Posts tagged as:

ASK

Consumergain.com spamvertise’s at Photobucket

by certifiedbug on August 30, 2008

in Security

So there I was at Photobucket looking at images when this popped up.


I clicked No and was redirected to the site anyway. In other words my browser was Hijacked.

WOT edged in to say no no no.

http://www.mywot.com/en/scorecard/consumergain.com

Site Advisor also flags consumergain.com
http://www.siteadvisor.com/sites/consumergain.com

Press release January 30, 2008 by the Federal Trade Commission (FTC).
Online Advertiser Settles FTC Charges. “Free” Products Weren’t Free; Settlement Calls for $200,000 Civil Penalty

According to the FTC, Member Source Media LLC, doing business as ConsumerGain.com, PremiumPerks.com, FreeRetailRewards.com, and GeatAmericanGiveaways.com, and the company’s principal, Chris Sommer, used deceptive spam and online advertising to lure consumers to its Web sites. For example, Member Source Media used e-mail subject lines such as, “Congratulations. You’ve won an iPod Video Player”; “Here are 2 free iPod Nanos for You: confirm now”; “Nascar Tickets Package Winner”; “Confirmation required for your $500 Visa Gift Card”; or “Second Attempt: Target Gift Card Inside.” The company’s Web-based ads contain similar representations: “CONGRATULATIONS! You Have Been Chosen To Receive a FREE GATEWAY LAPTOP.”

http://www.ftc.gov/opa/2008/01/media.shtm

The FTC should take another look at Consumergain.com.

Of secondary interest, Photobucket uses the ASK searchbar.

The searchbar can be used to perform an internal search of the website, and as with the ASK pre-checked toolbar that is offered for one’s browser during the installation of certain programs, a search still comes with plenty of sponsored results.

http://certifiedbug.com/blog/tag/ask/

{ 1 comment }

Pre-checked Installers

by certifiedbug on August 25, 2008

in Security

Bill Pytlovany posted that IAC/InterActiveCorp had asked him last week to reconsider adding their ASK toolbar to WinPatrol.

Again he declined.

It’s still surprising that programs like Zone Alarm, SpySweeper and Comodo Firewall install the Ask.com toolbar while other security programs still flag it as undesirable, suspicious or even adware.

What’s Wrong with Toolbars?

Added Donna’s Installers Hall of Shame to my Bookmarks.

See Certifiedbug’s Tag Cloud for previous posts on toolbars.

{ 0 comments }

Comodo SafeSurf Toolbar-ASK Toolbar

by certifiedbug on May 27, 2008

in Security

Comodo Firewall 3.0.23.364 offers the SafeSurf toolbar. Hmmm

STEP 8: Install Comodo SafeSurf Browser Toolbar
The Comodo SafeSurf Toolbar protects against data theft, computer crashes and system damage by preventing most types of Buffer Overflow attacks. This type of attack occurs when a malicious program or script deliberately sends more data to a target applications memory buffer than the buffer can handle - which can be exploited to create a back door to the system though which a hacker can gain access. Comodo developed the SafeSurf Toolbar explicitly to protect end-users from these kinds of attacks whilst they browse the Internet. After installation, the program will monitor and protect the memory space of all applications that are running on your system and immediately block any buffer overflow attacks. Apart from providing another essential layer of protection, the toolbar also provides one-click access to news, search, shopping; a built in pop-up blocker; is compatible with all major browsers and can be separately uninstalled or disabled at any time after installation.

we get money if you search/buy stuff using this. Its like an affiliate deal.
this way, only if you want to, you can help Comodo generate some money from searching and buying you already do, by choosing to do it via Comodo. Its a way to generate money so that we can keep bringing you even better security and products!

Topic: Re: COMODO Firewall Pro 3.0.23.364 Released!–EGEMEN

As usual Ask’s Toolbar is pre-checked for installation, you can of course opt out.

Comodo Firewall will not be added to the Calendar when the next update is available as per this thread if the Ask Toolbar is prechecked.

Calender Of Updates (COU)

I join Security Garden in being disappointed at this move by Comodo.

Certifiedbug:
Trillian Multiple Vulnerabilities
ASK Approaches WinPatrol
Another vendor bundles ASK
ZoneAlarm pre-checks toolbar
Conflict of interest at StopBadware?
InterActiveCorp/Ask Toolbars, what you need to know

{ 0 comments }

Trillian Multiple Vulnerabilities

by certifiedbug on May 23, 2008

in Security

Securia reports highly critical vulnerabilities in Trillian the popular instant messaging client.

Description:
Some vulnerabilities have been reported in Trillian, which can be exploited by malicious people to compromise a user’s system.

1) A boundary error within the header parsing code for the MSN protocol can be exploited to cause a stack-based buffer overflow via a specially crafted X-MMS-IM-FORMAT header with an overly long attribute.
Successful exploitation allows execution of arbitrary code.

2) An error within the XML parsing in talk.dll can be exploited to cause a memory corruption via certain malformed attributes within an ‘IMG’ tag.

Successful exploitation allows execution of arbitrary code.

3) A boundary error when parsing messages (e.g. via the AIM network) with overly long attribute values within the FONT tag can be exploited to cause a stack-based buffer overflow.

