Live data from Hacker News

Google Ad Disguising Itself as www.gimp.org

old.reddit.com

51–60 of 230 posts

Re: Google Ad Disguising Itself as www.gimp.org

#51
post #34

EDIT: There is definitely a mismatch between the display URL and the landing page URL. It's not clear to me how that can happen; for example https://www.youtube.com/watch?v=jx-gl6K2zQw shows that only the display path can be edited (not the domain), consistently with the wording on https://support.google.com/google-ads/answer/2616010 and https://support.google.com/google-ads/answer/2375287 . On the other hand, https:…

Just tested, you can still see this Ad if you search for gimp!

I don't see any ad when I search for "gimp". Maybe it's only targeting Windows users?

edit: nevermind. I was being saved by ublock origin. Searching with it disabled shows the malicious ad.

Re: Google Ad Disguising Itself as www.gimp.org

#52

Not to defend Google but this has been against Ad Words terms for as long as I can remember. It’s surprising they found a way to evade auto detection for this.

Terms is just a document Google uses to absolve itself of all responsibility. Look! On this document nobody really reads it says we don't allow this. See? Not our fault that our advertising platform linked you to malware or to scam websites.

The proper response is of course to ignore their excuses and block all advertising unconditionally.

Re: Google Ad Disguising Itself as www.gimp.org

#53
Reported to Google, for whatever that's worth. Currently (12:42 Eastern, 29 October) the ad is #1 hit and links to www...giimp...org which further links to some very sketchy looking downloads off the discord CDN.

I've been using Bing for a year now. Not perfect, but 1) never seen something like this on it and 2) if Google feels less like an invincible monopolist, perhaps they'll have some incentive to provide an acceptable service.

Re: Google Ad Disguising Itself as www.gimp.org

#54
yeah part of google worship has created common misconceptions like that things that appear in its automatic index are true answer to whatever question you have in mind (computers cant read minds). "this is the official link for some product" being only one possible question. then theres also the fact that a search engine cannot know the answer to "this is the right link for this software". i miss when search engines were just grep for the web and didnt pretend to be something more

this is a good example of how chicken shit design leads to security vulnerabilities. google probably lets the user post one link and make it lead somewhere else when you click it, as a "UX" feature. in reality it makes phishing much easier. this could have been avoided by not being a chicken shit and making links behave as one would expect, at the cost of 1% of use cases no longer working. the whole idea of treating URLs as a UX object is a misconception anyway, URLs should be opaque bit strings.

Re: Google Ad Disguising Itself as www.gimp.org

#55
post #40
post #21

Earlier quoted context omitted.

Yeah, blocking ads quickly became security improvement...

Always was. Does anyone remember the defacto original ad-blockers that blocking popups were? Firefox was marketed with this feature. It is basically a condom for the Internet. It makes maintenance for family computers much easier.

But if you block pop-ups, that web page with Rick Astley's cool video popping up won't play.

/s

Re: Google Ad Disguising Itself as www.gimp.org

#56
post #34

EDIT: There is definitely a mismatch between the display URL and the landing page URL. It's not clear to me how that can happen; for example https://www.youtube.com/watch?v=jx-gl6K2zQw shows that only the display path can be edited (not the domain), consistently with the wording on https://support.google.com/google-ads/answer/2616010 and https://support.google.com/google-ads/answer/2375287 . On the other hand, https:…

Yeah Google Ads lies about the destination URL, it always has. Which is why the correct choice is to consider Google Ad links malicious by default. There's actually no way to be sure where clicking them will send you, and tons of fraudsters have put scam ads with the official legit domain listed. I've seen both Amazon and Best Buy URLs on scam ads.

The entire hackjacking of the URLs needs to stop. It is destroying the web. From Safari hiding the full path in the browser in the name of "minimalism" to AMP and all the other bullshit.

URLs are sacred. Please don't fuck with them. Please.

Re: Google Ad Disguising Itself as www.gimp.org

#57
I was able to find this by searching for 'gimp download', and the gimp.org displayed ad redirected to 'gimp dot monster' and looked pretty good otherwise.

This is amazingly frustrating because I've wasted weeks of my life trying to deal with how google usually makes this impossible.

Re: Google Ad Disguising Itself as www.gimp.org

#60
post #34

EDIT: There is definitely a mismatch between the display URL and the landing page URL. It's not clear to me how that can happen; for example https://www.youtube.com/watch?v=jx-gl6K2zQw shows that only the display path can be edited (not the domain), consistently with the wording on https://support.google.com/google-ads/answer/2616010 and https://support.google.com/google-ads/answer/2375287 . On the other hand, https:…

I can't get the ad to show up for me, but maybe GIMP has an open redirect on their website and the malvertiser is taking advantage of that?

That's what I thought too, but I managed to get the malicious ad and confirmed that it's a destination mismatch in Google Ads rather than an open redirect (no requests to gimp.org in the network monitor).
Post reply on HN