Wednesday, November 01, 2006

Everything you want to know about Phishing attacks.

(If you are interested in reading only about how to protect yourself from phishing, then go part IV of this article where it is mentioned "How to protect yourself from phising." It also includes some tips for Myspace users. And, Part V of this article has links to freeware utilities to protect yourself.)

This article is divided into four parts:-

PART I WHAT IS PHISING AND DETAILS ABOUT PHISHING.
PART II MYSPACE USERS BE WARNED.
PART III IMAGES OF SOME PHISHING SCAMS.
PART IV HOW TO PROTECT YOURSELF FROM PHISING.
PART V FREE UTILTIES TO KEEP YOURSELF SECURED.


PART I WHAT IS PHISHING AND DETAILS ABOUT PHISHING:-





Well to start with for those who are not very familiar with the term, phishing is a criminal activity to fraudulently acquire sensitive information, such as passwords and credit card details, by masquerading as a trustworthy person or business in an electronic communication. Phishing is typically carried out using email or an instant message, although phone contact has been used as well.

Phishing involves sending email messages that seem to come from trustworthy sources, such as banking entities, but attempt to harvest confidential user data. In order to do so, they usually include a link that, if accessed, takes the user to a fake website. By doing this, users believe they are interacting with a trustworthy website, enter the information requested, which finally ends up in the hands of the fraudster.

Some of the most common characteristics that these forged email messages present are:


  • Use of the names of existing companies. Instead of creating a company's website from scratch, fraudsters imitate the corporate image and website functionality of an existing company in order to further confuse recipients of the forged message.
  • Use of the name of a real company employee as the sender of the spoofed message. By doing so, if recipients attempt to confirm the authenticity of the message by calling the company, they will be assured that the person that acts as spokesman of the company does actually work for the company.
  • Web addresses that seem to be correct. Forged emails usually take users to websites that imitate the appearance of the company used as bait to harvest the information. In fact, both the contents and the web address (URL) are spoofed and simply imitate legitimate contents. What's more, legal information and other non-critical links could redirect trusting users to the real website.
  • Fear factor. The window of opportunity open to fraudsters is very short, as once the company is informed that its clients are targets of these techniques, the server that hosts the fake website and harvests the stolen information is shut down within a few days. Therefore, it is essential for fraudsters to obtain an immediate response from users. On most occasions, the best strategy is to threaten them with either financial loss or loss of the account itself if the instructions outlined in the forged email are not followed, which usually refer to new security measures recommended by the company.

In addition to obscuring the fraudulent URL in an apparently legitimate email message, this kind of malware also uses other more sophisticated techniques:


  • Man-in-the-middle. In this technique, the fraudster is located between the victim and the real website, acting as a proxy server. By doing so, he can listen to all communication between them. In order to be successful, fraudsters must be able to redirect victims to their own proxy, instead of to the real server. There are several methods, such as transparent proxies, DNS Cache Poisoning and URL obfuscation, among others.
  • Exploitation of Cross-Site Scripting vulnerabilities in a website, which allow a secure banking web page to be simulated, without users detecting any anomalies, neither in the web address nor in the security certificate displayed in the web browser.
  • Vulnerabilities in Internet Explorer, which by means of an exploit allow the web address that appears in the browser address bar to be spoofed. By doing so, while the web browser could be redirected to a fraudulent website, the address bar would display the trustworthy website URL. This technique also allows false pop-up windows to be opened when accessing legitimate websites.
  • Some attacks also use exploits hosted in malicious websites, which exploit vulnerabilities in Internet Explorer or the client operating system in order to download keylogger type Trojans, which will steal confidential user information.
  • Pharming is a much more sophisticated technique. It consists in modifying the contents of the DNS (Domain Name Server), either via the TCP/IP protocol settings or the lmhost file, which acts as a local cache of server names in order to redirect web browsers to forged websites instead of the legitimate ones, when the user attempts to access them. Furthermore, if the victim uses a proxy in order to remain anonymous while surfing the web, its DNS name resolution could also become affected, so that all the proxy users are redirected to the false server.

