<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>stopthehacker.com &#187; google</title>
	<atom:link href="http://www.stopthehacker.com/tag/google/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.stopthehacker.com</link>
	<description>Jaal, LLC</description>
	<lastBuildDate>Wed, 01 Sep 2010 18:08:05 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Analyzing the Google Blacklist, Part 2</title>
		<link>http://www.stopthehacker.com/2010/06/30/analyzing-the-google-blacklist-part-2/</link>
		<comments>http://www.stopthehacker.com/2010/06/30/analyzing-the-google-blacklist-part-2/#comments</comments>
		<pubDate>Wed, 30 Jun 2010 16:37:43 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[blacklisting]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[monitoring]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1857</guid>
		<description><![CDATA[Building on our first article in the series, we continue to analyze the Google Safe Browsing List. In this part, we present more detailed statistics about the hashes seen on the blacklist and try to provide insight into what we observe.
Motivation
Understanding the behavior of infected websites is very important. This provides security researchers with strategies [...]]]></description>
			<content:encoded><![CDATA[<p>Building on our first article in the series, we continue to analyze the <a href="http://www.google.com/tools/firefox/safebrowsing" target="_blank">Google Safe Browsing List</a>. In this part, we present more detailed statistics about the hashes seen on the blacklist and try to provide insight into what we observe.</p>
<p><strong>Motivation</strong><br />
Understanding the behavior of infected websites is very important. This provides security researchers with strategies to help deal a blow to the bad guys and at the same time, provide website owners and administrators an idea of the current state of website security.</p>
<p>Since the publication of our last article in this series, we have received good feedback from our colleagues in security. We will attempt to incorporate their comments and concerns in this part of the series.</p>
<p><strong>Methodology</strong><br />
We discussed the aim of this experiment and methodology in the <a href="http://www.stopthehacker.com/2010/06/28/analyzing-the-google-blacklist/">last part of this series</a>. We won&#8217;t repeat them here, but we encourage you to take a look at our first article in this series if you haven&#8217;t already read it!</p>
<p><strong>Analysis</strong><br />
Below we present some graphs which provide more information about the analysis.</p>
<ul>
<li><strong>Websites have a high probability of getting hacked on a Wednesday!</strong></li>
</ul>
<div id="attachment_1876" class="wp-caption aligncenter" style="width: 449px"><img class="size-full wp-image-1876" title="Websites have a high probability of getting hacked on a Wednesday!" src="http://www.stopthehacker.com/wp-content/uploads/2010/06/gma1.gif" alt="Websites have a high probability of getting hacked on a Wednesday!" width="439" height="328" /><p class="wp-caption-text">Websites have a high probability of getting hacked on a Wednesday!</p></div>
<ul>
<li><strong>Websites have a high probability of getting hacked between 7-8 PM PDT.</strong></li>
</ul>
<div id="attachment_1877" class="wp-caption aligncenter" style="width: 502px"><img class="size-full wp-image-1877" title="Websites have a high probability of getting hacked between 7-8 PM PDT." src="http://www.stopthehacker.com/wp-content/uploads/2010/06/gma2.gif" alt="Websites have a high probability of getting hacked between 7-8 PM PDT." width="492" height="337" /><p class="wp-caption-text">Websites have a high probability of getting hacked between 7-8 PM PDT.</p></div>
<ul>
<li>On Monday websites get hacked most between 11 AM to 12 Noon, PDT</li>
<li>On Tuesday websites get hacked most between 9 AM to 10 AM, PDT</li>
<li>On Wednesday websites get hacked most between 7 PM to 8 PM, PDT</li>
<li>On Thursday websites get hacked most between 10 PM to 11 PM, PDT</li>
<li>On Friday websites get hacked most between 11 AM to 12 Noon, PDT</li>
<li>On Saturday websites get hacked most between 1 PM to 2 PM, PDT</li>
<li>On Sunday websites get hacked most between 11 AM to 12 Noon, PDT</li>
</ul>
<p>Note: Most hashes which stay on the blacklist (over the 113 day period) seem to get added to the blacklist on Wednesday.</p>
<p><strong>Conclusions</strong><br />