Successful exploitation allows execution of arbitrary code but requires that the user is tricked into opening a malicious image file.

Solution:
Update to version 3.1.10.0.
http://www.ceruleanstudios.com/downloads/

Your Trillian client may not inform you of the updates. I used the drop down menu, “Check for updates” and was informed no updates were available.

After downloading and starting the installation of the latest version, I saw the Weather Channel and ASK toolbar were offered as pre-checked options to install with Trillian.

Inside those tiny EULA boxes was a full page of disclosures for each program, if you copy/paste the text into an editor you can read the EULA rather than squinting at a scroll box. Know what you are agreeing to if leaving the box checked to install.

trillian

Weather Channel:
“1. PURPOSE. The software you are installing (the “Software”) is provided by The Weather Channel Interactive, Inc. (”TWCi”) and provides you with a quick view of the current weather in a city you select, and provides other weather-related information and data on your desktop (the “Services”). This Agreement contains terms and conditions that apply to both the subscription version of the Software (”Desktop Max Software”) and Services (”Desktop Max Services”) and the advertisement-supported version of the Software (”Desktop Software”) and Services (”Desktop Services”).
14. DESKTOP MAX SERVICES. You agree that if you license Desktop Max Services, the following additional terms will apply:
A. You agree to pay TWCi the monthly or annual service charge for your use Desktop Max Services using a valid credit or debit card, plus any applicable taxes, in accordance with the billing terms and prices in effect at the time the fee or charge becomes payable. You authorize TWCi to automatically bill the charge card you provide each month or year (as applicable), or withdraw funds via electronic transfer from your checking account (depending on what type of charge card you are using), until you cancel Desktop Max Services. Payments are billed in advance at the beginning of the applicable month or year. You agree to provide TWCi with a valid credit or debit card and accurate, complete and updated information required by the subscription registration form. Failure to comply may result in the immediate termination of Desktop Max Services.
B. You agree to notify TWCi about any billing problems or discrepancies within 90 days after they first appear on your account statement. If you do not bring them to TWCi’s attention within 90 days, you agree that you waive your right to dispute such problems or discrepancies.”

ask

ASK Toolbar:
“END USER LICENSE AGREEMENT/PRIVACY POLICY/TERMS OF SERVICES

IMPORTANT — PLEASE READ CAREFULLY - SHORT PLAIN ENGLISH SUMMARY OF END USER LICENSE

This is a legal contract between you and IAC Search & Media, Inc. You must agree to this contract and abide by its terms in order to download and use the toolbar. You must be 18 years of age in order to agree to this contract and download this product. IF YOU ARE NOT YET 18, PLEASE ASK YOUR PARENT OR GUARDIAN TO DOWNLOAD THE TOOLBAR FOR YOU.

UPON INSTALLATION OF THE TOOLBAR, THE FOLLOWING FEATURES WILL BE ADDED TO YOUR BROWSER:

SEARCH BOX is a toolbar to your Internet browser. The browser toolbar is customizable and will provide you access to Ask.com search results..

SEARCH ASSISTANT: This provides relevant links and results when your search request or browser address request is misspelled or incorrectly formatted.

In addition, an Easy Installer will be downloaded to install this software. It does not install any other software and is automatically deleted the first time you turn off your computer after installation of the above-described products.

THIS PRODUCT AND ALL THE FEATURES LISTED ABOVE ARE FREE.

NO REGISTRATION OR PERSONAL INFORMATION IS REQUIRED.”

Please read each EULA completely and if installing do so as an informed user. :)

{ 0 comments }

ASK Approaches WinPatrol

by certifiedbug on January 18, 2008

in Programs, Security

The sales pitch to include a toolbar with WinPatrol was compelling. I’m told that the my reputation wouldn’t be affected and I would be providing my customers with a service by including the free toolbar. All the companies currently installing the toolbar are very happy. He even leaked the news that another well known Anti-Spyware vendor who would be moving to the dark side soon.

Labels: IAC, Lavasoft, Toolbar, WinPatrol, Zwinky

I’m going to have to pass and keep WinPatrol simple and pure.

I applaud you Bill, a true blue honest vendor with a great product.

Bits From Bill: Would you like Toolbar with your Software Order?

{ 0 comments }

Another vendor bundles ASK

by certifiedbug on January 1, 2008

in Security

This time STOPzilla which was a 11.73MB download, 25.17MB install.

stopzilla

stopzilla

STOPzilla uses the ASK search engine. On performing a search the results page promoted the ASK toolbar, which I chose not to install. The less toolbars the better.

I uninstalled STOPzilla from Add/Remove, the only event being a questionnaire popping up asking for feedback.

Source: Sunbeltblog

{ 0 comments }

InterActiveCorp/Ask Toolbars, what you need to know

by certifiedbug on October 16, 2006

in Security

Suzi Turner interviewed Ben Edelman who has posted a new article where he presents and critiques the current installation and operation practices of certain toolbars provided by InterActiveCorp/Ask.

Both writeups make for an interesting and informative read; Ben Edelman’s article has screenshots as well as a video made on October 15, 2006 showing a non-consensual installation of the Ask toolbar.

Suzi Turner’s Article

{ 0 comments }