Another hack to keep an eye on

There’s plenty of word these days about SQL injection (Dancho Danchev’s blog is an excellent reference on this trend). Add another one to the list, a fairly extensive cross site scripting hack currently in action, pushing porn, and ultimately malware.

The images displayed are extremely graphic in content. When an image is clicked, the user is redirected to a site pushing a fake antispyware program.

Xss238823488

Xss238823488aa

Xss238823488b

Searching Google for the term “href=//imagesoap” pulls up a large number of results. (Warning: the results returned are highly graphic in content, and do lead to malware.)

Xssgooglesearch1238

Sites observed as infected include:

faa.org
movieweb.com
finlayongovernance.com
exmoorcastingsupplies.co.uk
interbrand.com
montecarlofans.com
ceiling-fans.biz
paxworld.com
travelandleisure.com
flexexamples.com
venganza.org
killerfrog.com

And plenty more.

Alex Eckelberry
(Thanks Francesco and Adam)

More spoofed sites

With thanks to Xavier for the help, here’s a quick follow up to my earlier posts here, here and here about the Vladzone malware gang spoofing legitimate sites.

We have more sites masquerading as legitimate ones. The following are run by the same group:

IP 207.226.177.244
Attrezzi biz
Foltax com
Master-x info
Siriusinter net
Slimcash com
Trasferimento biz

IP 209.8.151.190
Adslim com
Awmdev com
Gunbrethren com
Literaryaccess com
Nzpr com
Rosewedding net
Squareonerecords com
Tocsite com

And, one errant site, not necessarily Vladzone:

IP 216.255.179.140
dorifora com

Alex Eckelberry

Tough life in Florida

Today our friends at F-Secure posted pictures of their office during the winter and summer.  Same shot, same location, but dramatically different weather.

We do feel a great deal of empathy with them.

For example, like F-Secure, we took a shot of a local scene in the middle of winter:

Rjla_tampabay0814

Here is that exact same shot, only this time, taken during the summer:

Rjla_tampabay0814

It’s tough.  But we’re survivors.

Did I mention we’re hiring?

Alex

Yes, Haloscan is borked, and I don’t know why

A number of active commenters on this blog have noticed that Haloscan comments are being treated strangely. I have no idea what’s going on.  PG is seeing the same thing.

Hopefully it will fix soon.  Otherwise I’m going to have to do some serious re-plumbing (which I really don’t want to do…).

Alex Eckelberry

Lifelock CEO pwned

TODDEPICFAIL

Todd Davis has dared criminals for two years to try stealing his identity: Ads for his fraud-prevention company, LifeLock, even offer his Social Security number next to his smiling mug.

Now, Lifelock customers in Maryland, New Jersey and West Virginia are suing Davis, claiming his service didn’t work as promised and he knew it wouldn’t, because the service had failed even him.

Article link here.

Whatever. Incidentally, if you’re curious about these services, Dan Tynan did a good writeup recently, here. Also, the Fraudwar blog routinely writes on this area, and it’s worth putting into your feed if you have an interest in the subject.

Alex Eckelberry
(Thanks, Richard)

Using search engines in research and vulnerability assesment

An article I wrote for Virus Bulletin back in November about using search engines for malware research (and vulnerability assessment) is now available online.  You just need to go through the free registration (well worth it, as Virus Bulletin is an outstanding resource).

Link here.

Alex Eckelberry

More Vladzone fake pages

Follow-up to my earlier posts today about fake sites spoofing legitimate ones, Vladzone, the malware gang behind lots of pain, has more treats in store for us. There is another fake site on the same netblock, but with a different IP.  Further research and we have six more fake sites to add to the list:

Exe-prod com   — Impersonates the FCC
Fulldvd org  — Impersonates DVDTown
Pclem com  — Impersonates the Lunar and Planetary Institute
Phpbbscript com  — Impersonates FeedForAll
Planetbudtron net  — Impersonates the Sharper Image.
Queenshussars com –  Impersonates Kings College London

Alex Eckelberry
(Thanks to sharp-eyed Xavier for this latest catch, as well as MJ and Adam Thomas)

Explosion of spam pages on Google Pages

It’s been a problem over at Google Groups. Now Google Pages is undergoing an attack by spammers.

No direct malware links (but that can change in an instant), primarily redirects to sites used in spam.

Example, showing results added in the past 24 hours:

Googlepages12381238

The URLs have a particular look to them. Examples:

b2006e.e52bb.googlepages com
te09d0.e2ee.googlepages com

I hope Google can tweak their algorithms rapidly to fix this.

Alex Eckelberry
(Thanks and credit to Jim Murray)

Rash of fake sites copying PC World, CastleCops, others

As a follow-up to my post earlier today about a fake CastleCops page, there’s more to the story.

