AdRater 1.0 Firefox extension released

October 22nd, 2009

The AdRater Firefox Extension is now available. AdRater will rate the advertiser behind each Google ad that appears on each page you view.

This extension replaces our old Greasemonkey plug-in.

AdRater 0.8 released

December 18th, 2008

We’ve updated our AdRater plug-in for Firefox. DoubleClick and Google merged earlier this year, and in December, DoubleClick ads began to be served via Google’s AdWords system. AdRater has been updated to recognize the new format of DoubleClick ads.

Google AdSense advertiser quality report

March 23rd, 2008

Our AdRater system accumulates information on web advertisers. We are using this to evaluate the quality of advertisers accepted by different advertising services.

AdSense advertiser quality report

Sites Percent Rating
695 13.9% Site ownership and business identity verified. No significant issues found.
1975 39.5% Site ownership identified but not verified.
543 10.9% No information available.
1790 35.8% Site ownership unknown or questionable, or significant negative information about the business was found.

A rather high fraction of Google AdSense advertisers are rated as “site ownership unknown or questionable, or significant negative information about the business was found.” These are the ones for which we could not find the business behind the web site. We suggest dealing with such sites with caution. Users with AdRater installed will see the Red do-not enter icon displayed atop ads for such sites.

Who’s behind that ad? Announcing AdRater

March 3rd, 2008

Building facadeToday, SiteTruth introduces AdRater, an entirely new class of tool for consumers. AdRater looks at the ads on each page you visit and rates the advertiser. SiteTruth rating icons appear next to most text ads. Click on any rating icon to get the dirt on who’s behind the ad. Know who you’re dealing with before you click on the ad.

AdRater is free. No strings attached.

This is an alpha test; any problems, please report them here, on this blog.

Google fixes phishing bug

January 18th, 2008

Google recently fixed their “open redirector” in Google Maps, used by “phishing” sites to make attack URLs appear to be Google URLs.

PhishTank then marked the exploits formerly using it as “off line”, and SiteTruth automatically upgraded Google’s rating from to Do not enter to .

The number of major sites with security vulnerabilities exploited by phishing attacks has dropped from 171 problem domains in early December 2007 to only 54 domains today. We’ve been talking to PhishTank, the Anti-Phishing Working Group, the press, and some of the vulnerable sites to focus attention on this problem. It’s on its way to being solved.

“Cybercrooks lurk in shadows of big-name websites”

December 12th, 2007

The Register has published an article about SiteTruth with the dramatic headline, “Cybercrooks lurk in shadows of big-name websites”. It’s about our list of innocent but vulnerable sites exploited by phishing scams.

SiteTruth outage – APlus Phoenix

November 30th, 2007

SiteTruth is partially available due to network problems at an APlus.net colocation facility in Phoenix, AZ. Servers are being moved and we expect to be operational by Monday.

Update, December 4, 2007: The APlus.net outage continues.

Update, December 5, 2007: SiteTruth is back up for now, but the APlus problems have not been fully resolved.

Active phishing scams exploiting major domains

November 24th, 2007

After we discovered that a few major domains were being exploited by phishing scams, we added a new feature to SiteTruth – a continuously updated list of problem domains:

List of major domains being exploited by phishing scams

Each domain listed here is a well known domain in the Open Directory providing, perhaps unwittingly, a service for a phishing scam reported to PhishTank. The service provided may be hosting, URL redirection, or Internet connectivity. The owners of the domains listed are generally innocent of direct involvement with the scam. Domains listed typically have a security vulnerability which is being exploited.

There are only 164 such domains today. It’s not a problem that can’t be fixed, and it’s not a problem common to most web sites. A few major sites just need to clean up their act.

Domains on this list are down-rated by SiteTruth.

Google vs. PhishTank, or why we downrated Google

November 18th, 2007

SiteTruth is currently rating Google as Red do-not enter “Site ownership unknown or questionable. — Negative Info”

“google.com” has a negative report in PhishTank this week. A hostile site is exploiting a security hole in Google Maps, an “open redirector”, to give themselves a phony “google.com” web address. This assists the hostile site in evading spam filters and web filters.

Once Google plugs this security hole, PhishTank should notice within a day, and SiteTruth will pick up that information and rerate automatically.

We’ve seen this with a few other major sites. “rds.yahoo.com” is an open redirector, but, confined to a separate domain used only for redirection, it doesn’t open a hole through spam filters and so we don’t downgrade the whole “yahoo.com” domain. AOL uses “r.aol.com” in a similar way, but they also have an exploitable hole in AOLsearch that’s been reported to PhishTank.

Click on any SiteTruth rating icon for a detailed report about how the rating was computed.  If “Negative Info” is reported, click on “Show Details” for a link to the data source which reported trouble.

SiteTruth now listed in Yahoo Application Gallery

November 9th, 2007

SiteTruth is an “editor’s pick” today in Yahoo’s Applications Gallery.