Live data from Hacker News

Google Ad Disguising Itself as www.gimp.org

old.reddit.com

31–40 of 230 posts

Re: Google Ad Disguising Itself as www.gimp.org

#32
post #14

IMO checksums more or less offer a false sense of security for users if they're stored/shared on the same page/domain as the download, since it'd be trivial for a bad actor to change them if the files are compromised. Linux mint, for example, the attacker updated the checksums for the ISOs on the page when it was compromised https://www.infoworld.com/article/3036178/lesson-from-linux-... I don't really have a solid s…

Checksums are meant to verify data integrity. Who ever said otherwise?

It doesn't matter, people still use checksums as a signal to verify if a download has been tampered with

Re: Google Ad Disguising Itself as www.gimp.org

#33
post #8
post #3

Happens for me. Ad says "gimp.org" but links to "gimp.monster". Reported.

Well, it just took me to "giipm.org", a remarkable 10 hours after this was originally posted. It shows "gimp.org" in the status bar when I highlight it with the mouse, but of course "copy link address" just gets a link going through www.googleadservices.com/pagead/ with some long hashes at the end.

It looks like the Dropbox file at least 404s now. IDK if that is the attacker bailing out or Dropbox actually doing something faster even though it arguably didn't do anything wrong. But Google, the enabler is still sitting on its hands.

Re: Google Ad Disguising Itself as www.gimp.org

#34
EDIT: There is definitely a mismatch between the display URL and the landing page URL. It's not clear to me how that can happen; for example https://www.youtube.com/watch?v=jx-gl6K2zQw shows that only the display path can be edited (not the domain), consistently with the wording on https://support.google.com/google-ads/answer/2616010 and https://support.google.com/google-ads/answer/2375287. On the other hand, https://support.google.com/adspolicy/answer/6368661 talks about destination mismatch as if it is technically possible and just forbidden by policy.

The ad's ID is DChcSEwiPvfuL-YX7AhVmkmYCHUXQC1wYABAAGgJzbQ (displayed when reporting it), the display URL is https://www.gimp.org/ and the final location after clicking the ad is https[:]//gilimp[.]org/ (with no intermediate redirects via gimp.org).

Update: The DNS records for gilimp.org have been deleted. Archived snapshot: https://web.archive.org/web/20221029152445/https://gilimp.or....

-------------

Original comment:

The Reddit user says the ad's display URL was different from landing page URL. If that's the case it is particularly concerning. I believe Google Ads only allows the advertiser to set the path component of the display URL, and takes the domain from the landing page (real) URL; so it's unclear how the mismatch could happen.

Maybe the Reddit user took the screenshot on a separate occasion from when they clicked the malicious link, and the ad changed in that time (currently I can see an ad for GIMP, and it links to the official domain, and the linked Twitter thread linked by @pmoriarty says the attacker is actively changing things). The only other explanation I can think of is that the official GIMP website has an open redirect vulnerability.

Re: Google Ad Disguising Itself as www.gimp.org

#35
post #25

Earlier quoted context omitted.

It's just a setting in Google AdWords. The display URL and target URL are not related. You can also play tricks like a "tracking URL template" that is a URL that can be on another domain and receives the "target URL" as a parameter. It is expected to redirect to the correct URL, of course nothing enforces this other than a manual review. I can't believe that Google allows this but tracking is clearly more important t…

Of course it is, they live off ads.

Kind of wild they don't require domain ownership proof in this case though, if I'm displaying one domain but actually linking to another, I should need to prove I own the original domain

Re: Google Ad Disguising Itself as www.gimp.org

#36

This is outrageous. We need to find a way to stop Google. Google invades our privacy. Google holds us hostages for more money. Now this? When is enough is enough?

As outrageous as a site having a leak or being hacked. As for what someone can do. It's simple. Don't use Google.

Easier said than done. It seems like 40 precent of sites or better use some sort of google service. Even if you arent 'using' google, you are being used by google.

Re: Google Ad Disguising Itself as www.gimp.org

#37

This is outrageous. We need to find a way to stop Google. Google invades our privacy. Google holds us hostages for more money. Now this? When is enough is enough?

As outrageous as a site having a leak or being hacked. As for what someone can do. It's simple. Don't use Google.

Not using google doesn’t mean they aren’t using you. Kind of like the mafia.

Re: Google Ad Disguising Itself as www.gimp.org

#38
This has been happening to a smaller project I am affiliated with for years. You can report it to Google - typically they ignore the reports. Occasionally they'll remove the offending ad, but they are just replaced with more ads the following day. I don't think it's preventable.

Re: Google Ad Disguising Itself as www.gimp.org

#40
post #21

This is also a huge issue with Blender and pops up on /r/blender from time to time. (Here's a few random recent examples: https://redd.it/xxkx5s https://redd.it/vvrxko https://redd.it/xwkky8 https://redd.it/vuqu1r ) Ad networks and content providers get up in arms over widespread ad blocking but then allow stuff like this through.

Yeah, blocking ads quickly became security improvement...

Always was. Does anyone remember the defacto original ad-blockers that blocking popups were? Firefox was marketed with this feature.

It is basically a condom for the Internet. It makes maintenance for family computers much easier.

Post reply on HN