Tuesday, January 09, 2007

Opera users should update to 9.1

Secunia has reported that Opera 9.x has two vulnerabilities which can be used by an attacker to compromise a users system.

The two errors that have been reported are:

1) A error within the processing of JPEG files can be exploited to cause a heap-based buffer overflow via a JPEG file with a specially crafted DHT marker.

2) An error within createSVGTransformFromMatrix() can be exploited by passing an incorrect object to the said function.

Opera has been going through a phase without any big vulnerabilites being reported. But this has changed that. The last reported vulnerability with Opera before this one was the
URL Parsing Heap Overflow Vulnerability.

It is advised that all Opera users update their browser to Opera 9.1 which was released very recently with a whole lot of innovative features including the Real-Time Anti-Fraud technique.



Sunday, January 07, 2007

14 things to be avoided for SEO (Search Engine Optimization)

Ok, folks I came across a very informative article related to some basics of search engine optimization at Google Blogoscoped, a blog that covers Google and the tech world since 2003 with 80% focus on Google. The person behind Google Blogoscoped is Philipp Lenssen and his posts are widely read.

(Philipp Lenssen has also interviewed Matt Cutts, Google’s Gadgets Guy back in Nov.2005. If you are interested, read the interview here.)

In this article he gives some basic tips about search engine optimization and somehow what caught my eye was the 14 steps he has mentioned, that should certainly be avoided while trying to optimize your search engine rankings and I thought of sharing it with all the fellow bloggers who have just started setting their sights on the Blogosphere.

Here is the 14 things that are an absolute no no:

  • Don’t stuff too many keywords into places where they don’t belong.
  • Don’t optimize for search engines at the cost of human visitors; if someone told you adding a dash to the domain name helps your rankings, but you feel that dash might confuse your customers, then don’t add it.
  • Don’t trust people who promise you “instant #1 rankings”, “guaranteed top 10 positions” or anything of the sort.
  • Don’t link to others from your site just because they promised a link back to you.
  • Don’t link to others just because they paid you, unless you know exactly what you’re doing (i.e. you know about “bad neighborhoods,” the “nofollow” attribute, PageRank, JavaScript-ads vs text links, what it means to get googleaxed and so on).
  • Don’t create multiple pages with exactly the same content.
  • Don’t let others people “litter” URLs on your site; if you have a web forum, keep it spam-free.
  • Don’t “litter” your URL on other people’s sites.
  • Don’t invest in a cheap server that won’t be able to cope with your traffic; don’t build your whole site on free website tools only – if you want to have a high-quality site & server, you need to pay for it.
  • Don’t worry about a page’s meta descriptions, meta keywords and such; your time is better spent creating content.
  • Don’t use tools that automatically submit your site’s URL to directories, search engines and such.
  • Don’t present different content to search engines than you present to users; for example, don’t hide your text to visitors and show it to search engines.
  • Don’t “over-optimize"; relax, if search engines required webmasters to heavily optimize, they’d be doing a very bad job.
  • In general, don’t try to outsmart search engines (unless perhaps you intend to dedicate your life to that task); those maintaining search engines are paid to outsmart webmaster tricks, so in the long run, chances for successful tricks are low.
You can read the basics of Search engine Optimization at Google Blogoscoped.

Full movies/Tv shows for free--Simplistic's Movie Links.


Yes, there is a website that puts full length videos and Tv shows from sites like YouTube, Dailymotion, Guba etc:- The site is called Simplistic's Video Links and is updated daily. They get all the movies that are uploaded in parts on sites like YouTube, Dailymotion etc: and join them together and put it on this site. Most of the movies at this site are split into 10 parts. There are over 325 movies available at this site right now and it is updated daily.

According to the site it is legal since the contents are not hosted at the site but is provided through the video hosting sites.

How long each movie will stay at this site remains to be seen since whenever the movies are taken off from the original sites like YouTube because of copyright violations the movies will disappear at this site too.

Phishing sites using Flash.

It has been reported by F-secure that there are some phishing sites that have started appearing on the net using Flash instead of HTML. This technique is now being used to work around the Anti-phishing tool bars and the built in Anti-phishing techniques in the browsers like Firefox 2, Internet Explorer 7 and Opera 9.1

Two of the sites that have been found to be using these techniques are www.ppal-form-ssl.com and www.welcome-ppl.com, both targeting Paypal users.

If you right click on the pages you will see the "Zoom in" "show all" "play" options in the menu instead of the normal options you see on an HTML page.

When you type in login information, the SWF file displays a new page, asking for your credit card information.

So now even if your Anti-phishing tool bars does not alert you when you land at a phishing site be careful to check the url and above all use your prudence before giving out informations.

10 ways to use LinkedIn (by Guy Kawasaki)

LinkedIn is a site as most of know is network of professionals. So it certainly is a good platform to advertise your Job expertise and look for jobs and also a site which allows you to connect with professionals and people who are looking for experts and professionals for various aspects thus it is not just about getting jobs but forming partnerships or making sales etc: All 500 of the fortune 500 companies are represented at Linkedin.

