Friday, November 03, 2006

Test your firewall, browser and your internet or site speed.

You will find three sections in this article:-

SECTION I INTERNET CONNECTION OR WEBSITE SPEED TESTS.
SECTION II FIREWALL TEST.
SECTION II BROWSER TEST.


____________________________________________________________________________________
SECTION I INTERNET CONNECTION OR WEBSITE SPEED TESTS.
____________________________________________________________________________________

Well there are other sites that lets you check your Internet connection speed but I personally prefer these two sites because they are very easy to use and they each use different methods so that you can use both of these sites to have your connection speed tested in two different ways. Read on.


Mcafee speedometer.

What the Mcafee speed test does is that it sends a 150KB file to your computer and records the amount of time it took for your computer to receive it. Click on the "test your speed" link in the page and after a while the speedometer needle shows your speed and you can also see your speed on the digital counter below the needle.


Numion Internet speed tester.

Go to the page and scroll down and hit on the start button. check on the box against your country and language (usually by default it will be checked appropriately) before you do that.

What is different and I like about this test is that it simulates normal surfing behaviour by fetching small images (logo's) from the websites, and is heavily influenced by distance and latency. The average of all the micro-measurements is a very good (quantitative) representation of the (subjective) Internet speed as you experience it.

The other two handy tools you can see in the numion site are:-

Sitespeed.
Sitespeed lets you measure the speed of your website. If you have a website this is a handy tool. It tells you the speed of your website and displays the results in 7 comprehensive graphs. And it also provides you with details about how long do your visitors have to wait, whether your web server is becoming slower, whether your pages too big and also whether your website is fast even for remote visitors.

Stopwatch.
This tool can be used to measure the time it takes to load a particular web page of your choice. This is very interesting especially if you have some personal pages like one on myspace. I checked my myspace page and it was cool to see that it takes 10 secs to load. With some of your heavy duty graphics and stuff on your myspace page it would be interesting to watch the seconds flow by.

The beauty is that all these are free. So just try it.

____________________________________________________________________________________

SECTION II FIREWALL TEST
____________________________________________________________________________________


Go the GRC probe test page first.

Once you get to the page click on proceed. And when you get to the next page you will see the following options:-


From the list you can choose which kind of scan you want to do. As you can see you have different options:-

1. File sharing:- If you want to check whether your personal computer is working as an Internet server without your knowledge nor your permission and that whether it is serving up all or many of your personal files for reading, writing, modification and even deletion by anyone, anywhere, on the Internet you should click on this option.

This will scan port 139 and also try to connect with NetBios to your pC and if the scan says that it cannot connect to either then it means your firewall is doing a good job.

2.Common parts:- This helps you to do a quick check up on the most common ports used for services like HTTP, HTTPS , RPC, NNTP etc:- If the scan gives you a stealth status that is best you can get. If any hacker doing a port scan looking for this ports to be open and your firewall has stealthed all these ports it simply means that the port scanner does not even know this ports exist on your Ip address. A good firewall always is in stealth mode.

3.All service ports:-Use this one if you want to probe all the service ports and not just the common ports. The scanner scans all these ports in a grid and if all the grids are in green then it means all these ports are stealthed. The scanner looks for open, closed and stealthed ports. If your firewall does not stealth the ports at least it should have closed the ports.

But stealth mode is what good firewalls are capable of doing so that any one using a port scanner with a malicious intent never even know such a port exists in your machine while the port scanning is on.

4.Messenger spam:-
You guys probably know the problem created by Microsoft's various servers that are open and running, by default, on port 135. So this test lets you verify that Windows Messenger spam can not reach the system you are currently using.

You will see the default message written on the space but if you want to write something else do that and then hit the "Spam me with this note" button. If your Internet service provider (ISP), personal computer system, personal firewall, NAT router, or network is not currently blocking UDP traffic into port 135, and if you are running a version of Windows with the Windows Messenger Internet server enabled and listening for incoming UDP messages on port 135, a number of "Messenger Service" pop-up dialog boxes will immediately appear on your system's screen.

5.User specified Custom port Probe:- If you want to probe only a particular port then you can type that port number into the space provided and then hit this button and it will only scan that particular port.