There are other domains sharing the same IP (207.226.177.250):

pepato org
slim-cash com
spyware-wiper com
Cpaypal com
Crazycounter net

All are copying legitimate sites.

Pepato is loading a fake dvdplanet.com page:
Pepato12388123

Slim-cash is spoofing Allposters.com:Allpostersx23488

Spyware-wiper spoofs pcworld.com

Spywarewiper12381238

CrazyCounter copies the European Space Agency:

Crazycounter12381238

And Cpaypal copies AboutPayPal.org.

Cpaypal2134888

These domains belong to the “Vladzone” malware gang. A while back, we believe that they were responsible for DDoS attacks against webhelper4u.net (Patrick Jordan, who works for Sunbelt) and spamhuntress.com — and maybe a few others. I would not visit these sites…

Alex Eckelberry
(Thanks, Adam)

The problem with Live

So now Microsoft is going to pay for results. This is the kind of strategy I would figure coming out of Ask.com (or the old iWon). Not from Microsoft. And it won’t work in the long run. People search to find things. If they’re not finding what they want on a search engine, they won’t use it. And they won’t care about freebies and cash.

I started using Google back in 1998 because it was much better than Altavista (which was the best at the time). And I went to Altavista because it was better than Yahoo.

I’ve stuck with Google ever since. It’s quite simply the best search engine available.

When someone comes up with a better search engine than Google, I’ll certainly look at switching. And I’ll know, because word gets around to people like me when something is better. It spreads like wildfire throughout a technical community.

Microsoft’s problem has nothing to do with its marketing, giving cash back, or what have you. They are in a real quandary: This is one area where gobs of technical leadership is required.

Microsoft is a superbly run company, with many brilliant engineers. Now, I feel bad saying this next thing, because I have a lot of close friends at Microsoft (and I also have a lot of ex-Microsofters working here). But I would respectfully question if the company is internally wired to be a real technology leader. The business side has relied on the OS and low pricing (e.g. free) to push adoption in the past. Their products have always been decent, but rarely revolutionary. Only evolutionary. Now, the chickens have come to roost, because Microsoft is faced with one area where they are simply not innovating as fast as the compettition, and they won’t win unless they do. And they are worried (rightfully) because Google’s SaaS offerings are going to blow them out of the water if they don’t get their online strategy worked out.

Yahoo faces a similar problem. I downloaded some thing from Yahoo the other day for my Blackberry. It was crap. Slow, piggish, and difficult to use. In my eyes, the merger of the two companies would have been similar to what’s currently being proposed with Blockbuster and Circuit City: The flawed business logic that “two wrongs make a right”. Ballmer was right to back out.

Anyway, let’s compare a couple of search results.

Here’s a search for “Hospitals in Spokane, Washington” in Live:

Livesearch123a

Here’s that same search in Google, arguably better:

Googleearch123a

How about something more practical: I’ve arrived in Clearwater, Florida, and want to find a place to eat. I input, into my Blackberry, “places to eat in clearwater, florida”.

With Live, I get the first hit being an appliance repair company:

Livesearch223a

Oh, wait! It’s a sponsored link. But I can’t tell unless I look closely, because apparently Microsoft is trying to get more click-throughs for advertisers by making it impossible to tell if something is real or sponsored. That’s BS and backfires when people are actually trying to find something.

With Google, of course, I get something relevant right off the bat:

Googleearch223a

The difference is that Google’s first priority is making a good search experience (incidentally, the purpose of a search engine), and then advertisers. And to top it all off, Google implements beautifully on the future platform, mobile devices.

Oh, and while we’re at it, look at the difference between a search for my product, CounterSpy, between Google and Live. Do you think I’m happy about that? More importantly, do you think the customer is well served?

Now, I don’t want to be completely unfair. First, I’m not a heavy Live user. And Live is not that bad (for some searches, you may even prefer it). Plus, Live maps has some nice features (incidentally, it seems to locate some addresses that Google simply can’t — work to be done there, Google). But if I were Ballmer, I would do whatever I could to make Live the best product against Google. And skip the cash gimmicks. It will only buy a temporary bump, but won’t affect a long-term secular trend.

Alex Eckelberry

Spam Plan: Use social networks

It’s such a hassle these days to spam with a  URL that isn’t detected by some antispam program. And Google redirects get tired.  Plus… it would be cool get a bump in SEO while you’re at it.

So why not send spam that links to recognized social networks, that can then act as free hosting (accomplish all the objectives above)? 

That’s exactly what’s happening. 

Here are some examples from a recent spam:

Spam11293888

Spam21293888

Spam31293888

Spam41293888

Administrators who run these sites do need to stay on top of this kind of junk, because it affects the entire internet community. 

Alex Eckelberry
(Thanks Adam)

No, it’s our data and our privacy

Excellent writeup over at Schneier.