RECENT SURVEY

Accorindg to Zdnet the study, released on Monday, showed that the number of brands under attack from phishing was up 20 percent from June and 12 percent from the previous record in May. According to the study "In a year, the number of brands has more than doubled, illustrating that online criminals are simply not settling for the large, popular organizations and financial institutions,"

Dan Hubbard, vice president of security research at Websense, said in a statement. "The increase in the complexity of attacks goes hand-in-hand with the massive growth in phishing Web sites and the targeted, broad selection of brands that has followed."

The U.S. topped the list of countries hosting phishing sites, with 29.9 percent, followed by the Republic of Korea with 13.3 percent, China with 12 percent, France with 5.9 percent and Australia with 4.6 percent.
Attacks are getting more sophisticated, the group found, noting that a malicious site is now capable of placing a Trojan horse onto a system without user interaction. The Trojan involved, Web Attacker, is a Russian do-it-yourself toolkit sold for anywhere from $20 to $300.




PART II MYSPACE USERS BE WARNED




"Password-stealing MySpace log-in page removed"

Well that exactly was the heading of the Scmagazine article that appeared just two days ago.

Yes MySpace recently shut down a bogus profile page that was used to relay usernames and passwords to a remote server in France. The page was created using specially crafted HTML to eliminate the normal appearance of a user profile and instead resemble the real MySpace log-in page, according to internet monitoring firm Netcraft. Users would arrive at the page by following a phishing link. The fraudulent page was harvesting log-in details and communicating with a server in France, Paul Mutton, Netcraft's internet services developer, said Friday in a blog post.

With more than 100 million members and in the global top 10 of most visited websites, MySpace increasingly has become an attractive target for the malicious community, looking to take advantage of a young user set that is more trusting and less security minded than older generations.

Kevin Beecroft of Mashable labs in his very recent article says that MySpace Phishing Attack Appears on 3000 Pages. He goes on to say that a proportion of these pages are today active and will steal your email and password if you give it to them. The fake login pages are very convincing and even fooled Firefox into automatically filling in his credentials. Even cautious Internet users could get caught off guard by this trick.

You can also check out the netcraft page where you can see the illustrations on how the myspace login page was compromised.

I have given some tips for myspace.com users too to protect themselves under the "How to protect yourself from phishing" section.





PART III IMAGES OF SOME PHISHING SCAMS.







Above is a image from an email where Bank of America's name was used for the phishing attack. When the cursor was put on the hyperlink on which it says "To update your records click on the following link" it was clearly seen that link directs to a lycos.fr page and not Bank of America. That is why it is said always check for the url before u even login, whether it is yahoo account or bank account or whatever. And moreover banks will never ask you to fill in your personal data online.

Here is an example of phishing using paypal as the weapon.

Here is yet another example of how scare tactics are used to prompt the user to click on the link.






PART IV HOW TO PROTECT YOURSELF FROM PHISING.





Keep Antivirus Up To Date-
One of the most important things you can do to avoid phishing attacks is to keep your antivirus software up to date because most antivirus vendors have signatures that protect against some common technology exploits. This can prevent things such as a Trojan disguising your Web address bar or mimicking an https secure link. If your antivirus software is not up to date, you are usually more susceptible to attacks that can hijack your Web browser and put you at risk for phishing attacks.


Do Not Click On Hyperlinks In E-mails-
It is never a good idea to click on any hyperlink in an e-mail, especially from unknown sources. You never know where the link is going to really take you or whether it will trigger a malicious code. Some hyperlinks can take you to a fake HTML page that may try to scam you into typing sensitive information. If you really want to check out the link, manually retype it into a Web browser.


Take Advantage Of Anti-Spam Software-
Anti-spam software can help keep phishing attacks at a minimum. Many attacks come in the form of spam. By using anti-spam software, you can prevent most types of phishing attacks because the message will never end up in your mailbox.

