Archive

Archive for the ‘Company’ Category

stopthehacker.com Attends Technology Forum

February 22nd, 2010

The stopthehacker.com team traveled to Omaha, Nebraska, in early February to meet with other cyber security companies and corporate, academic and government leaders. Anirban Banerjee, stopthehacker.com co-founder, appeared in a video interview conducted by Jeff Slobotski of the Silicon Prairie News.

Watch Anirban describe the goals of stopthehacker.com:

Thanks again to the Silicon Prairie News for covering us at the event!

Company, News , , , ,

“Online Pharmacy” Spam Stalks Internet Forums/Boards

January 26th, 2010

Malicious hackers have, for many years, been offering services to unscrupulous individuals and companies for monetary compensation. With the growth of Email Spam advertising everything from medical supplements to cars and lottery tickets, email scrubbers and filters have taken the game up a notch by implementing ever increasing layers of complexity to cut down on such spam. In turn, hackers have started to focus on advertising spam, such as medication and fraudulent scams by compromising web-based message boards and forums.

Hackers employ two basic techniques:

  • Creating large numbers of users on forums. These accounts are then used to post spam on the message boards.
  • Exploiting Web Application vulnerabilities in the software used to run the forum.

Approximately two weeks ago, Lenny Zeltser, from ISC SANS, posted an informative article about online pharmacy ads popping up on message boards. In this vein we have conducted a limited experiment with about 14,000 websites which contain spam announcing online pharmacies.

The aim of the experiment:

  • What percentage of websites which advertise online pharmacies are message boards and Internet forums?
  • What Web Applications, e.g. CMS packages, are used on the message boards that are compromised?

We believe this will provide us with a rough estimate of how focused are hackers toward using message boards and forums on the Internet to advertise spam. From another perspective, it will provide us some idea of how vulnerable websites are if it hosts a message board or forum from being abused by hackers.

Testing methodology:

We have used Google to mine the websites which contain certain keyword patterns such as “buy zocor online”, or “buy brand kamagra online” etc. Once the links suggested by Google were mined, each of the websites was tested against Google’s Safe Browsing List to determine if they had hosted malware (according to Google). Next, an analysis was done to determine if the link(s) mined from Google pointed to a forum or message board. This was done by identifying the presence of multiple strings inside a link. For example, if a link has the keywords “topic”, “view”, “thread” or similar keywords, including characters associated with dynamic page generation, it is probably hosting a message board or forum.

The test was conducted between January 21st and January 23rd, 2010.

Popular software packages installed on compromised forums and message boards.

Popular software packages installed on compromised forums and message boards.

We present the most interesting results below:

  • 47.9% of websites displaying “online pharmacy” spam are message boards and forums.
  • None of the websites advertising “online pharmacy” spam were listed on Google Safe Browsing List.
  • 20.28% of forums displaying “online pharmacy” spam were using Jquery.
  • 15.73% of forums displaying “online pharmacy” spam were using phpBB.
  • 11.54% of forums displaying “online pharmacy” spam were using WordPress.
  • 10.84 % of forums displaying “online pharmacy” spam were using Mootools.

These results and other software packages, helper-scripts, tracking-code are depicted in the graph presented above.

This small experiment shows that a high percentage of websites displaying online spam campaigns are message boards or forums. This indicates that there are many unsecured software installations and older software packages still in use which are often exploited by malicious individuals to post spam. Further, it seems that most sites which were hacked are using jQuery. This supports our previous observations regarding jQuery scripts being used to push malware to unsuspecting visitors.

Read more…

Company, News, Report , , , ,

Free Google Blacklist Monitoring from stopthehacker.com!

November 23rd, 2009

Try our Blacklist Monitoring service for free. Blacklisting can happen to anyone. Now, with Blacklist Monitoring, know before it’s too late to keep your customers. Getting quick notice can let you fix the problem faster. Together, we can help make the web a safer, better place to surf.

What’s in it for you?

  • We tell you if your site appears on a blacklist, i.e. Google’s SafeBrowsing list.
  • You’ll receive an email every day with your status.

Sign up now. It’s Free!

Blacklisting happens to sites everyday and some don’t even know it until they hear that their readers and customers can’t reach them (see badwarebusters). Being blacklisted can practically take your website off the Internet! Most web browsers, like Firefox, Internet Explorer, Safari, or Chrome, will keep your visitors from accessing your site entirely, some won’t even give your visitor a choice.

We hope this never happens to you, but we can prepare you for when it does. We’ll notify you immediately. We can even help you recover.

We’ll be adding more services soon, so check back and don’t forget to subscribe to our feed, or follow us on Twitter or Facebook!

Company, News , , , , ,