On the evening of Saturday 12 September 2009 Troy Davis, a technology executive, opened an article on NYTimes.com and watched his anti-virus software raise a warning. A box on the page, 300 pixels by 250, held a frame drawn from a domain the Times did not own, and a script inside it passed his browser along a chain of other addresses to a page dressed as a system scan. It reported "353 trojans" and, in its own spelling, "431 Probably harmfull items was found!" It offered a 167-kilobyte file, Scanner-b4ba2_2006-63.exe — "too small for any virus scanner", Davis noted — which by his reading asked for administrator privileges. Other readers that weekend met the same pop-up and an offer of fake anti-virus software, the kind that invented infections and charged to remove them.

On the Sunday the Times posted a note: "Some NYTimes.com readers have seen a pop-up box warning them about a virus and directing them to a site that claims to offer antivirus software. We believe this was generated by an unauthorized advertisement and are working to prevent the problem from recurring." It asked readers not to click, but to quit and restart their browsers. On the Monday its spokeswoman, Diane McNulty, explained: "The culprit masqueraded as a national advertiser and provided seemingly legitimate product advertising for a week. Over the weekend, the ad being served up was switched so that an intrusive message, claiming to be a virus warning from the reader's computer, appeared." The national advertiser was Vonage, the internet telephone company, which had advertised on the site before.

Believing the campaign came from Vonage, the Times had let an outside vendor it had never vetted deliver it, so the advertisement lived, and could be changed, on a server the paper did not control. Readers' complaints, which went on through the weekend, sent the Times first to the networks that inserted advertising into its pages automatically, and it suspended them. "Our first instinct was that it was a third-party ad network," said Marc Frons, its chief technology officer. "That is where we looked first and why it took a longer amount of time to shut down." By the paper's own account the campaign had come through its advertising department and turned, possibly, late on the Friday; how many readers it reached, it did not know.

McNulty gave the rule that followed: "In the future, we will not allow any advertiser to use unfamiliar third-party vendors." The same week Microsoft filed five lawsuits in King County Superior Court in Seattle against unnamed defendants trading as Soft Solutions, Direct Ad and three other names, whose advertisements, it said, had carried malicious software or led to scareware; it called them the first of their kind. The Times did not name its buyer, and this archive has found no charge ever brought over the campaign. Nothing on the site had been broken. A familiar name, a week of good behaviour and a frame whose contents lived elsewhere were enough to put a fake virus warning in front of the readers of the New York Times.

Also that month · 7–30 September

An Ampersand in the Header

On 7 September 2009 Laurent Gaffié published code that remotely crashed Windows Vista, Windows Server 2008 and the Windows 7 release candidate: an ampersand in the Process ID High field of an SMB2 negotiate request was enough to bring up the blue screen. Microsoft's advisory the next day was headed "Vulnerabilities in SMB Could Allow Remote Code Execution" and advised switching SMB2 off or blocking ports 139 and 445; Windows XP and the finished Windows 7 were not affected. Within ten days four researchers at Immunity, led by Kostya Kortchinsky, had turned the crash into a working remote exploit for Canvas, the firm's commercial penetration-testing platform. "This is the kind of vulnerability that hits everybody who is sharing files with other users," said Dave Aitel, its chief technology officer, and the SANS Internet Storm Center warned that a stable exploit could very easily be used in a worm. A one-click Fix it followed on 17 September, and by the month's end Stephen Fewer of Harmony Security had put a free exploit into Metasploit. The patch, MS09-050, came on 13 October, with Microsoft saying it had no reports of attacks.

Also that month · 23 September

Half a Password

Twelve days after Albert Gonzalez pleaded guilty in Boston over the TJX thefts, a smaller case showed what stolen log-ins were for. On 23 September 2009 PayChoice, a payroll processor in Moorestown, New Jersey, whose online system was licensed to at least 240 other payroll firms serving 125,000 organisations, found its customers receiving email addressed to them by name. Each message quoted the recipient's user name for onlineemployer.com and part of the password, and said a browser plug-in was needed to keep using the site; the plug-in was malware built to harvest log-ins. PayChoice shut the site and forced password changes, and told customers that email addresses, log-in IDs and "some valid partial passwords" had gone into the messages, as Brian Krebs, then writing the Washington Post's Security Fix blog, reported. Steve Friedl, whose clients had received the emails and who also consulted for a PayChoice competitor, found that more than a day into the attack only five of 41 anti-virus scanners detected the malware. On 14 October clients found fictitious employees on their payrolls, added, PayChoice said, with valid user credentials in an attempt to send pay to fraudulent bank accounts, and the site went down for the second time in a month.

India desk · September 2009

The Caller Without a Number

On 15 September 2009 TeleGeography reported that the Intelligence Bureau had asked the Ministry of Communications and Information Technology to "block all internet telephony services in and out of the country" until the Department of Telecommunications could track such calls. The bureau's reasoning was about identity: "In the absence of Caller Line Identification (CLI) parameters of calls landing from abroad, it is next to impossible to identify the country of location of the caller." Incoming calls were the difficulty; outgoing ones could be traced. The ten men who attacked Mumbai in November 2008 had been directed from Pakistan by mobile phone and VoIP. Internet telephony was lawful in India but penned in — an internet provider could not connect a call to an ordinary telephone number — and MediaNama doubted any block could keep Fring, Nimbuzz or Skype off phones reaching the internet over 3G or Wi-Fi.

