Showing posts with label online security. Show all posts
Showing posts with label online security. Show all posts

Friday, July 4, 2008

Google's Free Web Application Security Scanner

Google has made public a beta version of one of its internal tools used for testing the security of Web-based applications.


Google Gives Away Free Web Application Security Scanner

Google has released for free one of its internal tools used for testing the security of Web-based applications.

Ratproxy, released under an Apache 2.0 software license, looks for a variety of coding problems in Web applications, such as errors that could allow a cross-site scripting attack or cause caching problems.

"We decided to make this tool freely available as open source because we feel it will be a valuable contribution to the information security community, helping advance the community's understanding of security challenges associated with contemporary web technologies," wrote Google's Michal Zalewski on a company security blog.

Ratproxy -- released as version 1.51 beta -- is quick and less intrusive than other scanners in that it is passive and does not generate a high volume of attack-simulating traffic when running, Zalewski wrote. Active scanners can cause problems with application performance.

The tool sniffs content and can pick out snippets of JavaScript from style sheets. It also supports SSL (Secure Socket Layer) scanning, among other features.

Since it runs in a passive mode, Ratproxy highlights areas of concern that "are not necessarily indicative of actual security flaws. The information gathered during a testing session should be then interpreted by a security professional with a good understanding of the common problems and security models employed in web applications," Zalewski wrote.

Google has posted an overview of Ratproxy as well as a download link to the source code. Code licensed under the Apache 2.0 license may be incorporated in derivative works, including commercial ones, but the origin of the code must be acknowledged.

Friday, June 6, 2008

Bluetooth, IE to Get Critical Microsoft Patches

Microsoft plans to issue seven sets of security patches next week for Windows.


Bluetooth, IE to Get Critical Microsoft Patches

Microsoft plans to issue seven sets of security patches next week, including critical fixes for DirectX, Internet Explorer and Bluetooth wireless software for Windows.

The updates are due Tuesday, the day Microsoft had previously scheduled to release its security patches. Fixes are also slated for Active Directory, the Windows Internet Name Service (WINS) and the Pragmatic General Multicast (PGM) protocol, used by Windows to stream media to many recipients. These updates are all rated "important."

A seventh update, rated "moderate," is listed as a "Kill Bit" update for Windows. This type of patch will disable code that is known to have a security bug.

"The Kill Bit will more than likely be for a third-party application," said Andrew Storms, director of security operations with security vendor nCircle.

Lately, Microsoft's security group has had to pay more attention to software that runs on top of Windows, as attackers have increasingly looked to products like QuickTime, Adobe's Flash and other media players when devising their attacks.

Last Friday, Microsoft warned that a widely publicized flaw in Apple's Safari browser could be combined with another Microsoft bug to let attackers run unauthorized software on a victim's PC.

It's not clear whether Microsoft plans to patch that bug. The IE update could include a fix, although it's unlikely that Microsoft has had enough time to run this software through its testing process, Storms said.

It is unusual for Microsoft to patch Bluetooth, a protocol used to connect devices like headsets to Windows, but added that "the more interesting question is will this patch and/or the bug extend into Windows mobile where it will more than likely have a greater impact?"

Microsoft announced the planned patches in a note posted to its Web site on Thursday.

World's Most Dangerous Domain

Hong Kong's ".hk" is now the world's most dangerous domain for surfing according to a report released by McAfee


McAfee Names '.hk' World's Most Dangerous Domain

Hong Kong's ".hk" is now the world's most dangerous domain for surfing and searching, according to a report released Wednesday by security company McAfee, but the survey's methodology may mean it is not as risky as its seems.

The Hong Kong Special Administrative Region (SAR) moved from number 28 in 2007 to the top of the company's "Mapping the Mal Web" survey, edging out its northern neighbor China's ".cn," which placed second. Finland's ".fi" was the safest, followed by Japan's ".jp."