Verify HTTPS (SSL)-
Whenever you are passing on sensitive information such as credit cards or bank information, make sure the address bar shows "https://" rather than just "http://" and that you have a secure lock icon at the bottom right hand corner of your Web browser. You can also double-click the lock to guarantee the third-party SSL certificate that provides the https service.

Many types of attacks are not encrypted but mimic an encrypted page. Always look to make sure the Web page is truly encrypted. The web address must begin with https:// and a little closed padlock must be displayed on the status bar of the browser.Double-click the padlock in order to view the digital certificate that confirms the website you are accessing is actually the one you expected.

Use Anti-Spyware Software-
Keep spyware down to a minimum by installing an active spyware solution and also scanning with a passive solution. If for some reason your browser is hijacked, anti-spyware software can often detect the problem and safely remove it.

Get Educated-
Educate yourself on how to prevent these types of attacks. A little research on the Internet may save you a great deal of pain if you are ever the victim of identity theft. You can report any suspicious activity to the FTC (in the U.S.). If you get spam that is phishing for information, forward it to spam@uce.gov. You can also file a phishing complaint at the "www.ftc.gov" (Federal Trade Commission). Another great resource is the FTC's identity theft page to learn how to minimize your risk of damage for ID theft. Visit the FTC's spam page to learn other ways to avoid e-mail scams and deal with deceptive spam.


Use The Microsoft Baseline Security Analyzer (MBSA)-
You can use the MBSA to make sure all of your patches are up to date. You can download this free tool from Microsoft's web site. By keeping your computer patched, you will protect your system against know exploits in Internet Explorer and Outlook (and Outlook Express) that can be used in phishing attacks.


Firewall-
Use a desktop (software) and network (hardware) firewall. On the desktop, you can use a software firewall or use Microsoft's built-in software firewall in Windows XP. The incorporation of a firewall can also prevent malicious code from entering your computer and hijacking your browser.

Use Backup System Images-
Keep a backup copy or image of all systems in case of foul play. You can then revert back to a pure system state if you suspect that a phishing attack, spyware, or malware has compromised the system.

Don't Enter Sensitive Or Financial Information Into Pop-up Windows-
A common phishing technique is to launch a bogus pop-up window when someone clicks on a link in a phishing e-mail message. This window may even be positioned directly over a window you trust. Even if the pop-up window looks official or claims to be secure, you should avoid entering sensitive information because there is no way to check the security certificate. Be sure to close pop-up windows by clicking on the X in the top-right corner. Clicking cancel may send you to another link or download malicious code.

Secure The Host File-
A hacker can compromise the hosts file on a desktop system and send a user to a fraudulent site. Configuring the host file to read-only may alleviate the problem, but complete protection will depend on having a good desktop firewall that protect against tampering by outside attackers and keep browsing safe.

Protect Against DNS Pharming Attacks-
This is a new type of phishing attack that doesn't spam you with e-mails but poisons your local DNS server to redirect your Web requests to a different Web site that looks similar to a company Web site (e.g. eBay or PayPal). For example, the user types in eBay's Web address but the poisoned DNS server redirects the user to a fraudulent site. This is what is considered new age phishing. This needs to be handled by an administrator who can use modern security techniques to lock down the company's DNS servers.

Always verify the information source -
Do not automatically reply to any email message that asks for your personal or financial information. If you feel uncertain about whether that company really needs the kind of information it is requesting, pick up the phone book and phone your usual contact, in order to check the information source.

Type the web address in your Internet browser yourself-
Instead of clicking on the links in the email message, type the web address (URL) in your browser, or use a previously defined bookmark. Even web addresses that look correct in the email message can be the path to a fraudulent website.

Reinforce your security-
Users making transactions through the Internet should install security suites that block this kind of threat on their computers, apply the latest security patches available through their usual vendors and make sure that they are operating in secure mode using digital certificates or communication protocols such as HTTPS.