6. Look up specific port information:- Hitting this button does not probe any ports. This button can used if you want to know the information regarding a particular port. If you want to know what service a port stands for and what protocol it uses and things like that you can type the port number in the space and then hit the button to learn the information about that particular port.

Remember that a good firewall will always be in stealth mode.

If the firewall is good and in stealth mode then not a single packet will be received from your system while the GRC probe test is being done. Your system will ignore and refuse to reply to repeated Pings (ICMP Echo Requests). This means any hacker who uses the port scanner, does not even know that your machine even exists on the Internet. Some personal firewalls or security systems expose their users by attempting to "counter-probe the prober", thus revealing themselves. And that means the firewall lets your system to be advertised on the net which is not a good thing at all except for the person using the port scanner.

____________________________________________________________________________________
SECTION III BROWSER TEST
____________________________________________________________________________________
The "Browser headers" button which you see among the other buttons (which you must have already seen in the screen shot of the GRC probe test page I have given above) can be used to find out what all information your browser is sending. Since it is not a firewall test and totally a browser test I have categorized it under this section.

Once you hit this button it will take you to a page which shows all the header information your browser is giving out to the world outside.

This page lets you to determine exactly what identifying information is being sent from your browser when it asks for any object from an Internet web server. If you choose to experiment with any of the third-party proxy and cookie filters, this page allows you to easily perform configuration experiments and to quickly verify that filtering is present and functioning as you expect and intend.

Once you hit the browser header button and get to the page you will see a whole lot of information there. You can use the "Feed browser this cookie" button to learn exactly how they operate by filling-in a non-blank name and value pair and also the "switch page to non-secure" button if you want to just check more details and do some experiments.

As many of you know your browser provides a whole lot of information to sites you visit and also to the third parties. With javascript and active x and cookies enabled it provides a whole lot of information. Even the pages you last visited or the page you came from is all know if the referrer logging is on.

Unfortunately with a million websites popping up each day it is hard to keep track of which one is good and which one is malicious. An unsuspecting user can just follow a link and land up in a site that uses malicious scripts and snooping techniques. The only way to work around this is by disabling the java scripts and active x and cookies before you visit an unfamiliar website.

You might be also interested to read about the firewall leak testing tool.

Also to be on the safer side read the article I wrote about phishing attacks. As the saying goes....a stitch in time saves nine.

Wednesday, November 01, 2006

Everything you want to know about Phishing attacks.

(If you are interested in reading only about how to protect yourself from phishing, then go part IV of this article where it is mentioned "How to protect yourself from phising." It also includes some tips for Myspace users. And, Part V of this article has links to freeware utilities to protect yourself.)

This article is divided into four parts:-

PART I WHAT IS PHISING AND DETAILS ABOUT PHISHING.
PART II MYSPACE USERS BE WARNED.
PART III IMAGES OF SOME PHISHING SCAMS.
PART IV HOW TO PROTECT YOURSELF FROM PHISING.
PART V FREE UTILTIES TO KEEP YOURSELF SECURED.


PART I WHAT IS PHISHING AND DETAILS ABOUT PHISHING:-





Well to start with for those who are not very familiar with the term, phishing is a criminal activity to fraudulently acquire sensitive information, such as passwords and credit card details, by masquerading as a trustworthy person or business in an electronic communication. Phishing is typically carried out using email or an instant message, although phone contact has been used as well.

Phishing involves sending email messages that seem to come from trustworthy sources, such as banking entities, but attempt to harvest confidential user data. In order to do so, they usually include a link that, if accessed, takes the user to a fake website. By doing this, users believe they are interacting with a trustworthy website, enter the information requested, which finally ends up in the hands of the fraudster.

Some of the most common characteristics that these forged email messages present are:


  • Use of the names of existing companies. Instead of creating a company's website from scratch, fraudsters imitate the corporate image and website functionality of an existing company in order to further confuse recipients of the forged message.
  • Use of the name of a real company employee as the sender of the spoofed message. By doing so, if recipients attempt to confirm the authenticity of the message by calling the company, they will be assured that the person that acts as spokesman of the company does actually work for the company.
  • Web addresses that seem to be correct. Forged emails usually take users to websites that imitate the appearance of the company used as bait to harvest the information. In fact, both the contents and the web address (URL) are spoofed and simply imitate legitimate contents. What's more, legal information and other non-critical links could redirect trusting users to the real website.
  • Fear factor. The window of opportunity open to fraudsters is very short, as once the company is informed that its clients are targets of these techniques, the server that hosts the fake website and harvests the stolen information is shut down within a few days. Therefore, it is essential for fraudsters to obtain an immediate response from users. On most occasions, the best strategy is to threaten them with either financial loss or loss of the account itself if the instructions outlined in the forged email are not followed, which usually refer to new security measures recommended by the company.