Just over 19 percent of ".hk" contain malware, viruses, have a high rate of spam or feature aggressive pop-up ads, McAfee said, as determined by a survey of 74 top-level domains using its SiteAdvisor software. Over 11 percent of ".cn" sites for China were similarly found to be dangerous. Comparatively, only 0.05 percent ".fi" sites were found to be hazardous.

However, one Hong Kong-based security analyst said the survey did not demonstrate any real risk as emanating from the SAR. "McAfee are only looking at the top-level domain bit, they are not looking at the location of the server," said Richard Stagg, director and managing consultant at Handshake Networking, a vendor-independent security consultancy. "They're not paying attention to where sites are actually hosted."

The report is also not specific on the degree of "badness" of the sites using the ".hk" domain, Stagg said, as McAfee puts risks such as malware and annoyances like pop-up ads together.

Malware purveyors and spammers choose their top-level domain registrations based in part on where it is difficult to get a domain name shut down, Stagg said. There are "huge, huge numbers of organized crime Web sites and porn Web sites are registered with .cn domains, but most of them are not hosted in China," he said.

Purveyors of malware and spam choose top-level domains in part based on how difficult it is to shut those domains down. For example, the U.S. Federal Bureau of Investigation can ask Network Solutions to close a .com domain, hosted in the U.S., within days, Stagg said, whereas it would have no jurisdiction with foreign domain registrars.

Monday, June 2, 2008

Safari Flaw Worse Than First Thought

Microsoft is warning that a previously disclosed flaw in Apple's Safari browser could have dire consequences for Windows users.


Safari Flaw Worse Than First Thought, Microsoft Warns

The Safari bug, originally disclosed on May 15 by security researcher Nitesh Dhanjani, allows attackers to litter a victim's desktop with executable files, an attack known as "carpet bombing."

It turns out that if this flaw is exploited in combination with a second unpatched bug in Internet Explorer, attackers can run unauthorized software on a victim's computer, according to Aviv Raff, a security researcher. Raff says he originally reported the IE flaw to Microsoft more than a year ago, and then told them about how it could be combined with the carpet bombing bug just over a week ago.

IDG News Service tested Raff's demonstration attack code, which runs Windows Calculator on a victim's system. For the attack to work, a victim must first visit a maliciously crafted Web page with the Safari browser, which in turn will trigger the carpet bombing attack and exploit the IE flaw.

Both the Safari and IE bugs "are moderate vulnerabilities that, combined, produce a critical flaw, which allows remote code execution," Raff said in an instant message interview.

Microsoft is taking the issue seriously. It released a security advisory on the problem late Friday, a sign that it may be working on a patch for the IE flaw. The advisory says that the vulnerability has to do with the way Windows handles desktop executables and recommends that Windows users "restrict use of Safari as a web browser until an appropriate update is available from Microsoft and/or Apple."

The attack reportedly affects all versions of Windows XP and Vista, Microsoft said.

Apple may not be rushing out to patch this bug, however. Dhanjani says that Apple has told him that it is not treating the Safari bug as a security issue, a response that has generated criticism from the security community. Last week, for example, the consumer advocacy group Stopbadaware.org urged Apple to reconsider this stance.

According to Raff, unless Apple patches the bug, more attacks like the one he found in IE are likely to pop up. "This is not the only issue that can be combined with the Safari vulnerability," he said. "If Microsoft fixes this, Safari users will still be vulnerable."

Monday, May 5, 2008

What is Backscattering? Part 1

Because e-mail filters now just delete messages that come from nonexistent domains, the spammers like to make their messages look like they come from real e-mail addresses. That means, if your e-mail address has been published on the Web somewhere, you're a prime candidate for backscattering.



100 E-mail Bouncebacks? You've Been Backscattered

The bounceback e-mail messages come in at a trickle, maybe one or two every hour. The subject lines are disquieting: "Cyails, Vygara nad Levytar," "UNSOLICITED BULK EMAIL, apparently from you."

You eye your computer screen; you're nervous. What's going on ? Have you been hacked? Are you some kind of zombie botnet spammer?

Nope, you're just getting a little backscatter -- bounceback messages from legitimate e-mail servers that have been fooled by the spammers.

