15–25 min Updated

Malvertising

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

Embedded adverts are a common target for hackers.

Prevalence
Occasional
Exploitability
Moderate
Impact
Devastating

What is malvertising?

Malvertising is a malware delivery attack in which an attacker buys or compromises advertising space on an ad network to serve malicious or deceptive adverts. The adverts appear on legitimate websites, including yours, and can redirect visitors to scam pages or install malware. Site owners are rarely the target, but their users are the victims.

What you'll learn

  • How an advert passes through networks and exchanges to reach your page
  • Why delayed, targeted payloads are hard for ad networks to detect
  • How vetting ad partners and a Content Security Policy protect your visitors
  • Malvertising lab

    Follow an advert through the chain of networks and exchanges that deliver it to a page, then watch what happens when one server in that chain is compromised. The lab shows why targeted, delayed payloads are hard for ad networks to detect.

  • How to prevent Malvertising

    The prevention guide covers five approaches:

    • Work with Reputable Ad Networks
    • Perform Due Diligence on Agencies and Advertisers
    • Implement a Content Security Policy
    • Use Client-Side Error Reporting Tools
    • Log Out-Going URLs
  • Malvertising quiz

    Three questions. Passing marks the lesson complete.

Sources

  • Toxic Dependencies

    Third-party libraries could be introducing vulnerabilities or malicious code into your system.

  • Clickjacking

    As an application author, you need to be sure your users aren't having their clicks stolen by attackers.

  • Subdomain Squatting

    Attackers will steal dangling subdomains to deliver malware and perform phishing attacks.

  • Cross-Site Scripting

    If your site allows users to add content, you need to be sure that attackers cannot inject malicious JavaScript.