This Column Is a Fraud!

This Column Is a Fraud!

Written By
Larry Seltzer
Larry Seltzer
Sep 21, 2006
3 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

In August 2004 an innovative phishing attack was launched, not against the usual targets of PayPal and large banks, but against the Kerry for President campaign. The campaign fought back against it, also in an innovative way.

Typical of phishing attacks, the e-mail and Web site linked directly to images on the Kerry campaign site johnkerry.com. It contained a picture of Kerrys brother Cam Kerry with an appeal for a contribution.

The original phishing e-mail had used a from: address of johnkerrys.com rather than johnkerry.com—note the extra “s” in the name—which was probably of no value to the phisher and, as youll see, contributed to countermeasures. Ill leave out the other technical guts of the phish—suffice it to say, as you may have already guessed, the money didnt go to the campaign.

The campaign responded quickly though. Since the phishing e-mail directly linked to the image of Cam on the Kerry Web site, site admins replaced that image with one that contained the text “WARNING! If this e-mail is from any address that includes @JohnKerrys.com it is not an official e-mail from Kerry-Edwards 2004, Inc. Do not donate using any link in this e-mail.”

This is what engineers call an “elegant” solution. A very simple change, using features designed into HTML, forced the attack to reveal itself. Users who opened the e-mail after the change saw clearly that something was wrong with it (unless they followed the common techie advice to turn off graphics in e-mail).

/zimages/2/28571.gifSymantec is launching the Symantec Phish Report Network.Click hereto read more about this effort to help businesses and researchers.

Presumably the site controls its own access to these graphics and can then point users to a new, legit version. Note that the Kerry graphic message hedges its bets somewhat by saying not that the site is necessarily illegitimate, but that it is if the mail came from johnkerrys.com. Ironically, this was probably an overly conservative approach by the campaign. But the basic approach should have worked.

Fast-forward two years, and this elegant approach is still unheard of in the face of phishing attacks. Then I read about a use of it in Brian Krebs Security Fix blog in the Washington Post.

/zimages/2/28571.gifClick hereto read more about CipherTrusts PhishRegistry.org.

Krebs shows an attack against phishing punching bag e-gold. The company responded in the same way by changing their graphics to declare: “STOP – THIS IS A FAKE FRAUDULENT WEB SITE.” Nothing ambiguous there. Anyone who still gets suckered by this site deserves what he gets.

I decided to ask PayPal, which has a near-monopoly on phishing victimhood, why it doesnt take this approach. But even before I got an answer I could see how difficult it could be.

First, there is the sheer scale and manageability of the problem. Doing this the conventional way with static images would require constant monitoring of phishing attacks and changing the images they use. On PayPals scale, this is a serious problem.

The obvious way around this problem is for images not to be static, but script-generated, where perhaps the script checks the address of the referring page. But once again the problem is scale, as this would entail an immense increase in processing load on PayPals servers. Doing it right means seriously limiting the caching of images.

There is also the problem of legitimate outside linkers. PayPal expressed concern about “the thousands of very small, legitimate businesses that sign up for PayPal every day and add our logo to their sites.” Its possible to imagine ways to whitelist such sites, but the process sounds complicated, expensive and failure-prone.

For small sites, even for some not-so-small sites like the Kerry campaign and e-gold, perhaps image-swapping is a practical solution, but not for PayPal. Practical considerations mandate other solutions, none of which appears to be all that effective. This magic bullet missed the big target.

Security Center Editor Larry Seltzer has worked in and written about the computer industry since 1983.

/zimages/2/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

More from Larry Seltzer

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.