Spammers like to put fake information in their e-mail messages in order to sneak them past e-mail filters. Because e-mail filters now just delete messages that come from nonexistent domains, the spammers like to make their messages look like they come from real e-mail addresses. That means, if your e-mail address has been published on the Web somewhere, you're a prime candidate for backscattering.

The spammer finds your address, or sometimes even guesses it, and then puts it in the "from" line of his messages, sending them out to hundreds of thousands of recipients. When the spam gets sent to an address that is no longer active, it can sometimes be bounced back ... to you.

Although Sophos estimates that backscatter makes up just two percent or three percent of all spam, antispam vendors say these messages are on the rise lately.

Users often think that the backscatter may be a sign that their computer has been hacked and is sending out spam messages, said Brad Bartman, a global support manager with Text 100, a public relations consultancy. "They look at it and they're like, 'Whoa, is my PC infected with a virus?'" he said.

Backscatter rarely hits more than one or two employees at the same time, so it isn't particularly disruptive. But it does worry users, he said. "It's mostly a psychological thing."

With their e-mail addresses widely circulated on press releases, Text 100's PR specialists are the ideal candidates for backscatter.

Because backscatter comes from legitimate mail servers, it can cause special problems. In fact, some security researchers believe that the spammers have been intentionally sending messages that will be bounced back as a way to sneak around spam filters. That's because some mail servers bounce back the original message as part of their notice.

Continued

What is Backscattering? Part 2

Because e-mail filters now just delete messages that come from nonexistent domains, the spammers like to make their messages look like they come from real e-mail addresses. That means, if your e-mail address has been published on the Web somewhere, you're a prime candidate for backscattering.



100 E-mail Bouncebacks? You've Been Backscattered

Continued

Dan Wallach, like Text 100's Bartman, was hit with a flood of backscatter messages earlier this week. Wallach, an associate professor with Rice University's Department of Computer Science, said that many of the messages he received contained links to suspicious executable files hosted on different Web sites.

"I'll bet that some spammer is rationally thinking 'error messages! Maybe I can get my message through via error messages!'" Wallach said in an e-mail interview. "They don't need many responses before this sort of tactic could be considered to be a success."

At its worst the phenomenon can even wipe Internet servers off the map.

Last month, Stephen Gielda, president of Packetderm, upset a fraudster who was trying to use his anonymous Internet service. Soon his servers were inundated with a tidal wave of backscatter messages. At one point, he was being hit by 10,000 bounceback messages per second, enough to throttle the server's Internet connection.

Gielda had to take his site off-line for five days as he waited for the problem to abate. "I'm used to backscatter, but I'd never seen it at this level before," he said.

While backscatter is extremely hard to filter out, it is a problem that can be fixed.

Backscatter comes in three varieties: messages from mail servers, saying that there is no such user available; "out of office" automated reply messages; and so-called challenge-response messages, which tell the sender that his message will be delivered only once he responds to the bounceback and confirms that the e-mail is coming from a legitimate address.

Security experts say that people should simply stop using these last two types of bounceback messages.

As for "no such user" bouncebacks, that can be fixed too. There are a few e-mail standards that could help with the problem: Variable Envelope Return Path(VERP) and Bounce Address Tag Validation (BATV), for example.

But the problem would largely disappear if server administrators configured their mail servers to immediately reject mail that is sent to nonexistent users, rather than accepting it and then bouncing it back to the faked addresses. Some ISPs (Internet service providers), AOL for example, have done this and have largely eliminated their role in the problem.

If there is spam in the backscatter message, antispam software should filter it out, but if a message has an ambiguous subject line, like "Hey" and the spam message stripped out, the backscatter will look like a legitimate bounceback and is probably going to get through, said Dmitry Samosseiko, manager of Sophos Labs Canada.

"This is a serious problem that is hard to deal with, to be honest," he said. "We can blame spammers for causing the issue in the first place, but it exists because of the mail servers that are not configured to deal with spam."