We have presented more interesting statistics regarding the appearance of website hashes on the Google Safe Browsing List. These statistics provide information which website administrators and owners can use better arm themselves with against attackers. We will continue analyzing the dataset to provide more interesting information. If you have any questions please add a comment.</p>
<p>At <a href="http://www.stopthehacker.com" target="_self">stopthehacker.com</a>, we work hard to help you combat malicious hackers. If you would like to work with us, please drop us an <a href="http://www.stopthehacker.com/contact/" target="_self">email</a>. You can also visit our <a href="http://www.stopthehacker.com/services/" target="_self">services</a> page to find out how we can help you, in fact you can even sign up for <a href="http://www.stopthehacker.com/services/blacklist-monitoring/" target="_blank">free</a> services!</p>
<p>Till next time&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/06/30/analyzing-the-google-blacklist-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Analyzing the Google Blacklist, Part 1</title>
		<link>http://www.stopthehacker.com/2010/06/28/analyzing-the-google-blacklist/</link>
		<comments>http://www.stopthehacker.com/2010/06/28/analyzing-the-google-blacklist/#comments</comments>
		<pubDate>Mon, 28 Jun 2010 17:52:36 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[blacklist]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[monitoring]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1833</guid>
		<description><![CDATA[Google&#8217;s efforts to clean up the Internet and provide a useful advisory to Internet users has been very successful. Nearly every modern browser now incorporates Google&#8217;s Safe Browsing List information, to prevent users from inadvertently visiting malware infested websites and phishing websites.
Motivation
In this article we will be analyzing the Google malware hash lists that have [...]]]></description>
			<content:encoded><![CDATA[<p>Google&#8217;s efforts to clean up the Internet and provide a useful advisory to Internet users has been very successful. Nearly every modern browser now incorporates <a href="http://www.google.com/tools/firefox/safebrowsing" target="_blank">Google&#8217;s Safe Browsing List</a> information, to prevent users from inadvertently visiting malware infested websites and phishing websites.</p>
<p><strong>Motivation</strong><br />
In this article we will be analyzing the Google malware hash lists that have been published over the past few months in order to answer these important questions:</p>
<ul>
<li>How many websites get blacklisted each day?</li>
<li>How many websites manage to get off the blacklist?</li>
<li>How soon do websites get off the blacklist?</li>
<li>How many never get off the blacklist?</li>
</ul>
<p>These are practical questions which are often posed by frustrated, sometimes confused and angry website owners, time and time again at help forums, and via our contact page.</p>
<p><strong>Resources</strong><br />
Google has done a good job creating detailed <a href="http://www.google.com/webmasters/tools/" target="_blank">help</a> content describing the process of blacklisting, as well as a <a href="http://www.google.com/support/forum/p/Webmasters/label?lid=2fe2a8ee8e37c08e&amp;hl=en">group</a> where website owners can ask for help. Additionally there are excellent resources like <a href="http://www.badwarebusters.org">BadwareBusters</a> where users can find volunteers to help them. We also participate in these groups.</p>
<p>Yet, there is still a demand for getting clear cut answers to some basic questions like the ones detailed above. In this vein we want to provide scientifically sound and statistically significant analysis of freely available information to provide clear answers to these questions. A small <a href="/faq/" target="_blank">FAQ</a> is also available on our site to answer questions from website owners and admins.</p>
<p><strong>Goals</strong><br />
This series of experiments is split into multiple parts. This article presents a first look (part 1) at openly available data. The goal of the experiment is to understand:</p>
<ul>
<li>How many websites get blacklisted each day?</li>
<li>How many websites manage to get off the blacklist?</li>
<li>How soon do websites get off the blacklist?</li>
<li>How many never get off the blacklist?</li>
<li>How many websites fall back onto the blacklist?</li>
<li>How much time elapses before a website falls back into the blacklist?</li>
</ul>
<p><strong>Methodology</strong><br />
For the purposes of this experiment, Google malware hash lists were collected from March 3, 2010 to June 1, 2010 (113 days). Malware hash lists were collected every 30 minutes. Each malware hash list contains the information in the Google malware hash specification. All hash lists were parsed and unique hashes were extracted and time stamped, and correlated with the malware hash list version.</p>
<p>Subsequently an analysis was conducted to answer the questions posed above. At no point was an attempt identify a website name from the hashes. Also, note that a single website can have more than one unique hash. For example: &#8220;www.abcd.com&#8221;, &#8220;abcd.com&#8221;, and &#8220;www.abcd.com/infected/&#8221; can all generate different hashes.</p>
<p><strong>Brief Highlights</strong></p>
<ul>
<li><strong>Total number of unique hashes tracked: 688,602.</strong></li>
<li><strong>Average number of unique hashes per day (over 113 day period): 6093.</strong></li>
<li><strong>25.8% of hashes never got off the Google blacklist.</strong><br />
Each one of these unique hashes was deemed infected for over 3 months (greater than 113 days).</li>
<li><strong>43% of hashes were listed exactly once as infected and managed to get off the Google blacklist.</strong><br />
The average time each of these hashes was blacklisted was 13 days (89 days max).</li>
<li><strong>2% of hashes were blacklisted exactly twice.</strong><br />
Each one of these hashes was blacklisted, was then removed from the blacklist and then fell back in (the sites were hacked again). These sites remained infected for an average of 19 days (89 days max), and remained clean for an average of 17 days before being hacked again.</li>
</ul>
<p><strong>Analysis</strong><br />
It is clear from these initial results that a very large number of websites, <strong>nearly one quarter of the 6000 hashes added per day never make it off the Google blacklist</strong>. There are a number of reasons for this. One being that most webmasters, who may be good at website design and layouts, may not have the technical skills which are required to clean websites infected by malware and code injection attacks. We have also met website owners who are extremely business savvy, but lack the technical expertise to recover from a blacklisting event. The income lost due to business interruption in these cases is considerable.</p>
<p>We see that 43% of websites which get blacklisted manage to make it off the blacklist, but <strong>these websites suffer for an average period of 13 days</strong>.</p>
<p>Some websites manage to get off the blacklist and then fall in again. The average time for these &#8220;repeat offenders&#8221; on the blacklist is larger than the previous case. <strong>The time for which these &#8220;repeat offenders&#8221; stay clean is not very high, an average of just 17 days.</strong></p>
<p><strong>Conclusion</strong><br />
These numbers clearly show the current sorry state of website security. It is unfortunate that thousands of websites are affected every day. At <a href="/" target="_self">stopthehacker.com</a>, we strive to help combat this trend.  These issues need to be addressed specifically by services that currently are not readily available to the masses. To address this vacuum in the service space, and disrupt the security market <a href="/" target="_self">stopthehacker.com</a> provides its advanced <a href="http://www.stopthehacker.com/services/health-monitoring/" target="_self">Health Monitoring</a> and <a href="http://www.stopthehacker.com/services/risk-assessment/" target="_blank">Vulnerability assessment</a> services for website owners. Our services take away the anguish which business owners face when their websites are attacked. Please visit our <a href="/services/" target="_self">services</a> page to find out how we can help you. In fact, you can even sign up for <a href="/services/blacklist-monitoring/" target="_blank">free</a> services.</p>
<p>Further detailed analysis will be presented in the second part of this series. We will show detailed analysis of the data and will provide more insight on the implications of these observations.</p>
<p>Stay tuned for Part 2!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/06/28/analyzing-the-google-blacklist/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why Did My PageRank Go Down? &#8211; SEO Poisoning</title>
		<link>http://www.stopthehacker.com/2010/05/10/why-did-my-pagerank-go-down-seo-poisoning/</link>
		<comments>http://www.stopthehacker.com/2010/05/10/why-did-my-pagerank-go-down-seo-poisoning/#comments</comments>
		<pubDate>Mon, 10 May 2010 17:00:10 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[link spam]]></category>
		<category><![CDATA[pagerank]]></category>
		<category><![CDATA[seo]]></category>
		<category><![CDATA[seo poisoning]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1597</guid>
		<description><![CDATA[Search engines like Google drive the majority of traffic to websites. Therefore, it is important for webmasters to appear high on search rankings and prominently in search results. To this affect website owners often spend large sums of money on Search Engine Optimization (SEO) strategies: using the right keywords, getting linked to by popular sites, [...]]]></description>
			<content:encoded><![CDATA[<p>Search engines like Google drive the majority of traffic to websites. Therefore, it is important for webmasters to appear high on search rankings and prominently in search results. To this affect website owners often spend large sums of money on Search Engine Optimization (SEO) strategies: using the right keywords, getting linked to by popular sites, getting a dialogue about the website going on good forums and much more.</p>
<p><strong>Overview</strong></p>
<p>The popularity, relevance and importance of a website, which determines where in the search rankings it should appear, can simplistically, thought to be represented by one magic number: the Google PageRank. This article is not about how to calculate, improve or tune your Google PageRank.</p>
<p>This article will discuss how a hacker can break into your site, without you knowing and reduce your Google PageRank, thereby making your website plummet from the top rankings in search engines, making your business lose money and visibility.</p>
<p><strong>An Example</strong></p>
<p>On May 7th, 2010, we reviewed a compromise of one of many sites we scan on a daily basis. This site was attacked by a hacker who had exploited a vulnerability in the web application used to host the website. Once the hacker had identified the specific vulnerability, which was WordPress based, he injected spam links into the source code of the pages on the site.</p>
<p>All the spam links are nicely placed after the main body of the legitimate HTML portion and even starts with a comment tag &#8220;&lt;!&#8211; google &#8211;&gt;&#8221;!</p>
<div class="gallery">
<div id="attachment_1598" class="wp-caption aligncenter" style="width: 310px"><a rel="attachment wp-att-1598" href="http://www.stopthehacker.com/wp-content/uploads/2010/05/injected_spam_links.jpg"><img class="size-medium wp-image-1598" title="Malicious spam links injected into the website." src="http://www.stopthehacker.com/wp-content/uploads/2010/05/injected_spam_links-300x249.jpg" alt="Malicious spam links injected into the website." width="300" height="249" /></a><p class="wp-caption-text">Malicious spam links injected into the website.</p></div>
</div>
<p><strong>Conclusion</strong></p>
<p>The affect of this spam link injection was that the PageRank of the legitimate site was potentially reduced since many links on the website now pointed to spam or malicious pages. This could result in lower positioning in search results as displayed on various search engines. This is yet another case where webmasters and administrators, who are already overloaded with many tasks, were either unaware or could not pay attention to the security breach.</p>
<p>At stopthehacker.com we are always available to help. If you have suffered from a breach of this kind and would like to share your experience, please contact us.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/05/10/why-did-my-pagerank-go-down-seo-poisoning/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is User Trust More Effective Than Blacklisting?</title>
		<link>http://www.stopthehacker.com/2010/04/06/comparing-blacklists/</link>
		<comments>http://www.stopthehacker.com/2010/04/06/comparing-blacklists/#comments</comments>
		<pubDate>Tue, 06 Apr 2010 17:00:48 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[bing]]></category>
		<category><![CDATA[blacklisting]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[wot]]></category>
		<category><![CDATA[yahoo]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1533</guid>
		<description><![CDATA[Blacklists are published by many security groups and organizations around the world to share knowledge about malicious websites, IP addresses and other security features which allow others to insulate themselves from the dark side of the Internet.
In recent years, the number of blacklist being published by web-centric organizations have grown by leaps and bounds. Large [...]]]></description>
			<content:encoded><![CDATA[<p>Blacklists are published by many security groups and organizations around the world to share knowledge about malicious websites, IP addresses and other security features which allow others to insulate themselves from the dark side of the Internet.</p>
<p>In recent years, the number of blacklist being published by web-centric organizations have grown by leaps and bounds. Large Internet based companies such as <a href="http://www.google.com" target="_blank">Google</a>, <a href="http://www.yahoo.com" target="_blank">Yahoo</a> and <a href="http://www.bing.com" target="_blank">Microsoft</a> have been providing cues to their users about malicious websites in trying to make the Internet a safer place. <a href="http://www.google.com" target="_blank">Google</a> provides much more in-depth information than the other two, <a href="http://www.yahoo.com" target="_blank">Yahoo</a> and <a href="http://www.bing.com" target="_blank">Bing</a>, and seems to have sophisticated virtual machine based analysis tools which can detect misbehaving malicious code. Yahoo employs McAfee&#8217;s Search scan service while Bing potentially uses Microsoft specific technologies.</p>
<p><strong>Experiment Goal</strong></p>
<p>The aim of this experiment is to compare the coverage for each of the blacklists published by Google, Yahoo and Bing and compare them to what users in the Internet believe. To do this we will compare the results of Google, Yahoo, Bing and <a href="http://www.malware.com.br" target="_blank">Malware Patrol</a> with <a href="http://www.mywot.com" target="_blank">Web of Trust (WOT)</a>. Furthermore, we have also tried to see how many of these malicious URLs are also involved in Phishing. We have done this by looking up each URL/domain via <a href="http://www.phishtank.org" target="_blank">Phishtank&#8217;s</a> API.</p>
<p>Blacklists provide an easy mechanism for users (via browsers) and developers (via APIs) to assimilate security information about websites, IPs and such in order to make an informed decision about whether to allow or deny access to an IP or website.</p>
<p><strong>Methodology</strong></p>
<p>We have collected 1095 confirmed malicious links from <a href="http://www.malwareurl.com" target="_blank">MalwareURL</a>. Each of these links was tested to determine if they are listed on blacklists supplied by Google, Yahoo and Bing. Note that Yahoo and Bing unlike Google do not provide any direct APIs to probe their databases. Thereby each link, and its associated domain was pushed via an HTTP request to Yahoo and Bing to analyze if the results indicated that the domain/link was infected.</p>
<p>To determine if a website is present in the Google malware blacklist, the domain name along with the link and its variations, as defined here, are converted to MD5 hashes and checked using Google&#8217;s Safe Browsing API. For Malware Patrol, the aggressive version of their blacklist is downloaded and comparisons are made locally. For WOT, we employ their XML based API to gather information about the belief of users in the Internet. For Phishtank we have used their XML based API. The tests were conducted on Mar 22 2010.</p>
<div id="attachment_1541" class="wp-caption aligncenter" style="width: 295px"><img class="size-full wp-image-1541" title="Comparing blacklists" src="http://www.stopthehacker.com/wp-content/uploads/2010/03/Screenshot.png" alt="Popular blacklists cover only a minuscule percentage of malicious sites." width="285" height="262" /><p class="wp-caption-text">Popular blacklists cover only a minuscule percentage of malicious sites.</p></div>
<p><strong>Highlights</strong></p>
<ul>
<li>Google marked 0.18% of the URLs as unsafe.</li>
<li>Yahoo marked 1.0% of the URLs as unsafe.</li>
<li>Bing marked 0.09% of the URLs as unsafe.</li>
<li>Malware Patrol marked 0.63% of the URLs as unsafe.</li>
<li>Phishtank marked 0% of the URLs as unsafe.</li>
<li>WOT marked 99% of URLs as unsafe.</li>
</ul>
<p>Note: 1095 unique, malicious URLs were tested with each service.</p>
<p><strong>Observations</strong></p>
<p>Interestingly, Web Of Trust (WOT) marked 99% of the URLs with &#8220;poor&#8221; or &#8220;very poor&#8221; or &#8220;unsatisfactory&#8221; reputation. We have to assume that when users will see such a rating they will not visit the website in question and hence treat this kind of rating as unsafe, for the purposes of this test. It remains to be determined if WOT uses a data feed from a malware URL which we have used to prime the test set. Nonetheless, it is surprising to see that a company which specializes in collating the trust and opinions of web surfers performs better orders of magnitude than large Internet companies and established blacklist providers.</p>