In addition to obscuring the fraudulent URL in an apparently legitimate email message, this kind of malware also uses other more sophisticated techniques:


  • Man-in-the-middle. In this technique, the fraudster is located between the victim and the real website, acting as a proxy server. By doing so, he can listen to all communication between them. In order to be successful, fraudsters must be able to redirect victims to their own proxy, instead of to the real server. There are several methods, such as transparent proxies, DNS Cache Poisoning and URL obfuscation, among others.
  • Exploitation of Cross-Site Scripting vulnerabilities in a website, which allow a secure banking web page to be simulated, without users detecting any anomalies, neither in the web address nor in the security certificate displayed in the web browser.
  • Vulnerabilities in Internet Explorer, which by means of an exploit allow the web address that appears in the browser address bar to be spoofed. By doing so, while the web browser could be redirected to a fraudulent website, the address bar would display the trustworthy website URL. This technique also allows false pop-up windows to be opened when accessing legitimate websites.
  • Some attacks also use exploits hosted in malicious websites, which exploit vulnerabilities in Internet Explorer or the client operating system in order to download keylogger type Trojans, which will steal confidential user information.
  • Pharming is a much more sophisticated technique. It consists in modifying the contents of the DNS (Domain Name Server), either via the TCP/IP protocol settings or the lmhost file, which acts as a local cache of server names in order to redirect web browsers to forged websites instead of the legitimate ones, when the user attempts to access them. Furthermore, if the victim uses a proxy in order to remain anonymous while surfing the web, its DNS name resolution could also become affected, so that all the proxy users are redirected to the false server.

RECENT SURVEY

Accorindg to Zdnet the study, released on Monday, showed that the number of brands under attack from phishing was up 20 percent from June and 12 percent from the previous record in May. According to the study "In a year, the number of brands has more than doubled, illustrating that online criminals are simply not settling for the large, popular organizations and financial institutions,"

Dan Hubbard, vice president of security research at Websense, said in a statement. "The increase in the complexity of attacks goes hand-in-hand with the massive growth in phishing Web sites and the targeted, broad selection of brands that has followed."

The U.S. topped the list of countries hosting phishing sites, with 29.9 percent, followed by the Republic of Korea with 13.3 percent, China with 12 percent, France with 5.9 percent and Australia with 4.6 percent.
Attacks are getting more sophisticated, the group found, noting that a malicious site is now capable of placing a Trojan horse onto a system without user interaction. The Trojan involved, Web Attacker, is a Russian do-it-yourself toolkit sold for anywhere from $20 to $300.




PART II MYSPACE USERS BE WARNED




"Password-stealing MySpace log-in page removed"

Well that exactly was the heading of the Scmagazine article that appeared just two days ago.

Yes MySpace recently shut down a bogus profile page that was used to relay usernames and passwords to a remote server in France. The page was created using specially crafted HTML to eliminate the normal appearance of a user profile and instead resemble the real MySpace log-in page, according to internet monitoring firm Netcraft. Users would arrive at the page by following a phishing link. The fraudulent page was harvesting log-in details and communicating with a server in France, Paul Mutton, Netcraft's internet services developer, said Friday in a blog post.

With more than 100 million members and in the global top 10 of most visited websites, MySpace increasingly has become an attractive target for the malicious community, looking to take advantage of a young user set that is more trusting and less security minded than older generations.

Kevin Beecroft of Mashable labs in his very recent article says that MySpace Phishing Attack Appears on 3000 Pages. He goes on to say that a proportion of these pages are today active and will steal your email and password if you give it to them. The fake login pages are very convincing and even fooled Firefox into automatically filling in his credentials. Even cautious Internet users could get caught off guard by this trick.

You can also check out the netcraft page where you can see the illustrations on how the myspace login page was compromised.

I have given some tips for myspace.com users too to protect themselves under the "How to protect yourself from phishing" section.