Regularly check your accounts-

Monthly statements are particularly useful to detect irregular transfers and transactions, both operations that you did not make but are reflected in the statement and operations made online but not reflected in the statement.

Myspace users:-

With the recent phishing attacks on myspace.com it is always safe now that you log in through your own page. Don't go to someone else's page and then log in through that page when it says "You need to log in to do that" Instead always take the safer path of logging first directly through your own account.

And never use a password and email which you use for your financial or very personal reasons on myspace. Use a separate email account and a unique password only for myspace.

Also MySpace.com suggests on its site that users do not reply to email or pop-up messages that seek personal or financial information, or click on links found in such messages.

These tips should be followed not just for myspace but for other popular sites too. Combine these tips with all the other tips mentioned above and you will be safe.





PART V FREE UTILTIES TO KEEP YOURSELF SECURED:-






Go here to get some of the best free utilities to protect yourself. Check out the utilities under the "Essential Downloads" to get some of the best spyware/adware removal tools and anti-virus and internet privacy tools. I personally use some of these free stuffs simply because they are just too good even if they are free. Also Check out the most popular section and the Editor's pick section. There are some awesome free tools there. The best free utilities like the adware/spyware removable tool Spybot Search and Destroy, Zone Alarm firewall and AVG anti-virus are all there among all the other things you need to protect yourself. Take a good look there. Basis 5 things you need are:- An Antivirus, A firewall, An Antispyware (ideally two), Anti Trojan, And an Anti Rootkit.

Use the netcraft toolbar if you like to. Check it out here. It was netcraft tool bar user that detected one of the fake pages at myspace recently and reported it to netcraft.

Related Reading:-
27 steps to prevent Virus.
Best free Antivirus softwares.
Great free tool to detect spywares.
Keeping your password safe and related tools.
What are root kits and Rootkit detecting sofwares.


(This article was written based on information from the following sources and from my own experience)
Credits:-
Zdnet.
Whitecanyon.
Securityfocus.
Wikipedia.
Security.yahoo.
Kevin Beecroft of mashable labs.
Scmagazine.
Pandasoftware.
Netcraft.

Tuesday, October 31, 2006

Microsoft and Secunia at it again. And FF 2 too affected?



It seems that Microsoft and Secunia is at it again. This is the second debate between the security company and Microsoft since the launch of Internet explorer 7. The first one was the for the mhtml re-direction information disclosure security flaw when Microsoft said it was a outlook express problem and Secunia pinning it on Explorer 7 saying since the browser paves way for it, it has to be held reponsible. Read about it here.

And now with the latest threat, the window injection security flaw they are at it again. Secunia says that it is a
vulnerability and that Firefox and Opera treated it as a vulnerability and already patched it within two months of this being reported in 2004 but Microsoft just didn't treat it as one and left it upatched and let it continue in explorer 7.

In the Microsoft Security Response blog they say that it is not a vulnerability. This is an excerpt from their response in the blog:-
"Like we always do, we investigated that claim thoroughly in 2004. We found that in all cases, for this to represent a threat for phishing or spoofing attacks, a user would have to decide to trust the authenticity of the page without verifying the page’s address (because there was no address bar) and without verifying an SSL connection (like we recommend on our website).

In other words, the scenario requires that you intentionally not use the security features specifically put in place to help protect against phishing and spoofing attacks. Because of that, we said in 2004 that this issue doesn’t represent a security vulnerability as we have defined it on our website.

Now, that said, we take all reports seriously even when they’re not security vulnerabilities. In this case, we did look at the scenario in question and asked ourselves what we could do to help improve our anti-phishing and anti-spoofing features so that customers can better protect themselves. We decided that one thing we could do was to add a feature to IE 7 where it always shows the actual URL of the web page, even in pop-up windows. So we added a pop-up window address bar, enabling users to more accurately make a trust decision."

