Feeds

Google and eBay thwart phishing redirection ruse

Clean up campaign bears fruit

Beginner's guide to SSL certificates

High-profile websites have cleaned up their act after a small team of security researchers documented how they were unwittingly helping phishing fraudsters.

Phishing scams often use "open redirector" exploits on major sites to make their attack URL look more legitimate. The trick also makes it more likely that fraudulent emails that form the basis of phishing attacks will slip past spam filters.

Typically, security shortcomings on targeted sites allow scammers to furnish links that appear kosher but actually redirect to a fraudulent site.

Previous Register stories have covered examples of the ruse practiced on websites including Barclays Bank (story here), eBay (here), and others.

A campaign by SiteTruth to name and shame high profile firms that fail to block open redirector exploits is beginning to bear fruit.

SiteTruth cross-referenced the 10,000 sites listed in PhishTank (a clearing house for reports about phishing sites) with the 1.7 million sites in the Open Directory Project database to discover a list of problem domains. Domains listed typically have a security vulnerability which is being exploited by phishing fraudsters.

URL redirection isn't the only category for listing in this blacklist (hosting or otherwise unwittingly helping phishing scams also counts), but the sites allowing URL redirection included many high-profile organisations that ought to know better, including Google Maps, AOL, and eBay.

Recent updates by Google Maps and eBay since we wrote about SiteTruth's work have nipped the problem in the bud. Other organisations, such as AOL, are yet to address the problem. Nonetheless, SiteTruth is happy at making inroads into the number of high-profile sites open to abuse.

"You'll be pleased to know that the combination of your article, our reports, efforts at the Anti-Phishing Working Group, and a certain amount of nagging on our part has made a considerable dent in the 'open redirector' problem," SiteTruth's John Nagle told El Reg. Google fixed its problem last week, and currently has no active phishing attacks listed in PhishTank. eBay also cleaned up its act and it too is now out of the tank.

AOL, however, is yet to clear up its problem, first reported earlier this month, that allows open redirector exploits (harmless example that redirects from AOL to El Reg here).

That's just one example that illustrates the problem is a long way from being resolved. Nonetheless, SiteTruth's list of problem domains is shrinking.

"Our list of major sites with exploited vulnerabilities, not all of which are open redirectors, has been shrinking as the word gets out. There were 171 problem domains in early December, and we're down to 54 today. Publicity is working," Nagle added.

Phishing sites come and go rapidly, but some problematic domains have become a fixture of SiteTruth's phishing blacklist.

"Only 16 of those domains have been on our list since its inception in late November. Most of those are DSL service providers inadvertently providing connections for computers hosting phishing attacks. The others come and go as phishers find vulnerabilities and site operators plug the holes," Nagle concluded. ®

Protecting users from Firesheep and other Sidejacking attacks with SSL

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
Jihadi terrorists DIDN'T encrypt their comms 'cos of Snowden leaks
Intel bods' analysis concludes 'no significant change' after whistle was blown
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
China hacked US Army transport orgs TWENTY TIMES in ONE YEAR
FBI et al knew of nine hacks - but didn't tell TRANSCOM
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Protecting users from Firesheep and other Sidejacking attacks with SSL
Discussing the vulnerabilities inherent in Wi-Fi networks, and how using TLS/SSL for your entire site will assure security.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.