Malvertising
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
Embedded adverts are a common target for hackers.
- Prevalence
- Occasional
- Exploitability
- Moderate
- Impact
- Devastating
What is malvertising?
Malvertising is a malware delivery attack in which an attacker buys or compromises advertising space on an ad network to serve malicious or deceptive adverts. The adverts appear on legitimate websites, including yours, and can redirect visitors to scam pages or install malware. Site owners are rarely the target, but their users are the victims.
What you'll learn
- How an advert passes through networks and exchanges to reach your page
- Why delayed, targeted payloads are hard for ad networks to detect
- How vetting ad partners and a Content Security Policy protect your visitors
This lesson includes
-
Malvertising lab
Follow an advert through the chain of networks and exchanges that deliver it to a page, then watch what happens when one server in that chain is compromised. The lab shows why targeted, delayed payloads are hard for ad networks to detect.
-
How to prevent Malvertising
The prevention guide covers five approaches:
- Work with Reputable Ad Networks
- Perform Due Diligence on Agencies and Advertisers
- Implement a Content Security Policy
- Use Client-Side Error Reporting Tools
- Log Out-Going URLs
-
Malvertising quiz
Three questions. Passing marks the lesson complete.
Sources
- Malvertising campaign leads to info stealers hosted on GitHub Microsoft
- Why does malvertising work? Center for Internet Security
- Google's Guide to Anti-Malvertising Google
Related lessons
Browse all 45 lessons
Toxic Dependencies
Third-party libraries could be introducing vulnerabilities or malicious code into your system.
Clickjacking
As an application author, you need to be sure your users aren't having their clicks stolen by attackers.
Subdomain Squatting
Attackers will steal dangling subdomains to deliver malware and perform phishing attacks.
Cross-Site Scripting
If your site allows users to add content, you need to be sure that attackers cannot inject malicious JavaScript.