<title>Malware in Webpages
- GNU Project - Free Software Foundation</title>
<h2>Malware in Webpages</h2>

<p><a href="/proprietary/proprietary.html">Other examples of proprietary

<div class="highlight-para">
    <em>Malware</em> means
<hr class="full-width" />
Nonfree (proprietary) software is very often malware (designed to mistreat or harm the user.
mistreat or harm the user.  (This does not include accidental errors.)
    Malware and nonfree software are two different issues.  The difference
    between <a href="/philosophy/free-sw.html">free software</a> and
    nonfree software is controlled by its developers, which puts them in
which puts them in
    <a href="/philosophy/free-software-even-more-important.html">
      whether the users have control of the program or vice versa</a>. It's not directly a question
    of what the program <em>does</em> when it runs.
    However, in practice nonfree software
is often malware, because the developer's awareness
basic injustice</a>. The developers and manufacturers often exercise
they ought to serve.</p>
    malicious functionalities tempts serve.</p>

<p>This typically takes
  the form of malicious functionalities.</p>
<hr class="full-width" />

<div class="article">
<div class="italic">
<p>This page lists web sites containing proprietary JavaScript programs that spy
on users or mislead them. They make use of what we call
the <a href="/philosophy/javascript-trap.html">JavaScript Trap</a>. Of course,
many sites collect information that the user sends, via forms or otherwise, but
here we're not talking about that.</p>


<div class="important">
<p>If you know of an example that ought to be in this page but isn't
here, please write
to <a href="mailto:webmasters@gnu.org"><webmasters@gnu.org></a>
to inform us. Please include the URL of a trustworthy reference or two
to serve as specific substantiation.</p>

<div class="column-limit" id="malware-webpages"></div>

<ul class="blurbs">
  <li id="M201811270">
    <p>Many web sites use JavaScript code <a
    to snoop on information that users have typed into a
    form but not sent</a>.
    </p> sent</a>, in order to learn their identity. Some are <a
    getting sued</a> for this.</p>

    <p>The chat facilities of some customer services use the same sort of
    malware to <a
    read what the user is typing before it is posted</a>.</p>

  <li id="M201807190">
    <p>British Airways used <a
    JavaScript on its web site to give other companies personal data on
    its customers</a>.</p>

  <li id="M201805170">
    <p>The Storyful program <a
    spies on the reporters that use it</a>.</p>

  <li id="M201805080">
    <p>A cracker used an exploit in outdated software to <a
    inject a “miner” in web pages</a> served to visitors. This
    cryptocurrency.</p>

    <p><small>(Note that the article refers to the infected software
    as “content management system”. A better term would be
    “<a href="/philosophy/words-to-avoid.html#Content">website
    revision system</a>”.)</small></p>

    <p>Since the miner was a nonfree JavaScript program,
    visitors wouldn't have been affected if they had used <a
    href="/software/librejs/index.html">LibreJS</a>. Some
    browser extensions that <a
    specifically block JavaScript miners</a> are also available.</p>

  <li id="M201712300">
    <p>Some JavaScript malware <a
    swipes usernames from browser-based password managers</a>.</p>

  <li id="M201711150">
    <p>Some websites send
    JavaScript code to collect all the user's input, <a
    which can then be used to reproduce the whole session</a>.</p>

    <p>If you use LibreJS, it will block that malicious JavaScript code.</p>

  <li id="M201701060">
    <p>When a page uses Disqus
    for comments, the proprietary Disqus software <a
    a Facebook software package into the browser of every anonymous visitor
    to the page, and makes the page's URL available to Facebook</a>.</p>

  <li id="M201612064">
    <p>Online sales, with tracking and surveillance of customers, <a
    businesses to show different people different prices</a>. Most of
    the tracking is done by recording interactions with servers, but
    proprietary software contributes.</p>

  <li id="M201611160.1">
    <p>A <a
    research paper</a> that investigated the privacy and security of
    283 Android VPN apps concluded that “in spite of the promises
    for privacy, security, and anonymity given by the majority of VPN
    apps—millions of users may be unawarely subject to poor security
    guarantees and abusive practices inflicted by VPN apps.”</p>
    <p>Here are two examples of

    <p>Here are two examples, taken from the research paper, of some 
    proprietary VPN apps from the
      proprietary VPN apps that use JavaScript to track users and infringe their privacy:</p>
    their privacy:</p>

    <dl class="compact">
      <dt>VPN Services HotspotShield</dt>
      <dd>Injects JavaScript code into the HTML pages returned to the
      users. The stated purpose of the JS injection is to display ads. Uses
      roughly five tracking libraries. Also, it redirects the user's
      traffic through valueclick.com (an advertising website).</dd>

      <dt>WiFi Protector VPN</dt>
      <dd>Injects JavaScript code into HTML pages, and also uses roughly
      five tracking libraries. Developers of this app have confirmed that
      the non-premium version of the app does JavaScript injection for
      tracking the user and displaying ads.</dd>

  <li id="M201603080">
    <p>E-books can contain JavaScript code, and <a
    sometimes this code snoops on readers</a>.</p>


  <li id="M201310110">
    <p>Flash and JavaScript are used for id="content", starts in <a
    “fingerprinting” devices</a> to identify users.</p>

  <li id="M201210240">
    <p>Many web sites rat their visitors to advertising
    networks that track users.  Of the include above top 1000 web sites, <a
    (as of 5/17/2012) fed their visitors third-party cookies, allowing
    other sites to track them</a>.</p>

  <li id="M201208210">
    <p>Many web sites report all their visitors
    to Google by using the Google Analytics service, which <a
    tells Google the IP address and the page that was visited</a>.</p>

  <li id="M201200000">
    <p>Many web sites try to collect users' address books (the user's list
    of other people's phone numbers or email addresses).  This violates
    the privacy of those other people.</p>

  <li id="M201110040">
    <p>Pages that contain “Like” buttons <a
    enable Facebook to track visitors to those pages</a>—even users
    that don't have Facebook accounts.</p>

  <li id="M201003010">
    <p>Flash Player's <a
    cookie feature helps web sites track visitors</a>.</p>

        <p>For information on coordinating and submitting contributing translations of
Please see the <a
<p>Copyright © 2017-2020 Free Software Foundation, Inc.</p>

<p>This page is licensed under a <a rel="license"
