2008-03-13

Wowhead, Thottbot, and other sites are having trouble with banner trojans

One more reason I recommend Firefox and No-Script. Everyone should check this out just to see how many sites runs scripts on your machine. I have seen one simple blog attempt to run scripts from 10 different sites on my machine. There is usually nothing wrong with this. But it certainly makes security much more difficult.

WoW General News - Mar 12, 2008 8:50 PM PST | Posted by Eldorian

As reported by World of Raids and then later WoW Insider, it seems that Wowhead, Thottbot, and Allakhazam have had some recent troubles with a banner trojan.

From WoWInsider.com:

You don't even need to click on the banner, apparently, simply mousing over it will be enough. Wowhead says that all they know for sure is that it originates from "ad.yieldmanager.com", and will produce a redirect to "xpantivirus.com." They're working at isolating it.

Some of the security methods you could use to prevent this kind of attack in the future is to download the Firefox web broswer and get the No Script extension. If you keep the javascripts causing this blocked you don't have to worry about it.

The problem seems to be stemming from a third party advertiser that their network seems to have little control over the content of and has been tough in tracking down. I'd just like to take this moment to let everyone know that the Stratics network does not use third party ad networks whatsoever for this reason alone.