." Also notable, and in fact the subject of my new article, is the fact that VeriSign allows and profits from these scams -- failing to enforce VeriSign's own rules as to accuracy in company names and as to prohibition against deceptive, malicious, or harmful installations.

How VeriSign Could Stop Drive-By Downloads
Join ABW to remove this sponsored message.
  #7  
Old February 2nd, 2005, 10:20 PM
2005 Linkshare Golden Link Award Winner 
Join Date: January 18th, 2005
Location: St Clair Shores MI.
Posts: 17,373
I say some quotes online from that article. Good sleuth work there Ben. The Feds are dying to make some of big networks and datamining perps like Comscore fork over huge fines in exchange for jailtime.
__________________
Webmaster's... Mike and Charlie

"What have you done today to put real value into a referral click...from a shoppers viewpoint!"
  #8  
Old February 3rd, 2005, 09:06 PM
Internet Cowboy
Join Date: January 18th, 2005
Posts: 4,677
I am on someone's spam list selling software at ridiculously cheap prices.
One day, I clicked on their link just to look and see what kind of site it is. This is where I got it.

Ben,
If you don't mind I will forward you the next e-mail I get like this. Of course they are all from different people, but it is very easy to pick them out.
The time I clicked on it, I got the bug and never saw a popup window or anything. It is obviously very easily and very secretively installed.
__________________

  #9  
Old February 4th, 2005, 04:44 AM
Full Member
Join Date: January 17th, 2005
Location: UK
Posts: 277
Can someone enlighten me on what exactly a drive-by-install actually is.

I assume it is catching some sort of spyware without any action by merely viewing a web page, but what is the mechanism in broad terms?

Is it to do with Activex X which I have always disliked as a way of distributing program code over the net as it is too dangerous,

I have got all the Activex options set to either be Disable or Prompt.

I have Javascript and Java enabled as I have always assumed the latter is OK and the former makes the web much easier to use.

Les
Join ABW to remove this sponsored message.
  #10  
Old February 4th, 2005, 09:39 AM
Full Member
Join Date: January 18th, 2005
Posts: 473
Websmith: A drive-by, to my mind, is any software installation that begins merely as a result of viewing a web page (other than a web page actually needing such software, or any web page specifically for the purpose of installing such software). An ActiveX installer fits this method, because the code (CAB file) is downloaded to a user's PC before the user is even told what's happening. Installation through security holes certainly also fits this definition.

Some folks think an installation is only a drive-by if user consent is not required at any stage of the process -- so security hole installations would meet the definition, but ActiveX installations would not, in general. Based on the harms users face from ActiveX installs, like what Haiko posted at the start of this thread, I think the better definition of drive-by is the more inclusive definition that includes the misleading ActiveX installations. But draw your own conclusions.
  #11  
Old February 8th, 2005, 05:27 PM
ABW Founder
Join Date: January 18th, 2005
Location: New York
Posts: 21,651
Send a message via AIM to Haiko de Poel, Jr.
I spoke with Marc Braunstein (CEO of SaHS) today and after clarifying what actually transpired, we both agreed that this was NOT a drive by *install* but, notwithstanding, this advertising medium ... as is, was flawed in "ethical" downloadable app marketing.

More on this on our next Affiliate Marketing Today Radio Show 2/15/05
__________________
Continued Success,

Haiko
The secret of success is constancy of purpose ~ Disraeli
  #12  
Old February 8th, 2005, 05:35 PM
Full Member
Join Date: January 18th, 2005
Posts: 473
It all depends on what "drive-by" means. Does a "drive-by" only occur when software is installed on a user's computer with absolutely no consent whatsoever? Or can we use that term to describe a misleading installation that begins randomly, as users perform some unrelated task, but admittedly still requires some user "consent" (e.g. pressing YES in a popup)? I think the term is still appropriate in the latter circumstance -- especially when the installation prompt was triggered by a totally unrelated site (particularly outrageous: a site targeted at minors or other unsophisticated users), and especially when the installation disclosures are deficient in any material respect. So I still think the term drive-by is appropriate for the screen-shot shown above.
Join ABW to remove this sponsored message.
  #13  
Old February 14th, 2005, 11:13 AM
Tree Hugging Liberal Hippy Realist
Join Date: January 18th, 2005
Posts: 2,938
Hey Ben,

How's your site holding up to being slashdotted for the http://www.benedelman.org/news/020305-1.html article? :^)
  #14  
Old February 14th, 2005, 11:40 AM
2005 Linkshare Golden Link Award Winner 
Join Date: January 18th, 2005
Location: St Clair Shores MI.
Posts: 17,373
Take it too Verisign Ben as they have a simple cure to deceptive drive-by installs if the BHO perps and the IAB/DMA haven't paid in some hush monies.
__________________
Webmaster's... Mike and Charlie

"What have you done today to put real value into a referral click...from a shoppers viewpoint!"
  #15  
Old February 14th, 2005, 11:46 AM
Full Member
Join Date: January 18th, 2005
Posts: 473
No problem with today's Slashdot'ing. DDoS has stopped, which makes things that much easier.

I think VeriSign is on shaky ground in issuing certs to facially invalid company names like "Click Yes to Continue." We'll see what happens...
Join ABW to remove this sponsored message.
  #16  
Old February 15th, 2005, 02:03 AM
Tree Hugging Liberal Hippy Realist
Join Date: January 18th, 2005
Posts: 2,938
The power of trust, yadda yadda.

Blerkkkkk.
Reply

Tools Search
Search:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
UGH!!!!!!!!! bob95603 Midnight Cafe' 24 August 8th, 2006 01:20 PM
PCMicroStore - Deals for the Day !! Andy Rodriguez Andy Rodriguez Consulting 42 October 27th, 2004 02:32 PM
Sqwire Toolbar Drive by appbizz Suspicious Activity! 6 June 6th, 2003 07:33 PM
Hard drive DIED - This Time I LOST EVERYTHING!! JadaKiss Midnight Cafe' 20 May 28th, 2002 06:44 PM


Content Relevant URLs by vBSEO ©2011, Crawlability, Inc.