Thirteen days later the same problem arrived on a landline. On 28 September the Times of India reported that a senior officer at Air Headquarters in New Delhi had given "sensitive information" to a caller claiming to be a joint secretary in the Defence Ministry — by the paper's account an official of a foreign embassy, Pakistan's being the prime suspect, though that was not confirmed. The ministry's chief security officer barred officers at the ministry and the three service headquarters from discussing "top-secret, secret or confidential" matters by telephone: "All communications are vulnerable to interception." Skype was not blocked. The demand narrowed to encrypted services and became the BlackBerry confrontation of August 2010, while calls from people posing as officials became a fraud of their own, set out on our India desk.

AI Tech desk · September 2009

Netflix's million, won by twenty minutes

On 21 September 2009, in New York, Netflix awarded its $1 million prize to BellKor's Pragmatic Chaos, seven researchers from four countries whose three merged teams had blended hundreds of models to predict subscribers' ratings 10.06 per cent more accurately than Cinematch, the company's own system. Under the rules it was a tie: The Ensemble, another coalition of former rivals, had matched the winning score on the hidden test set but submitted twenty minutes later, on 26 July, the final day, and the earlier entry won. A sequel was abandoned in March 2010, and Netflix, already using ideas from the contest's annual progress prizes, never deployed the winning ensemble in full; its engineers wrote in 2012 that the extra accuracy "did not seem to justify the engineering effort". On 16 September Google bought reCAPTCHA, a Carnegie Mellon spin-off whose puzzles paired a known word with one that scanning software could not read, to improve its scanning of books and newspapers; in 2013 Google's own researchers reported a neural network reading reCAPTCHA's hardest distorted text with 99.8 per cent accuracy.

Digital Guard desk · September 2009

Microsoft gives its anti-virus away

On 29 September 2009 Microsoft released Security Essentials, a free anti-virus and anti-spyware program for genuine copies of Windows XP, Vista and 7, offered in nineteen countries and eight languages with no registration, trial or renewal. It replaced Windows Live OneCare, a paid subscription suite with a firewall and backup that had been withdrawn from sale at the end of June, and kept only the protection against malicious software: scanning in real time, behaviour monitoring and a Dynamic Signature Service meant to deliver new definitions without waiting for the next download. The paid vendors were unimpressed. Jens Meggers, Symantec's vice-president of engineering for Norton, called it "a poor product" with very average detection rates and cited a test, paid for by Symantec, that put Norton well ahead; Carol Carpenter of Trend Micro thought it better than nothing but doubted it would worry the main vendors. Microsoft replied that anti-malware software was one part of a defence in depth. Its engine was built into Windows 8, on sale from October 2012.

⏳ Time capsule — September 2009

  • On 9 September, at nine minutes and nine seconds past nine in the evening, Sheikh Mohammed bin Rashid Al Maktoum opened the Red Line of the Dubai Metro with ten of its twenty-nine stations; the public rode it from six the next morning, on the first rapid transit network in the Arabian Peninsula.
  • On 15 September Dan Brown's The Lost Symbol was published by Doubleday and Transworld from a first printing of 6.5 million copies; the publisher said a million copies in hardback and e-book were sold in the United States, Britain and Canada on the first day.
  • On 24 September Science reported that the Moon Mineralogy Mapper, a NASA instrument led by Carle Pieters of Brown University and carried on India's Chandrayaan-1, had detected water on the Moon — nearly a month after the spacecraft itself had fallen silent.
  • On 25 September, at the David L. Lawrence Convention Center in Pittsburgh, the leaders of the Group of Twenty closed their summit with a declaration: "We designated the G20 to be the premier forum for our international economic cooperation."
Where it stands today — 2026

What the advertising box let in

Malicious advertising was not new in September 2009 — The Register counted the Daily Mail and ITV among its earlier victims — but the Times made it impossible to treat as a hazard of the web's disreputable corners. The pattern of that weekend held: a buyer trusted on a familiar name, an advertisement changed after approval, a delivery path the publisher did not control. The ring charged in Minneapolis in June 2011 had bought space on the Star Tribune's website by posing as an agency for a hotel chain; by January 2013 exploit kits were arriving through advertising networks on weather and news sites; and in March 2016 malicious advertisements reached the Times's readers again, through the networks of Google, AppNexus, AOL and Rubicon, with ransomware among the payloads.

In December 2022 the FBI advised people to use an ad-blocking extension when searching the web, because criminals were buying search advertisements that impersonated real businesses. The SMB2 hole was closed in October, but the file-sharing service behind it did not go quiet: a flaw in its older version, SMBv1, carried WannaCry in May 2017. Gangs already known for fake anti-virus were, by Symantec's conservative estimate in November 2012, making more than $5 million a year from ransomware posing as the police. And the Intelligence Bureau's question — who is at the other end? — has a partial answer in CERT-In's directions of April 2022, which make VPN and cloud providers keep subscriber records for five years. Each fix came to the same thing: stop taking an identity on its word.