Saturday, April 5, 2008

Symantec Has Bugs in Software

Symantec confirms flaws in its most popular consumer security software.

Symantec Confirms ActiveX Bugs in its Own Consumer Software

Symantec has confirmed flaws in its most popular consumer security software that could give attackers the means to hijack the Windows PCs that the programs are supposed to protect.

The vulnerabilities are in an ActiveX control that ships with several products, including Norton AntiVirus, Norton Internet Security, Norton SystemWorks and Norton 360.

Ironically, Symantec analysts have both cited the popularity of ActiveX bugs and urged caution when using the controls in comments about other companies' product flaws.

According to alerts released Wednesday by VeriSign Inc.'s iDefense, the ActiveX control "SymAData.dll" sports two vulnerabilities that could be used "to execute arbitrary code with the privileges of the currently logged in user" by attackers able to entice victims to malicious Web sites.

Symantec confirmed the vulnerabilities Wednesday in its own advisory, and said the buggy control has shipped with Windows versions of Norton AntiVirus 2006-2008, Norton Internet Security 2006-2008, Norton SystemWorks 2006-2008 and Norton 360 version 1.0.

While it acknowledged the bugs, Symantec also downplayed the threat, saying that attacks would only succeed from specially crafted sites. "To successfully exploit either vulnerability, an attacker would need to be able to masquerade as the trusted Symantec Web site, such as through a cross-site scripting attack or DNS poisoning," read the company's advisory .

However, cross-site scripting attacks have become common, and although DNS (domain name system) "poisoning" -- fooling a DNS server into thinking the bogus routing directions it's received are authentic -- is less common, it's not unheard of.

Symantec said it was unaware of any attempts to exploit the vulnerabilities.

The flawed ActiveX control is used by Symantec's AutoFix tool, which is included with some of the company's software and may also be downloaded to a PC during a live chat with a Symantec technical support representative. AutoFix diagnoses PC problems and offers up solutions.

Previously, Symantec researchers have called on the company's statistics to point out widespread problems with ActiveX. In February, for example, Oliver Friedrichs, director of the company's security response team, reported ActiveX composed 89% of all the browser plug-in vulnerabilities his team had counted in the first half of 2007.

That same month, Symantec joined with the U.S. Computer Emergency Readiness Team (US-CERT) and other security vendors to urge caution when using ActiveX controls after a wave of bugs were revealed in several other software makers' products, including those from Yahoo Inc., Facebook and MySpace.

Symantec has updated the affected consumer security software with new detection definitions designed to block any exploit of the ActiveX flaws, but will not automatically patch everyone's copy of the flawed control.

"An updated (non-vulnerable) version of the AutoFix tool will be automatically installed if customers participate in an online Chat session with Symantec Technical Support," Symantec said. Alternately, users can manually download and install a patched AutoFix from its Web site.

Friday, January 4, 2008

Ransomware Extorts Payment with Phone Call

New "ransomware" that locks up your PC and demands $35 to return control to you is on the prowl, a security researcher said this week.


'Ransomware' Extorts Payment With Phone Call

New "ransomware" that locks up a person's PC and demands US$35 to return control to its user is on the prowl, a security researcher said this week.

The extortionists tell victims of the Delf.ctk Trojan horse to dial a 900 number, said Alex Eckelberry, CEO of Sunbelt Software Distribution Inc., a Clearwater, Fla.-based security developer. That number can be traced to "passwordtwoenter.com," a payment processor also used by hardcore pornography Web sites to charge for access to their content, added Eckelberry.

Users infected with the Trojan horse see a full-screen message posing as an error generated by Windows, according to screenshots posted by Eckelberry on the Sunbelt company blog on Monday. "ERROR: Browser Security and Antiadware [sic] Software component license exprited [sic]," the message reads. "Surfing PORN, ADULT and some other kind of sites you like without this software is dangerous and threatens with infection of your computer by harmful viruses, adware, spyware, etc."