We leave data everywhere we go. It’s not just our bank accounts and stock portfolios, or our itemized bills, listing every credit card purchase and telephone call we make. It’s automatic road-toll collection systems, supermarket affinity cards, ATMs and so on.

It’s also our lives. Our love letters and friendly chat. Our personal e-mails and SMS messages. Our business plans, strategies and offhand conversations. Our political leanings and positions. And this is just the data we interact with. We all have shadow selves living in the data banks of hundreds of corporations’ information brokers — information about us that is both surprisingly personal and uncannily complete — except for the errors that you can neither see nor correct.

What happens to our data happens to ourselves.

This shadow self doesn’t just sit there: It’s constantly touched. It’s examined and judged. When we apply for a bank loan, it’s our data that determines whether or not we get it. When we try to board an airplane, it’s our data that determines how thoroughly we get searched — or whether we get to board at all. If the government wants to investigate us, they’re more likely to go through our data than they are to search our homes; for a lot of that data, they don’t even need a warrant.

Who controls our data controls our lives.

It’s true. Whoever controls our data can decide whether we can get a bank loan, on an airplane or into a country. Or what sort of discount we get from a merchant, or even how we’re treated by customer support. A potential employer can, illegally in the U.S., examine our medical data and decide whether or not to offer us a job. The police can mine our data and decide whether or not we’re a terrorist risk. If a criminal can get hold of enough of our data, he can open credit cards in our names, siphon money out of our investment accounts, even sell our property. Identity theft is the ultimate proof that control of our data means control of our life.

We need to take back our data.

Highly recommended reading. Link here.

Alex Eckelberry
(Thanks Eric)

Carrie’s MacBook Pro

Sexcity123888

I really, really dislike this show. Unfortunately, in a household with two daughters and a wife who practically worship it, I can’t escape it.

However, one has to give Apple kudos for working on a very smart marketing campaign with the promoters.

Go to http://www.sexandthecitymovie.com/macbook/, enter an email address, and “use” Carrie’s Macbook.

Now, one can’t really imagine “using Carrie’s Vista machine” (which is at the heart of Microsoft’s problem of not being perceived as hip). But what about if we all broke with the Great Unwashed Hipsters, and tried “using Carrie’s Ubuntu box”?

No, because it doesn’t come in pink.

Dear Lord.

Alex Eckelbery

Estonia’s cyberwar

Estonia123888

Ok, I’m a fan of Estonia. The president of that small country was recently here in Tampa, and while I didn’t get to see him talk, I was impressed with what I heard of the country.

Of course, there’s the extraordinary flat tax system (which actually goes down every year). I can only envy it from afar…

And, the country runs like a well-oiled machine compared to other democracies. The country is heavily online, with about 95% of all government activities done through the Internet. There’s no luddite Series of Tubes nonsense going on over there. These people are very hip to the Internets and The Google.

There’s a darker side: About a year ago, the country was nearly brought to its knees by a massive cyberwar. They fought back successfully, and the result is that the country is to become the center of a seven nation NATO cyberdefense center. I can’t think of a more perfect location, frankly.

So on that note, friend and colleague Gadi Evron wrote a detailed analysis of what happened last April. Recommended reading, and you can find it here.

Go Estonia.

Alex Eckelberry

Update: Counterpoint/debate here.

Bizarre: Spamming in bookstores

If you’re wondering why your next book purchase is clogged with pamphlets from local businesses, you can thank real estate marketer Carl White.

Here, whispering conspiratorially, he shows how to sneak into a book store aisle and insert personalized business cards into books.

(Direct link if you’re having problems accessing the video, here.)

The idea of angst-ridden real estate salespeople furtively inserting their business cards into real estate books… well, I admit, the image is funny (and sad), even if it is obnoxious as hell.

Alex Eckelberry

Recent trends in spam

Spam keeps changing. I thought I’d anecdotally highlight some recent trends we’re seeing in spam:

– Fake university degree offers appear to be way up.

Spam111111110

– A new type of spam which pushes affiliate links. The look is always the same — green link text, simple headline.

This one pushes AdultFriendFinder:

Spam211111110

This one pushes an adult site, again apparently using an affiliate ID.

Spam311111110

– Malware-pushing spam is still pandemic. Various interesting subject lines, and even resorting to outright begging:

Spam411111110

Spam511111110

Spam711111110

Spam611111110

Spam811111110

And so on…

– The plague of “me”: Another very popular spam going around these days is an email with an attachment (usually about 40k–50k in size), featuring a picture of this girl:

Me_218123881238

The spammers don’t put any extension on the file, which is named “me”. However, it is a jpeg format file.

Spam911111110

(This is just a baiting tactic to lure the recipient into a scam.)

Otherwise, for the most part, it’s still the same old fake luxury goods and “Cialis/Viagra/cheap meds” garbage, along with the usual extraordinary amount of spam promising the enlargement of a particular male body part.

Alex Eckelberry