Thursday, January 04, 2007

An evaluation of 10 Anti-phishing tool bars.

In a recent study of all the major Anti-phishing tool bars conducted by the Carnegie Mellon University, they analysed the following 10 Anti-phishing tool bars:


1.Cloudmark Anti-Fraud Toolbar
2.EarthLink Toolbar
3.
eBay Toolbar
4.
GeoTrust TrustWatch Toolbar
5.
Google Safe Browsing
6.McAfee SiteAdvisor
7.
Microsoft Phishing Filter in Windows Internet Explorer 7
8.Netcraft Anti-Phishing Toolbar
9.
Netscape Browser 8.1
10.
SpoofGuard

The study was conducted by using verified phishing URLs and legitimate URLs to test the effectiveness of 10 popular antiphishing toolbars. And according to the study the Anti-phishing tool bars that have been studied leaves a lot to be desired.

Let me break up the study and give you the main points:

  • SpoofGuard did a very good job at identifying fraudulent sites.At the same time, SpoofGuard incorrectly identified 38% of the legitimate URLs as phishing URLs. It would seem that such inaccuracies might nullify the benefits SpoofGuard offers in identifying phishing sites.
  • The only toolbar tested that is known to make NO use of blacklists was SpoofGuard. While it was able to identify the majority of phishing sites using only heuristics, it still missed some phishing sites and it had a very high false positive rate.
  • SpoofGuard could potentially be improved through the use of a whitelist, which would prevent the problems that occurred when phishing sites were visited before their corresponding legitimate sites. The whitelist would not necessarily need to be extremely large or updated frequently to be effective.
  • The study found that three of the 10 toolbars, SpoofGuard, EarthLink and Netcraft, were able to identify over 75% of the phishing sites tested.
  • EarthLink, Google, Netcraft, Cloudmark, and Internet Explorer 7 identified most fraudulent sites correctly and had few, if any, false positives, but they still missed more than 15% of fraudulent sites.
  • The TrustWatch, eBay, and Netscape 8 toolbars could correctly identify less than half the fraudulent sites.
  • McAfee SiteAdvisor did not correctly identify any fraudulent sites.
  • The 10 toolbars that the researchers examined used a variety of methods for identifying fraudulent sites; however, it was able to exploit vulnerabilities in most of them.
  • The experiments also suggest that there is no single technique that will always outperform others for identifying phishing web sites.
  • Most of the tools tested used blacklists, but only half of them were able to identify the majority of phishing web sites.
  • The researchers don’t know the size of the blacklists used by each toolbar, nor do they know what heuristics are used by any of the toolbars other than SpoofGuard.
  • The researchers suspect that the toolbars that performed best use larger and more frequently updated black lists. They may also use heuristics that allow them to detect phishing sites that haven’t yet been put on the blacklist.
  • Relying solely on heuristics requires that the software is designed with the foresight to prevent circumvention. In this study we were able to exploit both techniques, which leads us to believe that a combination of techniques is necessary
  • The success of a blacklist relies on massive amounts of data being collected at frequent intervals.
  • The study says that much more work needs to be done in this area from a technical standpoint. Yet even if it is possible to create a technically sound antiphishingtoolbar, it is still unclear as to whether or not this would be beneficial to users. Usability problemsplague all varieties of software, security software in particular. When using an anti-phishing toolbar, poorusability could mean the difference between correctly steering someone away from a phishing site and having them ignore the warnings only to become a victim of identity theft. Thus, we plan to further examine both the technical aspects of this domain as well as the human factors.

My conclusion:

Ok, after going through these facts I come to the conclusion that among the 10 tool bars tested EarthLink, Google, Netcraft, Cloudmark, and Internet Explorer 7 are the best among the 10 tested since they hardly gave any false positives and they identified 75% of the sites correctly. Spoofguard is also good but since it relies solely on heuristics it gave a lot of false positives. The other three tools viz:- TrustWatch, Ebay, and netscape 8.1, performed poorly. And am also so surprised at the fact that Mcafee's Site Advisor did not correctly identify any fraudulent sites.

Now I am waiting to see a study which includes Firefox 2 Anti-phishing and Opera 9.1 Real-time Anti- fraud technique. BUt firefox also use Google's Anti-phishing database and Opera uses database from GeoTrust. So may be that is why they were not included in the study since they included Google tool bar and GeoTrust's tool bar in the study. And if you look at the study while Google's Anti-phishing tool bar performed well, GeoTrust's TrustWatch performed badly. So if I go by the study it means among the popular three browsers, Viz:- Internet Explorer 7, Firefox 2 and Opera 9.1, GeoTrust which is used by Opera performed badly while the Anti-phishing tools in the other two browsers performed well. But am still waiting for a further study to make a strong conclusion about this aspect.

You can read the full report here (.PDF)

Update: Please look at the comment below by Shane Keats of Mcafee regarding Mcafee's Site Advisor.

Wednesday, January 03, 2007

Adsense inside the article/post in new blogger(beta).

With due credit to Loui$$ who maintains the blogginsecret.blogspot.com here am providing you with the hack he has mentioned at his blog to put Google Adsense right at the beginning of your article or within the post in Blogger Beta or the newblogger. Also see some additional notes from me.

Ok, let us have look at the method and how I did it:

1. Login to your Adsense account and get the code for the Adsense lay out you prefer and copy and paste it into a note pad.

Hope most of you know how to get the code. Google adsense account>adsense for content>Ad Unit>text ads.

2. Next on the notepad you will see the code in the following form:
<script type="text/javascript"><!--
your ads code
//--></script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>

Now replace the <!-- and //--> as &lt;!-- and //--&gt;

3.Login to your new blogger and go to Layout > Edit HTML > and copy and paste the template into your notepad.

4. In the notepad in which you have saved the template search within the notepad (using Cntrl + F ) for the following term: post-header-line-1

This will enable you to find div class="post-header-line-1" which is just below the data:post.title

5.Now copy the whole Adsense code that you got from Google Adsense accout that was changed by replacing the <!-- and //--> as &lt;!-- and //--&gt; as mentioned in step 2 and paste it just under the "post-header-line-1"

6.Replace the template in your blogger with this changed template by deleting the template in your blogger template box andthen copying and pasting the template from your notepad into the blogger template box. You are done.

Additional notes:

1.Before you copy and paste the template check the "Expand widget templates" and then copy and paste the template on yournotepad. Only then you will see the div class="post-header-line-1"

2.Back up your templates before changing it.

3. Google allows only 3 Adsense layouts and one link unit. So if you already have some, make sure before you add more Adsense within your post, those ones are deleted. Google ensures that only 3 different Adsense layouts are shown even if you place more. But it is better to be on the safer side by ensuring that you have put in only 3 Adsense layouts and one link unit.

4. If you already have placed Adsense in your blogger using the Add HTML page element save that in your notepad before taking it off as this will enable you to put it back easily if you want to experiment with the Adsense layouts instead of going back to your Adsense account each time to generate codes.

5. Originally Loui$$ had mentioned about just deleting the tags within the google Adsense code. But later it was changed to replacing the tags as mentioned in step 2 as this would ensure that the Google TOS is not violated. This particular idea was suggested by bloggerdigest.

How to put Adsense at the end of an article/post:

The above mentioned method allows people to put the Adsense Ads at the beginning of an article in the new blogger (Prev. Beta). To put an Adsense Ad at the end of an article or a post use the same method mentioned above, the only difference being this time the Adsense code (just like the hack mentioned above) has to be put under the class= 'post-footer-line post-footer-line-1'

How to wrap Adsense around posts:

Monday, January 01, 2007

How safe is your password?

Recently as most of the people know some of the passwords of the myspace users was compromised by using a fake login page. And this is just a drop in the ocean when you take into account the phishing attacks that have been so rampant on the net lately along with the vast amount of Trojans that have been making the rounds.

This article at the securiteam website clearly shows how some basic techniques can be used to steal passwords especially at a website like Myspace.com and how the passwords were compromised. Also, it was not long back a Digg user posted some user name and passes of Myspace users.

Clearly it has come to a stage where not just using complex 8 character or alphanumeric passwords is gonna safeguard the Internet users from their passwords being hacked.

Even the Firefox version 2 had a flaw in it's password manager which could allow malicious people to collect the passwords of the unsuspecting users. Till now Firefox has not taken care of this vulnerability. This was known as the Reverse Cross Site Request vulnerability.

Recently I read an article by Bruce Schneier and according him among the list of the stolen myspace passwords there were even some 32-character password: "1ancheste23nite41ancheste23nite4."

Other long passwords were "fool2thinkfool2thinkol2think" and "dokitty17darling7g7darling7."

All that effort put in to get those long and complex passwords didn't succeed to keep it safe in the end. All because someone managed to fool the users into believing that they were actually logging in through the myspace when actually what was happening was that all the passwords were being stored in a fake server set up by the attacker.