The bogus update window includes a "Click to activate new license" button that in turn brings up another screen, this one telling U.S. users to dial a 900 telephone number and enter a personal identification number (PIN). If the 900 number doesn't work, the page instructs users to dial alternate numbers -- one in the West African nation of Cameroon, the other a satellite telephone number.

"You're completely locked out of the system" after the Delf.ctk Trojan horse installs and runs, said Eckelberry. The only way to regain control is to pay up by dialing.

A search on Google for the 900 number returns results pointing to passwordtwoenter.com, a Web site registered to Global Voice SA, a company based in the Republic of Seychelles, an island nation in the Indian Ocean. The IP address used by passwordtwoenter.com is shared with similar domains, including "pintoenter.com" and "chargemyphonebill.com," which are also registered to Global Voice.

Global Voice did not respond to e-mail sent to the address listed in the domain registration information for passwordtwoenter.com.

Ransomware, a term used to describe malware that tries to extort money from users after an infection -- usually to return access to suddenly-encrypted files -- is rare, but not unknown. The last outbreak of any note was in July 2007, when another Trojan horse, dubbed "GpCode," demanded $300 to unlocked frozen files.

source: www.computerworld.com

Wednesday, December 26, 2007

Storm Worm Strikes Again

The Storm botnet delivers unwanted Christmas presents.

Storm Worm Tempts With Christmas Strip Show

The criminals behind the Storm botnet waited until the last minute, but they've finally started delivering unwanted Christmas presents.

Starting Monday, Storm-infected machines began sending out Christmas-themed spam in yet another attempt to trick victims into downloading malicious software. In this case, the site is named Merrychristmasdude.com, and the malware is a variation of the Storm Trojan horse program that has been plaguing systems around the world since January.

The e-mails contain titles such as "Find Some Christmas Tail," "Warm Up this Christmas" and "Mrs. Clause Is Out Tonight!"

One message reads "Yo, I am pretty sure this is up your alley, from the things you have told me before. This will be the best 2 min you spend this holiday. hehe."

Once the user clicks on the link to Merrychristmasdude.com, he is taken to a Christmas-themed Web site with photos of scantily clad women and offered a free download. That download is a malicious program, called Email-Worm.Win32.Zhelatin.pd by F-Secure, that connects to a P-to-P (peer-to-peer) network and begins downloading even more malware.

Storm's creators have built up networks of infected PCs -- called botnets -- over the past year by using a combination of sophisticated hacking tricks to avoid detection and by spamming potential victims with clever and timely e-mail messages. The network is called Storm because its original messages offered victims video of the deadly storms that battered Europe a year ago, but has also perfected the tactic of sending out holiday-themed messages.

Security experts estimate that the Storm has infected more than 15 million computers over the past year, although the current size of the network is much smaller than that.
This latest variant is being blocked by some antivirus vendors, including Kaspersky, Microsoft and Symantec, according to a technical write-up of the Christmas outbreak.

The SANS Internet Storm Center recommends that administrators block Web and e-mail access to the Merrychristmasdude.com domain.

source: www.pcworld.com

Sunday, December 9, 2007

Facebook Tracks Offline Users

The social-networking site acknowledges that its Beacon ad service tracks even logged-off users who are visiting their partner's website.

Facebook Tracks Even Logged-Off Users
The social-networking site Facebook confirms the findings of a CA security researcher that its Beacon ad service is more intrusive and stealthy than previously acknowledge. This contradicts the statements previously made by Facebook executive and representatives.

The ad service, Beacon, tracks users' off-Facebook online activities even if those users are logged off from the social-networking site. The Beacon tracks user's online activities on specific external websites and broadcasts it to their Facebook friends. Although this feature has an option to opt-out, Beacon still transmits data gathered to Facebook servers even if the user has previously declined to use Beacon.

According to a company spokesman, Facebook does nothing with the data transmitted back to its servers, and, in these cases, deletes it. The admission will probably fan the flames of the controversy engulfing Beacon, which has been criticized by privacy advocates.
The Facebook spokesman did not initially reply to a request for further explanation on how the Beacon action gets triggered if a user is logged off from Facebook, when the social-networking site's ability to track its users' activities should be inactive. It's also not clear whether the website plans to modify Beacon so it doesn't track and report on the off-Facebook activities of logged-off users.

