December 08, 2007

Websense: Google Pages hosting phishing attacks

Researchers are warning internet users to be on the lookout for website scams appearing on Google Pages.

This month, experts at Websense reported a spike in the user-created sites hosting phishing schemes, such as one for eBay, Dan Hubbard, vice president of security research at San Diego-based Websense, told SCMagazine.com today.

Attackers are drawn to the Google Pages, which are hosted on Google servers, because they may evade web filters. The sites may not be blacklisted because "Google has a good reputation as a brand. It’s not a bad domain hosted in China or Eastern Europe," Hubbard said.

There are a number of other factors that may attract the malicious community to Google Pages, AJAX-enabled websites released in 2006 that offer users the ability to upload dynamic content.

"Google has a phenomenal infrastructure so the server is not going to go down," Hubbard said. "You can also do it anonymously. It’s free. There’s tons of space available."

He added that some attackers have created a script that allows them to automatically create these websites to be used in phishing attacks. Google needs to do a better job of scanning content, Hubbard said.

Google, in a statement today, said the search engine giant has defenses in place to prevent against its hosted websites being misused.

"We take user security and safety very seriously," the statement said. "As part of our efforts to protect users, we proactively check uploaded content for malware and viruses. In addition, when we are notified of phishing or other malicious or illegal content, we work quickly to remove it."

Last year, Websense reported that Google servers were being used to host malicious binary files that tried to infect users.

Hubbard said the new brand of phishing attacks is one of a variety of techniques scammers use. Others set up the attacks on their own servers, compromise legitimate sites or use bots.

Organizations should deploy solutions to scan possibly malicious websites and educate end-users to not click on unknown links in emails or instant messages, he said.[SC Magazine]

MySpace users warned of drive-by exploit attack

Researchers are warning of a widespread MySpace drive-by exploit attack meant to compromise machines so more highly-profitable phishing schemes remain successful.

MySpace users become infected when they visit a profile page containing malicious JavaScript and then are silently redirected to an Internet Explorer exploit, which was patched in April, Johannes Ullrich, chief research officer of the SANS Internet Storm Center, told SCMagazine.com today.

The exploit installs a common proxy network bot, known as a flux bot, which is used to hide phishing sites behind constantly changing proxy servers, Ullrich explained. The cybercriminals, in other words, use their newly compromised PCs to hide the tracks of unrelated phishing scams targeting banks and other financial institutions.

"It’s lends some secrecy to the scam and it makes it harder to shut down," he said. "Now, the actual machine (the victim) is connected to get to the phishing site changes by the minute. You can’t easily block them. It’s not that obvious."

The botnets are also being used to send spam, Ullrich said.

Potentially thousands of MySpace pages could be infected with the malicious worm, but the infected profiles are "being shut down really quickly," he said.

A spokesperson for MySpace, which has more than 100 million members, could not immediately be reached for comment today.

Ullrich said cyberthieves traditionally tailor their worms for MySpace and other social networking sites because of the younger demographic that use them.

"It has a lot of non-technical users who do not patch their browsers," he said. "People are not that careful. They may visit MySpace thinking [it’s] a big a company and not realizing the content of the pages comes from the average user."

MySpace has been the victim of a number of attacks over the past year. Vincent Weafer, head of Symantec’s Global Security Response, said MySpace users are often easily duped into giving up their credentials.

"If I can get into your trusted group, I may be able to get information out of you," he said.

Colin Whittaker of Google’s Anti-Phishing Team wrote on the company’s security blog recently that many users are tricked into giving their usernames and passwords so crooks can send spam from their account or – worse – use that same log-in information to access their bank accounts. [SC Magazine]