On CBS MoneyWatch: How to Haggle on Your Rent
BNET Business Network:
BNET
TechRepublic
ZDNet

August 7th, 2009

Microsoft's Bing invaded by pharmaceutical scammers

Posted by Dancho Danchev @ 12:45 pm

Categories: Uncategorized

Tags: Advertisement, Pharmacy, Microsoft Corp., Scammer, Internet, Dancho Danchev

Rogue online pharmacies have found a way to exploit Bing’s advertising program.

According to a recently released report by KnujOn and LegitScript, 90% of the Bing sponsored pharmacy ads were rogue ones, shipping counterfeit prescription drugs, with the bogus companies participating part of larger affiliate networks like this one analyzed last year.

The report also details a brand-jacking scheme allowing bogus advertisers the option to choose their own “Display URL” and a separate “Destination URL” for displaying their ads.

More findings:

  • 89.7% of Internet pharmacy advertisements on bing.com that we reviewed are operating unlawfully. (Of the other 10.3%, about half are verified as legitimate, and half are “unverified” according to our standards.)
  • The majority of Internet pharmacy ads, and all ten of the sample ads that we dissected, did not require a valid (or any) prescription. We successfully attempted a test buy in two cases, receiving drugs in both cases that appeared to come from India
  • Some of the drugs sold via bing.com ads tested positive as counterfeit
  • Most of the Internet pharmacy advertisements that we analyzed are members of affiliate networks controlled by organized crime in Russia and Eastern Europe
  • In some cases, rogue Internet pharmacies have “hijacked” a legitimate Internet pharmacy’s domain name: the ad will look like it has been listed by a licensed, US-based pharmacy, but actually clicks-through to a rogue Internet pharmacy. This implies serious security holes in Microsoft’s advertising program

Despite that the research clearly demonstrates systematic abuse of a search engine that’s gaining momentum, it’s worth pointing out that these very same scammers are investing money in ads in between their main traffic acquisition tactic in their arsenal - blackhat SEO (search engine optimization) and spam.

On daily basis, hundreds of thousands of insecurely configured web servers become part of these campaigns, next to the systematic abuse of legitimate services such as Yahoo Groups, About.com forums, Scribd, SlideShare, LinkedIn, MyYearBook, and Digg — for starters. Collectively the traffic and sales that come from this abuse result in a positive return on investment for the scammers due to the efficient ways in which they abuse the services.

Say yes to your health, and don’t bargain with it.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 47 Talkback(s)
RE: Microsoft's Bing invaded by pharmaceutical scammers
amazing story


http://rx1-onlinepharmacy.com/... (Read the rest)
Posted by: pillso@... Posted on: 11/25/09 You are currently: a Guest | | Terms of Use
quote  xXSpeedzXx | 08/07/09
Yeah, like Google doesn't suffer from the same problem?  Confused by religion | 08/07/09
but,but,but  Intellihence | 08/07/09
Microsoft is better than Google.  fr0thy2 | 08/07/09
Never said anything about Google...  xXSpeedzXx | 08/07/09
One time while I was playing cards with an old man from Hoboken,he said  Intellihence | 08/07/09
RE: Microsoft's Bing invaded by pharmaceutical scammers  Loverock Davidson | 08/07/09
Exactly!  maskman01 | 08/07/09
"Expectations for Win 7 are mixed at best because of their past."  fr0thy2 | 08/07/09
"Mixed at best"?  honeymonster | 08/08/09
Running scared?  zkiwi | 08/08/09
'Decsion engine' is the term you use when you are not #1 in search.  B.O.F.H. | 08/09/09
Ok, but...  zkiwi | 08/09/09
"returning answers to your questions thus allowing you to make a decision"  fr0thy2 | 08/09/09
@fr0thy2 - Please stop lying.  PlayFair | 08/10/09
install?  levinson | 08/10/09
Decision engine??  cbiggs99@... | 08/10/09
humor= $6 a dose  tmsbrdrs | 08/11/09
@tmsbrdrs about humor and wit  Angel_LB | 08/11/09
that is bull  JamesDoyle | 08/15/09
Fun times...  zkiwi | 08/07/09
Except for your death.  doctordawg | 08/10/09
....  mojorison67@... | 08/10/09
Bing search results tainted  spinit | 08/08/09
Bing is also changing search criteria!!  bjbrock | 08/08/09
Bing answers queries the user didn't make with MS-centric spiel!  whisperycat | 08/10/09
Results  levinson | 08/10/09
The top six were also about stories  xXSpeedzXx | 08/11/09
Try again...  LeeC | 08/12/09
According to PC World... LOL  LeeC | 08/12/09
Done to Google, why wouldn't it happen to MS?  ejhonda | 08/10/09
Re: Frothy & Whisperycat  justanitguy | 08/10/09
THANK YOU!  PlayFair | 08/10/09
The only thing that smells fishy is Bing.  i8thecat | 08/10/09
And Google's different??  M.W.H. | 08/13/09
seriously  JamesDoyle | 08/15/09
Windows update patch for Bing LOL  Randalllind | 08/10/09
RE: Microsoft's Bing invaded by pharmaceutical scammers  Capt_Sparky | 08/10/09
RE: Microsoft's Bing invaded by pharmaceutical scammers  jemd@... | 08/10/09
Bing didn't reboot after windows update.  kraterz | 08/10/09
which flaw?  tmsbrdrs | 08/11/09
RE: Microsoft's Bing invaded by pharmaceutical scammers  john.foggitt@... | 08/11/09
Not surprised, after Live Spaces comment spam  cquirke | 08/11/09
LOL, it's typically Microsoft!  minardi | 08/11/09
RE: Microsoft's Bing invaded by pharmaceutical scammers  sykandtyed | 08/12/09
RE: Microsoft's Bing invaded by pharmaceutical scammers  JamesDoyle | 08/15/09
RE: Microsoft's Bing invaded by pharmaceutical scammers *NEW*  pillso@... | 11/25/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads