When Internet providers hire third-party companies to serve up advertisements on unused Web pages, that creative attempt to make money can open major security vulnerabilities they can’t control, a researcher has found.
One such vulnerability — described last weekend at a security conference by Dan Kaminsky, director of penetration testing for Seattle-based computer security consultant IOActive Inc. — works like this:
Say you mistype the name of a Web site into your browser. Instead of getting an error message, you get a wall of advertisements whose profits flow back to your Internet provider.
A hacker who breaks into the computer system of the company hired to display those ads can cause all kinds of mayhem, injecting code onto the pages you see or altering the pages to trick you into coughing up sensitive personal information.
“The security of the Web for these ISPs is limited to the security of these random ad servers,” Kaminsky said in an interview.
Kaminsky’s presentation centered around a “dead trivial vulnerability” he discovered on the servers used by U.K.-based Barefruit to serve ads for EarthLink Inc.’s Internet service.
The so-called “cross-site scripting” vulnerability allowed him to place his own code and content on pages Barefruit was serving.
Barefruit Chief Executive Dave Roberts said the company fixed the vulnerability — which he said could be exploited only in “incredibly unlikely circumstances” — within 30 minutes after Kaminsky told the company about it.
Kevin Brand, senior vice president for access products for Earthlink, said no users were harmed by the vulnerability, and he said Earthlink lets customers opt out of seeing ads on unused Web pages. But it requires them to alter the settings on their computers to do that.
“We’re not trying to hold any of our customers hostage by any means,” he said. “We’re just trying to improve their experience.”
Other security experts said Kaminsky’s…