PART III IMAGES OF SOME PHISHING SCAMS.







Above is a image from an email where Bank of America's name was used for the phishing attack. When the cursor was put on the hyperlink on which it says "To update your records click on the following link" it was clearly seen that link directs to a lycos.fr page and not Bank of America. That is why it is said always check for the url before u even login, whether it is yahoo account or bank account or whatever. And moreover banks will never ask you to fill in your personal data online.

Here is an example of phishing using paypal as the weapon.

Here is yet another example of how scare tactics are used to prompt the user to click on the link.






PART IV HOW TO PROTECT YOURSELF FROM PHISING.





Keep Antivirus Up To Date-
One of the most important things you can do to avoid phishing attacks is to keep your antivirus software up to date because most antivirus vendors have signatures that protect against some common technology exploits. This can prevent things such as a Trojan disguising your Web address bar or mimicking an https secure link. If your antivirus software is not up to date, you are usually more susceptible to attacks that can hijack your Web browser and put you at risk for phishing attacks.


Do Not Click On Hyperlinks In E-mails-
It is never a good idea to click on any hyperlink in an e-mail, especially from unknown sources. You never know where the link is going to really take you or whether it will trigger a malicious code. Some hyperlinks can take you to a fake HTML page that may try to scam you into typing sensitive information. If you really want to check out the link, manually retype it into a Web browser.


Take Advantage Of Anti-Spam Software-
Anti-spam software can help keep phishing attacks at a minimum. Many attacks come in the form of spam. By using anti-spam software, you can prevent most types of phishing attacks because the message will never end up in your mailbox.

Verify HTTPS (SSL)-
Whenever you are passing on sensitive information such as credit cards or bank information, make sure the address bar shows "https://" rather than just "http://" and that you have a secure lock icon at the bottom right hand corner of your Web browser. You can also double-click the lock to guarantee the third-party SSL certificate that provides the https service.

Many types of attacks are not encrypted but mimic an encrypted page. Always look to make sure the Web page is truly encrypted. The web address must begin with https:// and a little closed padlock must be displayed on the status bar of the browser.Double-click the padlock in order to view the digital certificate that confirms the website you are accessing is actually the one you expected.

Use Anti-Spyware Software-
Keep spyware down to a minimum by installing an active spyware solution and also scanning with a passive solution. If for some reason your browser is hijacked, anti-spyware software can often detect the problem and safely remove it.

Get Educated-
Educate yourself on how to prevent these types of attacks. A little research on the Internet may save you a great deal of pain if you are ever the victim of identity theft. You can report any suspicious activity to the FTC (in the U.S.). If you get spam that is phishing for information, forward it to spam@uce.gov. You can also file a phishing complaint at the "www.ftc.gov" (Federal Trade Commission). Another great resource is the FTC's identity theft page to learn how to minimize your risk of damage for ID theft. Visit the FTC's spam page to learn other ways to avoid e-mail scams and deal with deceptive spam.


Use The Microsoft Baseline Security Analyzer (MBSA)-
You can use the MBSA to make sure all of your patches are up to date. You can download this free tool from Microsoft's web site. By keeping your computer patched, you will protect your system against know exploits in Internet Explorer and Outlook (and Outlook Express) that can be used in phishing attacks.


Firewall-
Use a desktop (software) and network (hardware) firewall. On the desktop, you can use a software firewall or use Microsoft's built-in software firewall in Windows XP. The incorporation of a firewall can also prevent malicious code from entering your computer and hijacking your browser.

Use Backup System Images-
Keep a backup copy or image of all systems in case of foul play. You can then revert back to a pure system state if you suspect that a phishing attack, spyware, or malware has compromised the system.

Don't Enter Sensitive Or Financial Information Into Pop-up Windows-
A common phishing technique is to launch a bogus pop-up window when someone clicks on a link in a phishing e-mail message. This window may even be positioned directly over a window you trust. Even if the pop-up window looks official or claims to be secure, you should avoid entering sensitive information because there is no way to check the security certificate. Be sure to close pop-up windows by clicking on the X in the top-right corner. Clicking cancel may send you to another link or download malicious code.

Secure The Host File-
A hacker can compromise the hosts file on a desktop system and send a user to a fraudulent site. Configuring the host file to read-only may alleviate the problem, but complete protection will depend on having a good desktop firewall that protect against tampering by outside attackers and keep browsing safe.