Beacon is a major part of the Facebook Ads platform that the website introduced with much fanfare several weeks ago. Beacon tracks certain online activities of Facebook users on more than 40 participating websites, including those of Fandango and Blockbuster. These include purchasing a product, signing up of a service, and including an item on a wish list. It then reports those activities to the users' set of Facebook friends.

The program has been blasted by groups such as MoveOn.org and by individual users who have unwittingly broadcast information about recent purchases and other Web activities to their Facebook friends. This has led to some embarrassing situations, such as blowing the surprise of holiday presents.

On Thursday night, Facebook tweaked Beacon to make its workings more explicit to Facebook users and to make it easier to nix broadcast messages and opt out of having activities tracked on specific Web sites. Facebook didn't go all the way to providing a general opt-out option for the entire Beacon program, as some had hoped.

Facebook users are not informed that data on their activities at these sites is flowing back to Facebook, nor given the option to block that information from being transmitted.

If users have ever checked the option for Facebook to "remember me" -- which saves users from having to log on to the site upon every return to it -- Facebook can tie their activities on third-party Beacon sites directly to them, even if they're logged off and have opted out of the broadcast. If they have never chosen this option, the information still flows back to Facebook, although without it being tied to their Facebook ID, according to Stefan Berteau, senior research engineer at CA's Threat Research Group.

Facebook's admission over the weekend contradicts previous statements from the company regarding this issue. For example, in e-mail correspondence with Facebook's privacy department, Berteau was told, among other things, that "as long as you are logged out of Facebook, no actions you have taken on other websites can be sent to Facebook."

Saturday, December 8, 2007

Microsoft Internet Explorer Flaw

Microsoft acknowledges that there is a vulnerability with Internet Explorer 7 and rushes out fix


Microsoft IE7 to Patch
Microsoft went to work to fix a vulnerability with Windows Internet Explorer and its URI, or Uniform Resource Identifier. The fix is to address the problem in the way Internet Explorer 7 interacts with other programs. But with no fix available at the time, using IE7 on Windows XP machines is risky business.

The vulnerability of IE 7 lies in how it interacts, via the URI handler, with products such as Adobe's Acrobat Reader or Mozilla's Firefox. Before, Microsoft pointed fingers to Firefox. Then, the company, after acknowledging that the problem was its own, went to a slow work on a fix because no known exploit existed at the time. But it went on a frenzy when a Trojan horse attack started infecting machines in October.

The Trojan horse attack, which a user receives as an infected PDF, brings an old social-engineerin ploy, which malware filters usually don't vet. It tricks you into clicking the link by carrying a subject line such as "invoice" or "bill".

Adobe patched Reader, but that only covers one end of the worm home. Microsoft's patch has been in testing for quite a while, and may remain in that state for some time. As of now, try to avoid using Windows Internet Explorer 7 to browse sites that are suspicious. Try other alternatives, such as Firfox version 2.0.0.6 and up, which already has a patch for the URI vulnerability.

Opening e-mail attachements is growing riskier. A Microsoft report found that the first half of 2007 saw a 150 rcent increase in phishing scams and a 500 percent increase in malicous payloads.

Obtain a patch of Adobe Reader fix at the Adobe's site if you don't have the PDF fix yet.

Saturday, December 1, 2007

Google to Combat Malicious Sites

Last month, news about malicious sites taking advantage of Google's PageRank to stay on top of the search results, drawing unsuspecting users into their malware-ridden sites. Google creates an online form so users can report any malicious sites they may see.


Google's Response to Malware Sites
News leaked out about malicious sites using a technique called Google Bombing and spamdexing to stay on top of the search results, last month. Malware sites will likely to occur on the top of the search results, drawing unsuspecting victims into their malware-ridden sites, by exploiting Google's PageRank system. Once the user enters the site, it will try to install a number of malwares on the system.

