Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

Renko31

macrumors member
Original poster
Mar 17, 2004
47
5
North Yorkshire, UK
Hi

Just made a troubling discovery using Safari.

Visiting certain pages on digital spy.co.uk is automatically downloading a flash file for an advert - BLUEWATER_VIDEOAD_30s_inbanner.flv.
I didn't click on the advert link, it automatically happens when opening a page with this advert on it.
This despite having Flash turned off for this site in Preferences.

I am sure it is an innocuous file, but isn't this incredibly insecure?
 
Last edited:
Hi

Just made a troubling discovery using Safari.

Visiting certain pages on digital spy.co.uk is automatically downloading a flash file for an advert - BLUEWATER_VIDEOAD_30s_inbanner.flv.
I didn't click on the advert link, it automatically happens when opening a page with this advert on it.
This despite having Flash turned off for this site in Preferences.

I am sure it is an innocuous file, but isn't this incredibly insecure?
Yes. That concerns me too - that's the kind of vector the bad guys use - a so-called drive-by download.
 
I would suspect it is because the advertising provider isn't providing the correct 'mime type' for the object. I.e. it is not telling the browser that it is a flash file, but rather something else. Is there a specific page it is happening on?
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.