Protect Against DNS Pharming Attacks-
This is a new type of phishing attack that doesn't spam you with e-mails but poisons your local DNS server to redirect your Web requests to a different Web site that looks similar to a company Web site (e.g. eBay or PayPal). For example, the user types in eBay's Web address but the poisoned DNS server redirects the user to a fraudulent site. This is what is considered new age phishing. This needs to be handled by an administrator who can use modern security techniques to lock down the company's DNS servers.

Always verify the information source -
Do not automatically reply to any email message that asks for your personal or financial information. If you feel uncertain about whether that company really needs the kind of information it is requesting, pick up the phone book and phone your usual contact, in order to check the information source.

Type the web address in your Internet browser yourself-
Instead of clicking on the links in the email message, type the web address (URL) in your browser, or use a previously defined bookmark. Even web addresses that look correct in the email message can be the path to a fraudulent website.

Reinforce your security-
Users making transactions through the Internet should install security suites that block this kind of threat on their computers, apply the latest security patches available through their usual vendors and make sure that they are operating in secure mode using digital certificates or communication protocols such as HTTPS.

Regularly check your accounts-

Monthly statements are particularly useful to detect irregular transfers and transactions, both operations that you did not make but are reflected in the statement and operations made online but not reflected in the statement.

Myspace users:-

With the recent phishing attacks on myspace.com it is always safe now that you log in through your own page. Don't go to someone else's page and then log in through that page when it says "You need to log in to do that" Instead always take the safer path of logging first directly through your own account.

And never use a password and email which you use for your financial or very personal reasons on myspace. Use a separate email account and a unique password only for myspace.

Also MySpace.com suggests on its site that users do not reply to email or pop-up messages that seek personal or financial information, or click on links found in such messages.

These tips should be followed not just for myspace but for other popular sites too. Combine these tips with all the other tips mentioned above and you will be safe.





PART V FREE UTILTIES TO KEEP YOURSELF SECURED:-






Go here to get some of the best free utilities to protect yourself. Check out the utilities under the "Essential Downloads" to get some of the best spyware/adware removal tools and anti-virus and internet privacy tools. I personally use some of these free stuffs simply because they are just too good even if they are free. Also Check out the most popular section and the Editor's pick section. There are some awesome free tools there. The best free utilities like the adware/spyware removable tool Spybot Search and Destroy, Zone Alarm firewall and AVG anti-virus are all there among all the other things you need to protect yourself. Take a good look there. Basis 5 things you need are:- An Antivirus, A firewall, An Antispyware (ideally two), Anti Trojan, And an Anti Rootkit.

Use the netcraft toolbar if you like to. Check it out here. It was netcraft tool bar user that detected one of the fake pages at myspace recently and reported it to netcraft.

Related Reading:-
27 steps to prevent Virus.
Best free Antivirus softwares.
Great free tool to detect spywares.
Keeping your password safe and related tools.
What are root kits and Rootkit detecting sofwares.


(This article was written based on information from the following sources and from my own experience)
Credits:-
Zdnet.
Whitecanyon.
Securityfocus.
Wikipedia.
Security.yahoo.
Kevin Beecroft of mashable labs.
Scmagazine.
Pandasoftware.
Netcraft.

Tuesday, October 31, 2006

Microsoft and Secunia at it again. And FF 2 too affected?



It seems that Microsoft and Secunia is at it again. This is the second debate between the security company and Microsoft since the launch of Internet explorer 7. The first one was the for the mhtml re-direction information disclosure security flaw when Microsoft said it was a outlook express problem and Secunia pinning it on Explorer 7 saying since the browser paves way for it, it has to be held reponsible. Read about it here.

And now with the latest threat, the window injection security flaw they are at it again. Secunia says that it is a
vulnerability and that Firefox and Opera treated it as a vulnerability and already patched it within two months of this being reported in 2004 but Microsoft just didn't treat it as one and left it upatched and let it continue in explorer 7.

In the Microsoft Security Response blog they say that it is not a vulnerability. This is an excerpt from their response in the blog:-
"Like we always do, we investigated that claim thoroughly in 2004. We found that in all cases, for this to represent a threat for phishing or spoofing attacks, a user would have to decide to trust the authenticity of the page without verifying the page’s address (because there was no address bar) and without verifying an SSL connection (like we recommend on our website).