Security vendor Sunbelt Software said hackers appeared to be using various tricks to ensure their malicious sites appear high in Google's search results. Sunbelt said it turned up 27 different domains hosting malware, each with up to 1,499 malicious pages, or some 40,000 pages in total.

Google's initial response was to purge from its index these sites, although Google has not confirmed that this happened. At least, your search result will now less likely contain a malicious website. It was the first search engine to act on this situation. After all, it is its technology being used to bait users. Yahoo and Windows Live Search has not yet reported to the said breakout.

Currently, we know of hundreds of thousands of Web sites that attempt to infect people's computers with malware. Unfortunately, we also know that there are more malware sites out there," Google's Ian Fette wrote in the company's security blog.

To protect online users even more, Google launched an online form so ordinary web users can report any website they suspect that contain malicious code. It contains a simple form that lets users enter the URL of the site and additional information. It also features a CAPTCHA to prevent automated bots from reporting sites automatically.

Thursday, November 29, 2007

Google Cleans Up Malware

Reports say that certain malware distributing sites are making their way to the top of Google's search results, taking advantage of their PageRank system.


Google Purges Malware Websites
This week, news spread in the web saying that malware sites are taking advantage of Google's PageRank system to appear on the top of the search results. Researchers confirmed this Wednesday that Google Inc. has cleaned its index for malware websites.

Malware websites forced its way to the top of search results in Google search by processes known as spamdexing and Google bombing. Spamdexing creates invisible text in the websites that is used to lure users to the websites and is usually irrelevant to the page's content, while Google bombing employs the work of bots that increases the PageRank of a page. For more information about these techniques, see the article, Clicking Google Search Result May Lead to Malware in Sonicsoft Wired.

Researchers, however, said that Google has purged the malware sites from its index, effectively removing these sites from appearing on their search results.

The malware sites, once visited, will attempt to install tons of spywares, viruses, password stealers, rootkits onto the user's system. These malwares are easily prevented by the most recent patches available and uses no new exploits of software.

"They look gone to us," said Alex Eckelberry, the CEO of Sunbelt Software Distribution Inc., the company that broke the news Monday of a massive, coordinated campaign by attackers to spread malware through search results on Google, Yahoo, Microsoft Live Search and other sites.
Google did confirm yesterday with us that they were working the case, and they are good about nailing this stuff," Eckelberry added. He notified Google about his research this Monday.

Ironically, Google refuses to confirm or deny that it did remove from its index the 40,000 malware hosting sites, or even that they had existed. "Google takes the security of our users very seriously, especially when it comes to malware," a company spokeswoman said Wednesday. "In our search results, we try to warn users of potentially dangerous sites when we know of them. Sites that clearly exploit browser security holes to install software, such as malware, spyware, viruses, adware and Trojan horses, are in violation of the Google quality guidelines and may be removed from Google's index."

However, she did not mention how long Google made the purge, and if the company had ever done any countermeasures against malware sites from perform this kind of trick in the future.

Microsoft has just confirmed the presence of the malware sites, and are working on it, says a representative of the Live Search team. Yahoo has not yet made a comment.

Wednesday, November 28, 2007

Google Trouble

A new wave of malware distribution is stewing, and it utilizes Google's PageRank system to appeal to users.


Clicking Google Search Result May Lead to Malware
Google is really famous for this technology, and is probably why it's service is leading from its rivals, Yahoo! Search and MSN Search. Google's PageRank technology was designed so popular websites appear on top of search results.

Google's PageRank uses a nifty logic to determine which page is important and which are not by counting the websites that links to the website. In an example, let's say we will need to rank Page A. Google's spiderbot will count how many websites will link to Page A, thus adding a vote to the site, and increasing its rank. The higher the number of sites, the higher the rank would be. All websites are ranked using this technology. For more information about Google PageRank, see this page.