However many of the people who join the site is not fully aware of how to make the most use of it and according to Guy Kawasaki it is a tool that is under-utilized. In his blog Guy Kawasaki has posted a top-ten list of ways to increase the value of LinkedIn. And here are the 10 things he has covered:

1.Increasing your visibility.
2.Improving your connectability.
3.Improving your Google PageRank.
4.Enhancing your search engine results.
5.Performing blind, “reverse,” and company reference checks.
6.Increasing the relevancy of your job search.
7.Making your interview go smoother.
8.Gauging the health of a company.
9.Gauging the health of an industry.
10.Tracking startups.

For those who are interested in reading the complete advice go to Guy Kawasaki's blog.

Thursday, January 04, 2007

An evaluation of 10 Anti-phishing tool bars.

In a recent study of all the major Anti-phishing tool bars conducted by the Carnegie Mellon University, they analysed the following 10 Anti-phishing tool bars:


1.Cloudmark Anti-Fraud Toolbar
2.EarthLink Toolbar
3.
eBay Toolbar
4.
GeoTrust TrustWatch Toolbar
5.
Google Safe Browsing
6.McAfee SiteAdvisor
7.
Microsoft Phishing Filter in Windows Internet Explorer 7
8.Netcraft Anti-Phishing Toolbar
9.
Netscape Browser 8.1
10.
SpoofGuard

The study was conducted by using verified phishing URLs and legitimate URLs to test the effectiveness of 10 popular antiphishing toolbars. And according to the study the Anti-phishing tool bars that have been studied leaves a lot to be desired.

Let me break up the study and give you the main points:

  • SpoofGuard did a very good job at identifying fraudulent sites.At the same time, SpoofGuard incorrectly identified 38% of the legitimate URLs as phishing URLs. It would seem that such inaccuracies might nullify the benefits SpoofGuard offers in identifying phishing sites.
  • The only toolbar tested that is known to make NO use of blacklists was SpoofGuard. While it was able to identify the majority of phishing sites using only heuristics, it still missed some phishing sites and it had a very high false positive rate.
  • SpoofGuard could potentially be improved through the use of a whitelist, which would prevent the problems that occurred when phishing sites were visited before their corresponding legitimate sites. The whitelist would not necessarily need to be extremely large or updated frequently to be effective.
  • The study found that three of the 10 toolbars, SpoofGuard, EarthLink and Netcraft, were able to identify over 75% of the phishing sites tested.
  • EarthLink, Google, Netcraft, Cloudmark, and Internet Explorer 7 identified most fraudulent sites correctly and had few, if any, false positives, but they still missed more than 15% of fraudulent sites.
  • The TrustWatch, eBay, and Netscape 8 toolbars could correctly identify less than half the fraudulent sites.
  • McAfee SiteAdvisor did not correctly identify any fraudulent sites.
  • The 10 toolbars that the researchers examined used a variety of methods for identifying fraudulent sites; however, it was able to exploit vulnerabilities in most of them.
  • The experiments also suggest that there is no single technique that will always outperform others for identifying phishing web sites.
  • Most of the tools tested used blacklists, but only half of them were able to identify the majority of phishing web sites.
  • The researchers don’t know the size of the blacklists used by each toolbar, nor do they know what heuristics are used by any of the toolbars other than SpoofGuard.
  • The researchers suspect that the toolbars that performed best use larger and more frequently updated black lists. They may also use heuristics that allow them to detect phishing sites that haven’t yet been put on the blacklist.
  • Relying solely on heuristics requires that the software is designed with the foresight to prevent circumvention. In this study we were able to exploit both techniques, which leads us to believe that a combination of techniques is necessary
  • The success of a blacklist relies on massive amounts of data being collected at frequent intervals.
  • The study says that much more work needs to be done in this area from a technical standpoint. Yet even if it is possible to create a technically sound antiphishingtoolbar, it is still unclear as to whether or not this would be beneficial to users. Usability problemsplague all varieties of software, security software in particular. When using an anti-phishing toolbar, poorusability could mean the difference between correctly steering someone away from a phishing site and having them ignore the warnings only to become a victim of identity theft. Thus, we plan to further examine both the technical aspects of this domain as well as the human factors.

My conclusion:

Ok, after going through these facts I come to the conclusion that among the 10 tool bars tested EarthLink, Google, Netcraft, Cloudmark, and Internet Explorer 7 are the best among the 10 tested since they hardly gave any false positives and they identified 75% of the sites correctly. Spoofguard is also good but since it relies solely on heuristics it gave a lot of false positives. The other three tools viz:- TrustWatch, Ebay, and netscape 8.1, performed poorly. And am also so surprised at the fact that Mcafee's Site Advisor did not correctly identify any fraudulent sites.

Now I am waiting to see a study which includes Firefox 2 Anti-phishing and Opera 9.1 Real-time Anti- fraud technique. BUt firefox also use Google's Anti-phishing database and Opera uses database from GeoTrust. So may be that is why they were not included in the study since they included Google tool bar and GeoTrust's tool bar in the study. And if you look at the study while Google's Anti-phishing tool bar performed well, GeoTrust's TrustWatch performed badly. So if I go by the study it means among the popular three browsers, Viz:- Internet Explorer 7, Firefox 2 and Opera 9.1, GeoTrust which is used by Opera performed badly while the Anti-phishing tools in the other two browsers performed well. But am still waiting for a further study to make a strong conclusion about this aspect.

You can read the full report here (.PDF)

Update: Please look at the comment below by Shane Keats of Mcafee regarding Mcafee's Site Advisor.

Google