Secunia's response to this was "Today, in 2006 they (Microsoft) still say this isn't a vulnerability - despite the fact that they intended to protect users against this in IE7 by disabling the "Navigate sub-frames across different domains" "functionality" by default."

Secunia has given anillustration on how the latest security flaw (window injection vulnerability) can be misused by a malicious site and why it treats it as a security flaw and how even the newly added and
always visible address bar in Internet explorer 7 does not mitigate this.

Now what I wonder is when Secunia says that Firefox and Opera took care of this issue within two months of this security flaw reported across multiple browsers way back in 2004 why only Microsoft has dealt with it in a different way. May be like they say they don't consider this as a security flaw or vulnerability.

And yesterday I read on Betanews that Firefox 2 has also been detected with the same security flaw. When it has been said that both Opera and Firefox took care of this issue way back then how come it has cropped up again in Firefox 2. Betanews says they conducted some tests on Firefox 2 too and it has some issues with this.

So far I have not seen Mozilla saying anything about this officially. I would like to know from Betanews that whether they got any response from Firefox 2. I have already posted about this in the mozilla forum. May be we can get an answer there.


Monday, October 30, 2006

Yet another security flaw spotted in IE 7 today.



Secunia has confirmed today that a window injection vulnerability has been detected in internet explorer 7. This is now the third vulnerability that has been spotted in IE 7 the first two being the Internet Explorer 7 "mhtml:" Redirection Information Disclosure and the Popup Address Bar Spoofing Weakness. Among these two the mhtml vulnerabilty as I had mentioned in my earlier article lead to a debate between Microsoft and Secunia as Microsoft said that since the actual problem for the mhtml vulnerability lies with outlook express it cannot be attributed to Explorer 7 and Secunia saying that the vulnerability is fully exploitable via IE, which is the primary attack vector, if not the only attack vector.

Now this security flaw on IE 7 detected by Secunia and released today is termed as moderately critical where as the other two were termed as just moderate. This security flaw can be exploited by malicious people to spoof the content of websites.

According to the report a website can inject content into another site's window if the target name of the window is known. This can e.g. be exploited by a malicious website to spoof the content of a pop-up window opened on a trusted website.

The vulnerability has been confirmed on a fully patched system with Internet Explorer 7.0 and Microsoft Windows XP SP2.

What I find really amazing about this is that this vulnerability was actually reported on 2004-12-08 by secunia for explorer 5.01, 5.5 and version 6.x So does this mean that this issue was not addressed and patched earlier by Microsoft in their earlier versions and that it has just been passed onto the version 7?

And another thing to be noticed is that this same window injection vulnerability was detected in many other browsers including firefox, Opera, Netscape etc:- in 2004. It was an issue for multiple browsers at that time. But so far I have not seen this issue mentioned by Secunia for the Firefox 2. So it makes me wonder whether Mozilla has patched this in Firefox but Microsoft simply left it out. Or may be Secunia has not yet tested this security flaw on Firefox 2. I mean if this issue which was earlier detected in 2004 has been patched in Firefox and other browsers but hasn't been patched only in Explorer then that is really something very unpleasently surprising.

We have to wait and see the Microsoft's response to this and also let us see whether this same problem exists with Firefox too.

Secunia's today's report.
Secunia's report in 2004.

UPDATE: Just after I finished this article it has been confirmed now that Fire Fox 2 is also facing the same security flaw. I was in the right direction when I mentioned that since it was a mulitple browser problem including Opera, Firefox, Netscape and Explorer originally reported in 2004 by Secunia it could mean that those browsers could be affected too. I am waiting to see what the other browsers too have to say.

You can read the latest news on Firefox too being affected by this here.

Friday, October 27, 2006

All IE 7 and Firefox 2 Vulnerabilities as of date.


INTERNET EXPLORER 7 ISSUES.

