False Advertising: How Modern Ad Platforms Can Be Used for Targeted Exploitation

Presented at ToorCon San Diego 19 (2017), Sept. 2, 2017, 4:30 p.m. (50 minutes)

In this presentation I would like to demonstrate how modern ad platforms can be hijacked by a malicious user to deliver an extremely targeted phishing campaign to an unsuspecting victim. This campaign can target anyone from a CEO to a college intern, and can be configured to show on any predetermined device. Everyday, millions of people use social networks to reach out, interact, share, and partake in an ever growing digital consciousness. Behind these networks sit unseen ad platforms serving up relevant advertisements to whoever advertisers would like to target. Modern ad platforms are designed to allow advertisers to grow their revenue and brand presence while being easy enough to use that everyone from a fortune 500 executive, to a general contractor, can now take part in the digital advertising revolution. What most non-advertisers don’t know is that while advertising to a broader audience is excellent for business, ads can be and have been, used as a sharp skewer, precisely targeting a single individual. Modern ad platforms have given advertisers the power to reach anyone they please, anywhere in the world; this power could be harnessed by malicious users to serve as a gateway onto the network of their intended victim.


Presenters:

  • Tyler Cook
    My name is Tyler, I like to break things.

Links:

Similar Presentations: