Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    This Column Is a Fraud!

    Written by

    Larry Seltzer
    Published September 21, 2006
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      In August 2004 an innovative phishing attack was launched, not against the usual targets of PayPal and large banks, but against the Kerry for President campaign. The campaign fought back against it, also in an innovative way.

      Typical of phishing attacks, the e-mail and Web site linked directly to images on the Kerry campaign site johnkerry.com. It contained a picture of Kerrys brother Cam Kerry with an appeal for a contribution.

      The original phishing e-mail had used a from: address of johnkerrys.com rather than johnkerry.com—note the extra “s” in the name—which was probably of no value to the phisher and, as youll see, contributed to countermeasures. Ill leave out the other technical guts of the phish—suffice it to say, as you may have already guessed, the money didnt go to the campaign.

      The campaign responded quickly though. Since the phishing e-mail directly linked to the image of Cam on the Kerry Web site, site admins replaced that image with one that contained the text “WARNING! If this e-mail is from any address that includes @JohnKerrys.com it is not an official e-mail from Kerry-Edwards 2004, Inc. Do not donate using any link in this e-mail.”

      This is what engineers call an “elegant” solution. A very simple change, using features designed into HTML, forced the attack to reveal itself. Users who opened the e-mail after the change saw clearly that something was wrong with it (unless they followed the common techie advice to turn off graphics in e-mail).

      /zimages/2/28571.gifSymantec is launching the Symantec Phish Report Network. Click here to read more about this effort to help businesses and researchers.

      Presumably the site controls its own access to these graphics and can then point users to a new, legit version. Note that the Kerry graphic message hedges its bets somewhat by saying not that the site is necessarily illegitimate, but that it is if the mail came from johnkerrys.com. Ironically, this was probably an overly conservative approach by the campaign. But the basic approach should have worked.

      Fast-forward two years, and this elegant approach is still unheard of in the face of phishing attacks. Then I read about a use of it in Brian Krebs Security Fix blog in the Washington Post.

      /zimages/2/28571.gifClick here to read more about CipherTrusts PhishRegistry.org.

      Krebs shows an attack against phishing punching bag e-gold. The company responded in the same way by changing their graphics to declare: “STOP – THIS IS A FAKE FRAUDULENT WEB SITE.” Nothing ambiguous there. Anyone who still gets suckered by this site deserves what he gets.

      I decided to ask PayPal, which has a near-monopoly on phishing victimhood, why it doesnt take this approach. But even before I got an answer I could see how difficult it could be.

      First, there is the sheer scale and manageability of the problem. Doing this the conventional way with static images would require constant monitoring of phishing attacks and changing the images they use. On PayPals scale, this is a serious problem.

      The obvious way around this problem is for images not to be static, but script-generated, where perhaps the script checks the address of the referring page. But once again the problem is scale, as this would entail an immense increase in processing load on PayPals servers. Doing it right means seriously limiting the caching of images.

      There is also the problem of legitimate outside linkers. PayPal expressed concern about “the thousands of very small, legitimate businesses that sign up for PayPal every day and add our logo to their sites.” Its possible to imagine ways to whitelist such sites, but the process sounds complicated, expensive and failure-prone.

      For small sites, even for some not-so-small sites like the Kerry campaign and e-gold, perhaps image-swapping is a practical solution, but not for PayPal. Practical considerations mandate other solutions, none of which appears to be all that effective. This magic bullet missed the big target.

      Security Center Editor Larry Seltzer has worked in and written about the computer industry since 1983.

      /zimages/2/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

      More from Larry Seltzer

      Larry Seltzer
      Larry Seltzer
      Larry Seltzer has been writing software for and English about computers ever since—,much to his own amazement— He was one of the authors of NPL and NPL-R, fourth-generation languages for microcomputers by the now-defunct DeskTop Software Corporation. (Larry is sad to find absolutely no hits on any of these +products on Google.) His work at Desktop Software included programming the UCSD p-System, a virtual machine-based operating system with portable binaries that pre-dated Java by more than 10 years.For several years, he wrote corporate software for Mathematica Policy Research (they're still in business!) and Chase Econometrics (not so lucky) before being forcibly thrown into the consulting market. He bummed around the Philadelphia consulting and contract-programming scenes for a year or two before taking a job at NSTL (National Software Testing Labs) developing product tests and managing contract testing for the computer industry, governments and publication.In 1991 Larry moved to Massachusetts to become Technical Director of PC Week Labs (now eWeek Labs). He moved within Ziff Davis to New York in 1994 to run testing at Windows Sources. In 1995, he became Technical Director for Internet product testing at PC Magazine and stayed there till 1998.Since then, he has been writing for numerous other publications, including Fortune Small Business, Windows 2000 Magazine (now Windows and .NET Magazine), ZDNet and Sam Whitmore's Media Survey.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×