Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - AdBlocking and Adblocker Blocking
Articles

AdBlocking and Adblocker Blocking

ISBuzz TeamBy ISBuzz TeamOctober 21, 2015Updated:July 4, 20248 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
AdBlocking and Adblocker Blocking
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Most people are familiar with the notion of an adblocker. It’s pretty much what it says on the label: a program that blocks ads from showing. They may not, however, be entirely familiar with how adblockers work or what the best kind of adblocker for their use might be.

Likewise, people are starting to become aware of sites trying to block users from browsing with adblockers enabled – but the ways in which that works are also somewhat obscure.

Adblocking at the browser-level is the variety which most people are familiar with: the user downloads a plugin for their browser, which then blocks the ads.

The best sort of adblockers entirely block the request to the adserver – they rewrite the page before it’s rendered to replace the request that would otherwise be made with a placeholder. This is the best approach because no spurious traffic is generated – it keeps the network traffic to a minimum, and doesn’t tip off any ad-company analytics that the page was loaded at all. In a way, it’s the most ‘honest’ way of adblocking.

Other methods interrupt the ad loading at different points in the process – either they allow the request to complete but do not accept the returned payload, or they put some kind of blocking panel over the ad so the user does not see it.

These types of adblocking are not as effective as the first. Your browser may still see malvertisements, for example, so you could still be subject to attack – and they end up not only increasing the amount of network traffic to the user but also reveal things about the user’s movements to ad company trackers.

Image 1There are also network-based adblockers that are installed by a network owner so that protections apply to every system and every browser on the network regardless of whether or not an adblocking plugin is installed or even available.

These are especially useful for mobile browsers, which often have very poor support for adblocking plugins, and which are often quite vulnerable to malvertising. With the addition of a VPN, which provides a ‘tunnel’ for all the network traffic to a trusted network, a network-based adblocker can allow a mobile device to benefit from adblocking in the same way that any other computer can.

Some of these adblocking methods are used in conjunction with content filtering proxy servers. The same kind of servers that are put in place to prevent employees from playing games or looking at racy pictures can be tuned to block advertisements as well. Others adjust firewalls to disallow connections to ad network addresses and filter any such requests at the network gateway. A third kind is the “sinkholed” DNS, which requires a little bit of explanation.

Image 2DNS is the service that acts like a phone book – it enables your computer to take a human-friendly name, like ‘google.com‘, and look up the network address that it corresponds to – 216.58.192.14 in my case. Normally, it does this by making requests to figure out where the ‘authoritative’ nameserver for the domain is, or whether the answer to that particular query is cached nearby, and then returning the result so your computer can make the connection.

If someone has configured a ‘sinkholed’ DNS for you, however, the server is configured to respond to certain domains with ‘dummy’ entries. This means that the request cannot successfully complete – so any domain with such a ‘dummy’ entry will be inaccessible to your browser. This is a sort of defensive application of “DNS Hijacking” – a common tactic used by malware to enable man-in-the-middle attacks.

Sinkholed DNS is extremely useful when fighting certain kinds of malware, and it’s also extremely useful in adblocking. Regardless of whether an adblocking plugin is installed, any attempt to load an ad’s URL will be stymied by the inability of the browser to look up the adserver’s domain name. The request won’t be successful, so the ad won’t load.

Ad networks, however, are fighting back.

Most of the measures that they use currently are based around javascript. Javascript’s near-universal availability in modern browsers and the large array of libraries that are available for developers give the networks many tools to detect what happens in users’ browsers.

Most of the current generation of adblock detectors use methods that try to figure out if the ad was fetched or displayed on screen; if it wasn’t, then they’ll attempt to take some measure to ask the user to turn off their adblocker.

These range from displaying a request where the ad would be (the easiest and most inoffensive solution; the ad would otherwise cover up the message) to popping up a modal window – that is, an overlay to the page that can’t be dismissed by normal means – to block the user from viewing the content. However, if the user turns off javascript support, the page – while likely less visually appealing and without some functionality – generally will still load just fine.

All of the anti-adblock solutions that I’m aware of on the market at this time depend on the end-user’s browser supporting them. From an information security standpoint, that’s a laughable stance. Nearly everyone in infosec knows that trusting the end user’s browser to do the right thing is a sure way to end up with headaches and breaches; similarly, trusting the browser to correctly report on advertising rendering is an ultimately futile endeavour.

Without having total control over the user’s browser (and thus making it into a trusted endpoint) advertisers will never be able to defeat every ad-blocking measure: this is an arms race that they won’t be able to win.

“The only winning move is not to play.”

On one side, ad networks are fighting for their survival, since adblocking, in its current form, post an existential threat to their business model.

On the other side, adblocking has started to become a lucrative business, and the companies that distribute them have realized that, besides charging users a fee for installing their adblocking software, they can charge ad networks a fee to be ‘whitelisted’ so that their ‘reliable’ ads will still display.

(This is a situation that one ad company exec, Mike Zaneis, compared to “blackmail” in an interview with C|NET recently.)

Will a new wave of adblockers that ‘play nice’ with ad publishers start to dominate?

Perhaps. The mobile economy has a high demand for adblocking plugins, and relatively few mobile users want to go through the fuss and bother of connecting to a VPN for all their traffic. These apps also have lots of budget available for, ironically enough, advertising. They’ve been written about in several publications recently, and the companies behind them are clearly trying to make them become the ‘acceptable’ alternative – a middle ground between those who are extremely anti-advertisement and the ad networks who demand delivery.

These middle-ground adblockers can still do some good. If they provide the kind of auditing services needed to police the ad networks into ensuring that only non-malicious ads get through to the users, that would be a distinct improvement over the current situation. Even users without the software would benefit overall, as the overall market would drive out those networks that aren’t willing to handle this policing.

On the other hand, there are still more than enough people who are dedicated to eliminating as many advertisements as possible and who have the technical skill and ability to make it happen. If these “ethical” adblocking programs do not suffice, the much more severe measures are still very much available for those who want to use them.

[su_box title=”Eric Rand, Security Consultant at Brown Hat Security and was guest blogging for AlienVault” style=”noise” box_color=”#0e0d0d”]AlienVaultAlienVault’s mission is to enable organizations with limited resources to accelerate and simplify their ability to detect and respond to the growing landscape of cyber threats. Our Unified Security Management (USM) platform provides all of the essential security controls required for complete security visibility, and is designed to enable any IT or security practitioner to benefit from results on day one. Powered by threat intelligence from AlienVault Labs and the AlienVault Open Threat Exchange—the world’s largest crowd-sourced threat intelligence network — AlienVault USM delivers a unified, simple and affordable solution for threat detection, incident response and compliance management. AlienVault is a privately held company headquartered in Silicon Valley and backed by Trident Capital, Kleiner Perkins Caufield& Byers, GGV Capital, Intel Capital, Sigma West, Adara Venture Partners, Top Tier Capital and Correlation Ventures.

AlienVault, Open Threat Exchange and Unified Security Management are trademarks of AlienVault. All other company and product names mentioned are used only for identification purposes and may be trademarks or registered trademarks of their respective companies.[/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}