  • Internet Explorer 7 "mhtml:" Redirection Information Disclosure
First one that stands out is the outlook express vulnerability which uses IE7. It was traced back to nov.2003. So that means it is an old issue which has still not been adressed properly. The flaw actually lies in Outlook Express. Microsoft is still investigating the issue. Even though the flaw lies with the outlook express and the older versions of explorer like IE6 have been facing this issue a lot of attention has been drawn to these with the launch of IE7.

The vulnerability apparently involves a very simple trick where a call to a MIME HTML, or MHTML, resource can trigger the running of an executable file, even with high-level security settings. Secunia rates this problem as "less critical," perhaps mainly because this is a trigger mechanism rather than a full-scale virus or Trojan. Conceivably, however, it could be utilized by malicious users within a more complete malware setup. The impact is exposure of sensitive information according to Secunia. The vulnerability is caused due to an error in the handling of redirections for URLs with the "mhtml:" URI handler. This can be exploited to access documents served from another web site.

Microsoft responded to reports of the first exploit affecting Internet Explorer 7, which cropped up less than 24 hours after the browser's official launch. Christopher Budd from Microsoft's Security Response Center says the flaw lies not in IE7, but in an Outlook Express component.

Secunia has confirmed the vulnerability on a fully patched system with Internet Explorer 7.0 and Microsoft Windows XP SP2. Other versions may also be affected.

Even if this vulnerability is not directly related to IE7, the security company Secunia does not exclude IE7. Secunia CTO Thomas Kristensen held true to his company's stance that the exploit is attributable to Microsoft's new Web browser. He says that "Microsoft claims the recent IE7 vulnerability is an Outlook Express vulnerability," begins Kristensen's statement to us. "This may be true, from an organizational point of view within Microsoft. However, the vulnerability is fully exploitable via IE, which is the primary attack vector, if not the only attack vector."


  • Internet Explorer 7 Popup Address Bar Spoofing Weakness

This spoofing issue uncovered by an anonymous discloser which was tested by the security firm Secunia and is categorized as less critical appears to be the first genuine, publicly disclosed flaw in the new Microsoft browser. The outlook express issue is a different story since according to microsoft it is not an IE7 vulnerability and as far as Secunia goes since the vulnerability is fully exploitable via IE they won't exclude IE7 from that. SO that issue is entirely upto to the users to whether take it as IE vulnerability or the outlook one. But this one without doubt points directly to IE 7.

The issue occurs in popup windows. It is possible to display a somewhat spoofed address bar, the company said. According to Secunia the problem is that it's possible to display a popup with a somewhat spoofed address bar where a number of special characters have been appended to the URL. This makes it possible to only display a part of the address bar, which may trick users into performing certain unintended actions.An attacker could exploit this weakness to trick people into believing they are on a trusted Web site when in fact they are viewing a malicious page, Secunia said in an alert.

According to an email statement issued by a Microsoft representative to Zdnet the problem lies in the way Web addresses are displayed in the IE 7 address bar. An attacker could exploit the issue by tricking a user to click on a specially formatted link, the representative said.

However, an attack won't work if a Web site is known to be part of a phishing scam since the IE 7 phishing shield will identify such sites and warn the user. And so far Microsoft is not aware of any attacks that actually use the reported vulnerability, the company said.

This issue is currently under investigation by Microsoft and they have said that once it is completed they will take the appropriate steps to protect it's customers.

However George Ou in his blog gives a solution..he says "The address bar spoofing weakness against IE7 happens when a small popup is spawned and a URL shows up with trailing spaces. The trailing spaces pushed the URL to the left and partially out of site which hides the actual domain and shows you a fake domain. If you click anywhere on the popup page or click on the background window, the left side of the URL and the actual domain name is revealed but the initial spoofing condition might be useful in a phishing attack to the unsuspecting user. This condition is repeatable when you click on the address bar and that is probably what is being exploited since the popup first shows up with the address bar in focus. The possible solution to this would be to strip out the trailing spaces (since spaces aren't supported in URLs anyways) when popping up browser windows or not allow it to start with the address bar in focus."