In other words, the scenario requires that you intentionally not use the security features specifically put in place to help protect against phishing and spoofing attacks. Because of that, we said in 2004 that this issue doesn’t represent a security vulnerability as we have defined it on our website.

Now, that said, we take all reports seriously even when they’re not security vulnerabilities. In this case, we did look at the scenario in question and asked ourselves what we could do to help improve our anti-phishing and anti-spoofing features so that customers can better protect themselves. We decided that one thing we could do was to add a feature to IE 7 where it always shows the actual URL of the web page, even in pop-up windows. So we added a pop-up window address bar, enabling users to more accurately make a trust decision."

Secunia's response to this was "Today, in 2006 they (Microsoft) still say this isn't a vulnerability - despite the fact that they intended to protect users against this in IE7 by disabling the "Navigate sub-frames across different domains" "functionality" by default."

Secunia has given anillustration on how the latest security flaw (window injection vulnerability) can be misused by a malicious site and why it treats it as a security flaw and how even the newly added and
always visible address bar in Internet explorer 7 does not mitigate this.

Now what I wonder is when Secunia says that Firefox and Opera took care of this issue within two months of this security flaw reported across multiple browsers way back in 2004 why only Microsoft has dealt with it in a different way. May be like they say they don't consider this as a security flaw or vulnerability.

And yesterday I read on Betanews that Firefox 2 has also been detected with the same security flaw. When it has been said that both Opera and Firefox took care of this issue way back then how come it has cropped up again in Firefox 2. Betanews says they conducted some tests on Firefox 2 too and it has some issues with this.

So far I have not seen Mozilla saying anything about this officially. I would like to know from Betanews that whether they got any response from Firefox 2. I have already posted about this in the mozilla forum. May be we can get an answer there.


Monday, October 30, 2006

Yet another security flaw spotted in IE 7 today.



Secunia has confirmed today that a window injection vulnerability has been detected in internet explorer 7. This is now the third vulnerability that has been spotted in IE 7 the first two being the Internet Explorer 7 "mhtml:" Redirection Information Disclosure and the Popup Address Bar Spoofing Weakness. Among these two the mhtml vulnerabilty as I had mentioned in my earlier article lead to a debate between Microsoft and Secunia as Microsoft said that since the actual problem for the mhtml vulnerability lies with outlook express it cannot be attributed to Explorer 7 and Secunia saying that the vulnerability is fully exploitable via IE, which is the primary attack vector, if not the only attack vector.

Now this security flaw on IE 7 detected by Secunia and released today is termed as moderately critical where as the other two were termed as just moderate. This security flaw can be exploited by malicious people to spoof the content of websites.

According to the report a website can inject content into another site's window if the target name of the window is known. This can e.g. be exploited by a malicious website to spoof the content of a pop-up window opened on a trusted website.

The vulnerability has been confirmed on a fully patched system with Internet Explorer 7.0 and Microsoft Windows XP SP2.

What I find really amazing about this is that this vulnerability was actually reported on 2004-12-08 by secunia for explorer 5.01, 5.5 and version 6.x So does this mean that this issue was not addressed and patched earlier by Microsoft in their earlier versions and that it has just been passed onto the version 7?

And another thing to be noticed is that this same window injection vulnerability was detected in many other browsers including firefox, Opera, Netscape etc:- in 2004. It was an issue for multiple browsers at that time. But so far I have not seen this issue mentioned by Secunia for the Firefox 2. So it makes me wonder whether Mozilla has patched this in Firefox but Microsoft simply left it out. Or may be Secunia has not yet tested this security flaw on Firefox 2. I mean if this issue which was earlier detected in 2004 has been patched in Firefox and other browsers but hasn't been patched only in Explorer then that is really something very unpleasently surprising.

We have to wait and see the Microsoft's response to this and also let us see whether this same problem exists with Firefox too.

Secunia's today's report.
Secunia's report in 2004.

UPDATE: Just after I finished this article it has been confirmed now that Fire Fox 2 is also facing the same security flaw. I was in the right direction when I mentioned that since it was a mulitple browser problem including Opera, Firefox, Netscape and Explorer originally reported in 2004 by Secunia it could mean that those browsers could be affected too. I am waiting to see what the other browsers too have to say.

