Possible advertisment security problem

BudEWiser

Active Member
Dec 24, 2008
224
112
When I visited today I got a popup from my antivirus, and the "Internet explorer has blocked this site from downloading files onto your computer"

It is a well known fact that several advertisment providers are providing ads that have major security flaws, even on sites like the wall street journal. I just thought I would bring this to your attention as someone with out decent protection could get infected with some nastys while visiting if that advertisment happens to rotate in. I will investegate a little further to see if I can find the specific advertisment that is causing this issue.

I'm running in a virtual machine, so even if something happens to gain access I just revert to a prior state and all is good... someone else may not be so lucky.

Code:
c:\documents and settings\***\local settings\temporary internet files\content.ie5\rosjp62g\s002106201317r0409ra84ed789xce7f6693y85868706z0100f080[1].pdf
____________________________
____________________________
On computer as of
5/23/2010 at 10:10:53 PM
Last Used:
5/23/2010 at 10:10:53 PM
Startup Item: No
Launched: No
____________________________
____________________________
Very Few Users
Fewer than 10 users in the Norton Community have used this file.
____________________________
High
This file risk is high.
____________________________
Threat Details
Detection of a potential threat based on its behavior.
____________________________
Origin

Downloaded from  Not Available
____________________________
URL Not Available
UNTESTED

Source
s002106201317r0409ra84ed789xce7f6693y85868706z0100f080[1].pdf
____________________________
File Actions
File: c:\documents and settings\****\local settings\temporary internet files\content.ie5\rosjp62g\s002106201317r0409ra84ed789xce7f6693y85868706z0100f080[1].pdf
Blocked
____________________________
File Thumbprint:
db1d601e6c9f9275e0e1750f129504721a2a75208056719dec2e4ea07c2e28cc
____________________________
 

BudEWiser

Active Member
Dec 24, 2008
224
112
So far I can only say that it happens when the 18 passport advertisment at the bottom AND the Sakura Live with the lips in the upper right corner appear at the same time. They may be setting a cookie to block the file from downloading more than once, because refreshing the page and getting the same ads will not generate the security warning until I delete cookies.
Both are being served by Adbright, so maybe contacting them will help the problem go away.