Malvertising malware testing - few questions

We recently had a problem where an advertiser who purchased ads through a third-party partner distributed malware through the ads they purchased.

As a result, Google Black quickly selected our web property for a short period of time.

This issue has been resolved.

After that, we decided that we ourselves would advertise our advertisers.

After searching the Internet for services that provide this service, we found several ... Armorize (www.armorize.com), among others, provides this type of service. But after talking with their telephone sales, we found that they charge aprox 10K-15K USD / year for this service. Out of our price range.

We don’t have such a pie.

We have a smart head on our (erroneous, my) shoulders.

So here is what I developed.

A) Selenium running firefox.
B) Firefox proxying all requests via a locally hosted squid proxy.

Result?

Pipe in advertisers URL → Selenium Firefox → Squid Access Log → Good clean list of all URLs hit by the advertisement (s).

The next step was to test them against any list of malware. We are now testing their repeated API for creating a browser ( https://developers.google.com/safe-browsing/ ).

The result is exactly what we wanted. A way to test through a "real browser" of each URL provided by our advertisers.

So, the questions are as follows:

a) Does their API (googles) use, as appropriate for Google? We will keep this 100% in the house and will not resell this service. Its 100% for us.

b) API Google URL- ?

c) - - API-, URL-? / :)

!

+5
1

. API Google API , , .

. URL, - (, liderlab.ru/absa/vs. liderlab.ru/absa/page/1), - phising , ).

. PhishTank , , , Google ( ). BrightCloud - . URL- - , , .

+2

All Articles