You can read the latest news on Firefox too being affected by this here.

Friday, October 27, 2006

All IE 7 and Firefox 2 Vulnerabilities as of date.


INTERNET EXPLORER 7 ISSUES.

  • Internet Explorer 7 "mhtml:" Redirection Information Disclosure
First one that stands out is the outlook express vulnerability which uses IE7. It was traced back to nov.2003. So that means it is an old issue which has still not been adressed properly. The flaw actually lies in Outlook Express. Microsoft is still investigating the issue. Even though the flaw lies with the outlook express and the older versions of explorer like IE6 have been facing this issue a lot of attention has been drawn to these with the launch of IE7.

The vulnerability apparently involves a very simple trick where a call to a MIME HTML, or MHTML, resource can trigger the running of an executable file, even with high-level security settings. Secunia rates this problem as "less critical," perhaps mainly because this is a trigger mechanism rather than a full-scale virus or Trojan. Conceivably, however, it could be utilized by malicious users within a more complete malware setup. The impact is exposure of sensitive information according to Secunia. The vulnerability is caused due to an error in the handling of redirections for URLs with the "mhtml:" URI handler. This can be exploited to access documents served from another web site.

Microsoft responded to reports of the first exploit affecting Internet Explorer 7, which cropped up less than 24 hours after the browser's official launch. Christopher Budd from Microsoft's Security Response Center says the flaw lies not in IE7, but in an Outlook Express component.

Secunia has confirmed the vulnerability on a fully patched system with Internet Explorer 7.0 and Microsoft Windows XP SP2. Other versions may also be affected.

Even if this vulnerability is not directly related to IE7, the security company Secunia does not exclude IE7. Secunia CTO Thomas Kristensen held true to his company's stance that the exploit is attributable to Microsoft's new Web browser. He says that "Microsoft claims the recent IE7 vulnerability is an Outlook Express vulnerability," begins Kristensen's statement to us. "This may be true, from an organizational point of view within Microsoft. However, the vulnerability is fully exploitable via IE, which is the primary attack vector, if not the only attack vector."


  • Internet Explorer 7 Popup Address Bar Spoofing Weakness

This spoofing issue uncovered by an anonymous discloser which was tested by the security firm Secunia and is categorized as less critical appears to be the first genuine, publicly disclosed flaw in the new Microsoft browser. The outlook express issue is a different story since according to microsoft it is not an IE7 vulnerability and as far as Secunia goes since the vulnerability is fully exploitable via IE they won't exclude IE7 from that. SO that issue is entirely upto to the users to whether take it as IE vulnerability or the outlook one. But this one without doubt points directly to IE 7.

The issue occurs in popup windows. It is possible to display a somewhat spoofed address bar, the company said. According to Secunia the problem is that it's possible to display a popup with a somewhat spoofed address bar where a number of special characters have been appended to the URL. This makes it possible to only display a part of the address bar, which may trick users into performing certain unintended actions.An attacker could exploit this weakness to trick people into believing they are on a trusted Web site when in fact they are viewing a malicious page, Secunia said in an alert.

According to an email statement issued by a Microsoft representative to Zdnet the problem lies in the way Web addresses are displayed in the IE 7 address bar. An attacker could exploit the issue by tricking a user to click on a specially formatted link, the representative said.

However, an attack won't work if a Web site is known to be part of a phishing scam since the IE 7 phishing shield will identify such sites and warn the user. And so far Microsoft is not aware of any attacks that actually use the reported vulnerability, the company said.

This issue is currently under investigation by Microsoft and they have said that once it is completed they will take the appropriate steps to protect it's customers.

However George Ou in his blog gives a solution..he says "The address bar spoofing weakness against IE7 happens when a small popup is spawned and a URL shows up with trailing spaces. The trailing spaces pushed the URL to the left and partially out of site which hides the actual domain and shows you a fake domain. If you click anywhere on the popup page or click on the background window, the left side of the URL and the actual domain name is revealed but the initial spoofing condition might be useful in a phishing attack to the unsuspecting user. This condition is repeatable when you click on the address bar and that is probably what is being exploited since the popup first shows up with the address bar in focus. The possible solution to this would be to strip out the trailing spaces (since spaces aren't supported in URLs anyways) when popping up browser windows or not allow it to start with the address bar in focus."