Although this may look like a very good system, it's not without its flaws. A technique known as Google bombing is a technique used to manipulate the search results of Google Search. Since Google uses PageRank, which counts how many websites that links to a page, Google bombing involves creating tons of websites, or blogposts, that links to a page you want its rank to increase. If enough false websites or posts links to the page, it might appear on top of the search result of Google. Also, a technique called Spamdexing, is closely related to Google bombing, employing a different technique, usually involves creating invisible text (like white text, that blends perfectly with the background) to increase the likelihood that the page is ranked higher.

Malwares are now using these techniques to direct unsuspecting users to enter the website, that installs tons of viruses, trojan horses, rootkits, and password stealers. A bot may be used to create hundreds of blogposts that links to the malware page, effectively increasing its rank, and increasing its chance to appear on top of the search result page. Innocent keywords, from 'how to I teach my dog to play fetch' to 'how to cisco routing vpn dial in', may produce links that leads malicious websites on the very top of the results. Most users wouldn't suspect anything's amiss with the rogue results, although the ultra-wary might be suspicious because many of the malicious URLs are just a jumble of characters, with China's .cn top-level domain at their ends.

Once a user enters the bogus site, he'll be bombarded with malware installation. It may guise itself as a fake video codec. If that doesn't get the user, its IFRAME will. "This is what's doing the most damage," added Sunbelt malware researcher Adam Thomas. "It's loaded with every piece of malware you can think of, including fake toolbars, rogue software and scareware."

One site that Thomas encountered tried to install more than 25 separate pieces of malware, including numerous Trojan horses, a spam bot, a full-blown rootkit, and a pair of password stealers. All the malicious code pitched at users is well-known to security vendors, and can only exploit PCs that aren't up-to-date on their patches.

Sunday, November 4, 2007

The Giant Google

Google is expanding, and it can have so much data about you that you might not even aware of. But can we trust it with so much data?


Is Google Too Big?

Google is popular as a search engine, but it's really more than that. Now you have emails run by Google, along with word processors, spreadsheets, and presentations. Add to that Google's Picasa, Maps, and other things. Google is becoming big - too big perhaps.

With all that online services available from Google, it's not really a shocking revelation that it knows a lot of information about you.

The question is can you trust Google with your data?

This is a short list of what Google knows about you:


  • Google Search
    Tying your search history to your browsing activities via the DoubleClick advertising network gives the company a much more detailed view of your online activities

  • GMail
    The routing information and content of your mail--including any attachments--reside unencrypted on Google servers. Loss of, or unauthorized access to, business correspondence increases your company's legal exposure

  • Google Docs and Spreadsheets
    Your files are stored unencrypted on Google servers. A business could be found negligent if it loses, or allows unauthorized access to, business documents. Until applications supporting Google Gears arrive, you lose access to your files when your Internet connection fails

  • Picasa Web Albums
    Photographs in albums designated "unlisted" can still be viewed by anyone who knows the URL. At present you have no option to view or back up your albums offline

  • Google Calendar
    Your daily schedule and associated information reside unencrypted on Google servers. Loss of, or unauthorized access to, business information puts your company at risk. You can't open your calendar without an Internet link, although this will change with the arrival of the Google Gears browser extension

  • Google Desktop
    If you neglect to lock the search function, anyone using your PC has access to your personal files. Copies of business documents may be stored on Google servers, making them susceptible to loss or unauthorized access

  • Google Talk
    Instant-message logs can be archived and searched in Gmail

  • Google Product Search
    A log of your product searches could be associated with your browsing history via the pending DoubleClick acquisition

    Source: PCWORLD.com

The question is, can you trust Google with all that information about you? And since the data resides unencrypted on Google's server, who knows who can access your data - the government? agencies, hackers, rival business?


Google's online trove of personal and sensitive information is proving attractive to law enforcing agencies. In the previous year, Google has prevented the Department of Justice from demanding millions of search queries, stating that this is an invasion of privacy.


Google also said that it will begin clearing out some personal information of users, like their IP address, after 18 months from its logs, though this step may be insufficient for security-conscious users.


I'm not saying your data is at-risk all the time, but you should take precautions over what to store with Google. Also, Google should take steps to prevent unauthorized access and enforce privacy restrictions on the data it stores.