I hope they do take the necessary actions before these less critical issues are massively exploited by some of the malicious minds out there. No wonder it is reported that microsoft has chided the anonymous disclosure because it prefers that security issues be disclosed privately so it can repair them before they get publicly known.

Outlook express issue sources:-
Betanews.
Secunia's related info.
Zdnet's related article.

Spoofing issue
sources:-
Zdnet's related article.
Secunia's related info.
George Ou's article

Also talking about IE7 I thought I would share this article titled "Is Internet Explorer 7 spying on me?" which i saw at the DCoT blog. Take a look at it here. It is interesting to read not just the article but there is a good discussion going about it in the comments area. As far as the debate about the browsers go I personally feel that both has it's own advantages and I use both.





FIRE FOX ISSUES

Now on the other end Mozilla's Firefox is having it's share of security issues and along with the glory it's getting tainted with it's own security issues. Here goes:-

  • Issues brought up by Bugtraq:

First issue was again surprisingly in this case had something to do with mails. Bug tracking mailing lists have been talking about a flaw affecting the just released Firefox 2. Even though Bugtraq called the condition critical Mozilla's security chief Window Snyder insisted the report is wrong and that the problem was already "fixed". And Secunia which has reported both the IE7 issues has listed this issue as affected by zero Secunia advisiories.

Actually it all started when Bugtraq mailing list reported that the issue, labeled "critical" by Mozilla, resurfaced in Firefox 2. But Mozilla says the Firefox bug was considered critical and "fixed" last month.

Crash condition:

Window Snyder admitted a crash condition remained. "The exploitable issues are fixed. There is a crash, but it is a denial of service," Snyder said. "We're going to look at it and make sure there is really nothing there."

George Ou says in his zdnet blog that "any kind of flaw that can cause an application to crash has to be alarming because it might be exploitable. It sounds like some modifications were made to make the exploit condition less exploitable but a crash condition still exists." And he goes on "this may or may not still be a serious flaw since the exploit still crashes Firefox 2.0. At some point Mozilla would have to admit this is a problem and really fix it so that the browser doesn't crash at all."

Cyberscams issue:

Another report on the Full Disclosure mailing list suggested that there is a flaw in Firefox 2 that could be exploited to aid in cyberscams. The report included some computer code, but not enough for Mozilla to determine whether there is a problem, Snyder said.

"We don't have enough information to identify it. If we get more information, then we will investigate," she said.

Two old issues still unpatched on FireFox:

There are still two 2 rated vulnerability (rated by Secunia out of 5 which is a similar rating to the two issues in IE7) that has still not been patched by Mozilla. They are:-

1.Mozilla / Mozilla Firefox Cross-Domain Cookie Injection Vulnerability
2.Mozilla / Mozilla Firefox Apple Java Plugin Tab Spoofing Vulnerability

Check them out here. vulnerability 1 vulnerability 2



Sources:
Mozilla's info on bug tracking issue fixed last month.
Secunia's info on bug tracking issue.
Zdnet related article.

George Ou's article about media bias.


So it seems the both IE7 and Firefox are having a common issue when it comes to phising.

Talking about the phising issue here is another article that talks about how it has grown and the number of brands under attack from phishing was up 20 percent from June and 12 percent from the previous record in May. An interesting thing to note from the article is that "The survey found a large increase in traffic redirectors, and DNS redirectors in particular. These modify a system's DNS settings to direct some or all DNS lookups to a fraudulent DNS server capable of directing users to fraudulent sites when particular addresses are entered."

Read more from the survey and news about phising here.








Wednesday, October 25, 2006

Fire fox version 2 . Tweak it up baby with this guide.


Folks,
This is a must read for all those firefox fans out there. As you all know fire fox just recently released its version 2 (if you did not know it is high time you get out from under that rock). I just came across this tweaking guide for the browser written by Koroush Ghazi. It is a very well laid out guide. As he calls it it's a true objective TweakGuides tweak guide, and not a gushing ad for a free web browser.