I hope they do take the necessary actions before these less critical issues are massively exploited by some of the malicious minds out there. No wonder it is reported that microsoft has chided the anonymous disclosure because it prefers that security issues be disclosed privately so it can repair them before they get publicly known.

Outlook express issue sources:-
Betanews.
Secunia's related info.
Zdnet's related article.

Spoofing issue
sources:-
Zdnet's related article.
Secunia's related info.
George Ou's article

Also talking about IE7 I thought I would share this article titled "Is Internet Explorer 7 spying on me?" which i saw at the DCoT blog. Take a look at it here. It is interesting to read not just the article but there is a good discussion going about it in the comments area. As far as the debate about the browsers go I personally feel that both has it's own advantages and I use both.





FIRE FOX ISSUES

Now on the other end Mozilla's Firefox is having it's share of security issues and along with the glory it's getting tainted with it's own security issues. Here goes:-

  • Issues brought up by Bugtraq:

First issue was again surprisingly in this case had something to do with mails. Bug tracking mailing lists have been talking about a flaw affecting the just released Firefox 2. Even though Bugtraq called the condition critical Mozilla's security chief Window Snyder insisted the report is wrong and that the problem was already "fixed". And Secunia which has reported both the IE7 issues has listed this issue as affected by zero Secunia advisiories.

Actually it all started when Bugtraq mailing list reported that the issue, labeled "critical" by Mozilla, resurfaced in Firefox 2. But Mozilla says the Firefox bug was considered critical and "fixed" last month.

Crash condition:

Window Snyder admitted a crash condition remained. "The exploitable issues are fixed. There is a crash, but it is a denial of service," Snyder said. "We're going to look at it and make sure there is really nothing there."

George Ou says in his zdnet blog that "any kind of flaw that can cause an application to crash has to be alarming because it might be exploitable. It sounds like some modifications were made to make the exploit condition less exploitable but a crash condition still exists." And he goes on "this may or may not still be a serious flaw since the exploit still crashes Firefox 2.0. At some point Mozilla would have to admit this is a problem and really fix it so that the browser doesn't crash at all."

Cyberscams issue:

Another report on the Full Disclosure mailing list suggested that there is a flaw in Firefox 2 that could be exploited to aid in cyberscams. The report included some computer code, but not enough for Mozilla to determine whether there is a problem, Snyder said.

"We don't have enough information to identify it. If we get more information, then we will investigate," she said.

Two old issues still unpatched on FireFox:

There are still two 2 rated vulnerability (rated by Secunia out of 5 which is a similar rating to the two issues in IE7) that has still not been patched by Mozilla. They are:-

1.Mozilla / Mozilla Firefox Cross-Domain Cookie Injection Vulnerability
2.Mozilla / Mozilla Firefox Apple Java Plugin Tab Spoofing Vulnerability

Check them out here. vulnerability 1 vulnerability 2



Sources:
Mozilla's info on bug tracking issue fixed last month.
Secunia's info on bug tracking issue.
Zdnet related article.

George Ou's article about media bias.


So it seems the both IE7 and Firefox are having a common issue when it comes to phising.

Talking about the phising issue here is another article that talks about how it has grown and the number of brands under attack from phishing was up 20 percent from June and 12 percent from the previous record in May. An interesting thing to note from the article is that "The survey found a large increase in traffic redirectors, and DNS redirectors in particular. These modify a system's DNS settings to direct some or all DNS lookups to a fraudulent DNS server capable of directing users to fraudulent sites when particular addresses are entered."

Read more from the survey and news about phising here.








Wednesday, October 25, 2006

Fire fox version 2 . Tweak it up baby with this guide.


Folks,
This is a must read for all those firefox fans out there. As you all know fire fox just recently released its version 2 (if you did not know it is high time you get out from under that rock). I just came across this tweaking guide for the browser written by Koroush Ghazi. It is a very well laid out guide. As he calls it it's a true objective TweakGuides tweak guide, and not a gushing ad for a free web browser.

I am was so happy when firefox released it latest version and now I guess with this guide we already have something to play around with the new browser toy for the big boys. Since he has a big intro and all I suggest you start reading from page 6 onwards because the basic tips and tweaks starts from there and the advanced tweaking part starts from page 8.

Digg it or you can go directly to the guide here.

Google