Also according to Bruce Schneier the following were the 20 most common passwords used among the 34,000 compromised Myspace user passwords:

password1,
abc123,
myspace1,
password,
blink182,
qwerty1,
fuckyou,
123abc,
baseball1,
football1,
123456,
soccer,
monkey1,
liverpool1,
princess1,
jordan23,
slipknot1,
superman1,
iloveyou1
monkey.

Among these the most commonly used was password1

So in these days were security exploits are rampant along with phishing attacks there are also a wide range of password hacking tools available for free on the net. Tools like Access Diver, which is actually supposed to be used by security personnels to test their network are being used widely by hackers for various attacks like bruteforce, dictionary attacks etc:- Also, available freely and widely are tools like Brutus, Caine & Abel etc:- Add to it Trojans and keyloggers especially the christmas themed malwares and the New Year themed Postcard.exe trojan that have been making the rounds.

So the users have no other option but to build a strong defense. And how can you build a good defense? Ok, let me give you some input:

  • Use browsers with antiphishing tool bars like Firefox 2 (but disable the Password manager in FF2 because of the RCSR vulnerability I mentioned earlier) and Internet explorer 7 or Opera's new 9.1 browser with Real time Anti-fraud technique.
  • Also one can use Netcraft's Toolbar to protect oneself from the malicious websites. It was a Netcraft Toolbar who spotted the fake website that was stealing passwords of the Myspace users.
  • One can also use Mcafee's site advisor tool. You download it here.
  • Disable Java, Java scripts, cookies, Active X in your browser as much as you can.
  • Use complex and different Passwords for each sites using Password generators and Password storing tools, some of which even does the encrypted auto filling. You have a look at some of the best Password related tools here.
  • Anti-trojans-- Get a good Anti-Trojan. Read this article I wrote for more information.
  • Antispywares--You will find a list of some of the best Anti-spywares with a review here.
  • 27 steps to prevent viruses-- Read this article to get an idea about how one can protect themselves from getting a computer virus.
  • Anti-Rootkits--Check it out here.
And above all always use your judgement. Happy and safe surfing folks.



Sunday, December 31, 2006

Letterpop--Create amazing newsletters for free.

I came across this amazing site today where you can create your own creative and unique newsletters. Now instead of going to various sites to pick a greeting card you can create your own. Once you sign up for a free registration you can even use your own pics and photos and thus customize it.

There is a 12 month free premium membership available for users registering now.

One can even use this to create wedding cards, newsletters for small businesses etc:- All you will need is a printer if you want to have a hard copy of the newsletter. But if you just want to send your custom made newsletter or cards to someone over the internet just click on the email button.

There are currently 14 templates available and once you are upgraded to premium (which as I mentioned is free now) you will get a wider range of templates. All users signing up now will be upgraded to premium soon. And there are six pre-set images. But like I mentioned earlier one can upload their own images once you sign up. You can upload upto 25 images.

You can drag and drop the template and then your images. By clicking on the "Headlines" and "Text here" you get to see the composer and you can choose a variety of fonts and colors.

The news letters are auto saved and you can always go back to the newsletters that you have been working on even if happen to accidentally close a page.

This site was started recently and you can expect a lot of upgrades.

So, pay a visit to the Letterpop and let your creative juices flow.

Anti Rootkit for Windows Vista.

F-secure has on 29th Dec released a beta version of it's Black light AntiRootkit software which supports Windows vista. This also supports the Windows 2003 server and will work with all other supported platforms too.

Currently it supports 32 bit versions. But F-secure is adding support for 64 bit OS.

There are currently no known rootkits for the 64 bit operating systems. But since it is not impossible to create rootkits for the 64 bit operating systems F-secure is will be adding support for that too.

As I had mentioned in an earlier article about Kaspersky and Vista, Kaspersky also has released a beta version of it's Antivirus software which supports Windows vista.

You can download the new beta BlackLight here.

Related reading:-
What are rootkits and AntiRootkits.

Worm sends massive amounts of fake NewYear greetings.



Luder.A also known as Tibs.jy is an email worm, a dropper for a trojan downloader and a file infector and it has been reported by F-Secure that this worm is sending out mass emails in the form of fake New year greetings.

The numbers are big enough for F-secure to raise the threat level for this worm to Radar Alert Level 2.
The attachments mostly comes in the form of Postcard.exe and is always themed around New year even though the text might vary.

According the report, before spreading the worm collects e-mail addresses from an infected computer. It locates and reads the WAB (Windows Address Book) file. The worm avoids sending e-mails to e-mail addresses that contain any of the following:

* microsoft
* .mil
* .gov

To learn how to disinfect the worm go here.

Google