I am was so happy when firefox released it latest version and now I guess with this guide we already have something to play around with the new browser toy for the big boys. Since he has a big intro and all I suggest you start reading from page 6 onwards because the basic tips and tweaks starts from there and the advanced tweaking part starts from page 8.

Digg it or you can go directly to the guide here.

More adsense and other useful tips from the blogosphere.


Yesterday I had posted about adsense tips from the google adsense expert and today I had spent more time at the google adsense blog and I thought I wld share some of the information I found useful. Also at the bottom of the article I have given links to other useful related resources I find useful for people who are planning to make blogging their profession and earn some money out of it with ofcourse the primary focus being on providing people with good articles.

GENERAL ( For any website)

  • Try using large Rectangle Ad (336 x 280) or the the 728x90 Leaderboard, 160x600 Wide Skyscraper, and 300x250 Medium Rectangle. Try to pick the three among this which you think would best suit your site.

  • Increasing ad unit presence on your site and placing ads 'above the fold' (i.e., the area visible on a page without scrolling down) can enhance the likelihood that people will see and respond to your ads.

  • Article based pages are an exception, as placing ads directly below an article can lead to a greater number of readers clicking through.

  • Embed the ads. If you wanna know what that means check it out here.

  • Ads placed near rich content and navigational aids usually do well because users are focused on those areas of a page.

  • Google strongly recommends putting your users first when deciding on ad placement.

  • On pages where users are typically focused on reading an article, ads placed directly below the end of the editorial content tend to perform very well. It's almost as if users finish reading and ask themselves, "What can I do next?" Precisely targeted ads can answer that question for them.

Three more tips specific to blogs:-

  • Blend your ad units into the background of your blog. Choose a bold color for the ad title to help draw attention to your ads, then make sure that the background and borders of your ads are the same color as the background of the area where the ad is placed.

  • In general, wider ad formats tend to be more reader-friendly. Placing an ad unit after the first post will likely catch your readers' attention. Take a look at the Google sample implementations to get some ideas.

  • Also, consider placing a Skyscraper (120x600) or vertical link unit on the right side of your blog. If you're using Blogger, you can find instructions on placing AdSense code in your blog's sidebar at blogger.com

The sciencedaily.com website had some great success with adsense and here is how it happened:-

According to Hogan the person who set up the website "It was easy to get started, even with setting up sophisticated ad filtering, but the real value of AdSense was apparent once the ads began running." Using AdSense for content, Hogan matched his own site's color scheme and content, maintaining a presence as a serious science daily. "The ads really match our articles," he says. "For visitors, the AdSense ads are a useful extension of our content. That's what's great about Google AdSense—the ads are appealing and appropriate." Read the article here.


The effectiveness of Hogan's cost-per-click ads on AdSense is four to five times that of the other ad networks.
Based on Google's recommendations and his own testing, he moved ads from the bottom of pages to the directly below articles. Average eCPM immediately jumped by 10 percent.

"AdSense for search performs extremely well. It gives us an exceptional click-through rate of 10 percent and generates 10 to 20 times the clicks of a job search service we've tried," Hogan says. "Plus, by using Google site search, I can now drive traffic to content on ScienceDaily that visitors might not find otherwise."


Content.

But just like google says you should remember that it is the people first and hence the content. And also a lot depends on your website's layout. Basically the ads must blend with your website's design and yet stand out. But if there is no good content it will be of no use. The ads should be an useful extension of the content not the other way round. If you don't have a passion for what you write and say it will certainly show.

If you need some tips about writing you can find some at these folksonomy and problogger pages.

Also at stevepavlina's blog he has written a very big article about how one should approach if you are thinking about making blogging your profession and trying to make some money out of it. You can read the article right here.

As I learn things I would like to share and I hope this helps the people who haven't been able to keep track of this things due to some reason. Also it is always good to go around checking the established websites and blogs and analyse how they have structured it.

Google