Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Storm Tries to Spread with Halloween Hoax | Main | Hacking: It's Nothing Personal, It's Just Business »

ISPs Pushing Their Own Ads on Customers

Think you don't pay enough for your Internet access? Not to worry, some ISPs have reportedly decided to push their own adds into content as it is served up. This was first reported in Slashdot last June and now DarkNet has updated the story with information about the University of Washington's Web integrity checker, a tool for testing your ISP to see if it's polluting your content.

Here's a summary of how the tool works, from the project's Web site:

Our experiment first loads custom "integrity checking" JavaScript programs into your web browser. We collectively refer to these "integrity checking" scripts as the Experiment Harness. The Experiment Harness requests pages from the following six domains, plus an IP address:

1. washington.edu,
2. uwsecurity.com,
3. uwprivacy.org,
4. uwsystems.net,
5. uwcse.ca,
6. happyblimp.com,
7. 128.208.6.75.

The Experiment Harness requests pages from these different locations because ISPs may treat different types of websites differently, and we'd like to understand these differences. For example, some ISPs might only inject ads into .com sites, as observed by some users [BenAnderson].

The Experiment Harness then determines the integrity of each web page -- i.e., the Experiment Harness determines if your ISP (or some other party in the middle) modified the web page between when our server sends it and when it arrives at your web browser. Our Experiment Harness is not affected by changes caused by browser plugins or extensions. If a page is modified in-flight, the Experiment Harness will show you exactly what changed.

Besides checking your ISP, when you use this you provide data to the researchers at U. of WA.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/505

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net