<p>One must keep in mind though that Google&#8217;s approach to maintaining an ever changing blacklist is slightly different from the other actors in the game. Google publishes an updated version of its list every 30 minutes or so and specifies which MD5 hashes need to be purged and which ones need to be inserted. Some blacklist services do not take this approach and hence may claim to store information on millions of sites, which were infected at one point in time. The probability of this happening in the Google blacklist is low, because they have opened up a review process via their webmaster central area to update their blacklist.</p>
<p>In contrast, Bing and Yahoo do not provide public APIs for developers and applications to use.</p>
<p>Also, we see that none of the URL/domains were actually listed on Phishtank. It seems that websites which aim to infect users with malware are quite different from the set of sites used for phishing. It does not seem that malware laced websites are also used to commit phishing.</p>
<p><strong>Conclusion</strong></p>
<p>Large Internet companies, some of whom have published effective blacklists, used by many developers and application all over the world, still have a long way to go in order to become truly effective. As we have seen, only minuscule numbers of malicious websites are identified by the blacklist services. WOT seems to be extremely effective at identifying unsafe websites. It remains to be determined whether the data-set used for this test has a large overlap with any of the sources WOT uses to classify websites.</p>
<p>Another interesting result is that it does not seem that websites which aim to infect users with malware are actively involved in phishing campaigns.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/04/06/comparing-blacklists/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hackers Use Google Trends to Poison Searches</title>
		<link>http://www.stopthehacker.com/2010/04/05/google-trends-for-seo-poisoning/</link>
		<comments>http://www.stopthehacker.com/2010/04/05/google-trends-for-seo-poisoning/#comments</comments>
		<pubDate>Mon, 05 Apr 2010 18:49:40 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[poison]]></category>
		<category><![CDATA[seo]]></category>
		<category><![CDATA[trends]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1544</guid>
		<description><![CDATA[Hackers are using a relatively new technique to lure users into visiting malicious websites. SEO poisoning is a method by which hackers can get a malicious link or URL, indexed by a search engine. When users search for terms that match the context of the malicious link, unsuspecting web surfers are often served malicious links [...]]]></description>
			<content:encoded><![CDATA[<p>Hackers are using a relatively new technique to lure users into visiting malicious websites. <a href="http://wiki.answers.com/Q/What_is_an_%27SEO_poisoning_attack%27" target="_blank">SEO poisoning</a> is a method by which hackers can get a malicious link or URL, indexed by a search engine. When users search for terms that match the context of the malicious link, unsuspecting web surfers are often served malicious links which can divert them to harmful websites that commit all kinds of nasty deeds, ranging from ID theft to installing malware.</p>
<p><strong>Overview</strong></p>
<p>SEO poisoning is not new, but it is definitely a <a href="http://www.securityfocus.com/brief/701" target="_blank">growing trend</a>. It is becoming a vector of choice for hackers. The procedure to commit this crime is actually quite similar to the method of code-injection. First, find a vulnerability in the website or hosting infrastructure which will allow a hacker to upload malicious code or modify the behavior of the web application. Once this is achieved a hacker can insert URLs into a web page which will be indexed by search engines such as <a href="http://www.google.com" target="_blank">Google</a>.</p>
<p>Below, we provide a screen shot to illustrate that hackers are reverse-engineering popular keywords from Google search trends to exploit unsuspecting users. In this particular example, the search query is extracted from Google Trends and results clearly show URLs which redirect users to fake anti-virus websites. Unfortunately, few of these URLs are even blacklisted by Google and hence users do not even have the luxury of making a decision to visit an unsafe website or not.</p>
<div class="gallery">
<div id="attachment_1552" class="wp-caption aligncenter" style="width: 282px"><a rel="attachment wp-att-1552" href="http://www.stopthehacker.com/wp-content/uploads/2010/03/google-spam-1.png"><img class="size-medium wp-image-1552" title="An example of SEO poisoning using a search query from Google Trends." src="http://www.stopthehacker.com/wp-content/uploads/2010/03/google-spam-1-272x300.png" alt="An example of SEO poisoning using a search query from Google Trends." width="272" height="300" /></a><p class="wp-caption-text">An example of SEO poisoning using a search query from Google Trends.</p></div>
</div>
<p><strong>Experiment Goal</strong></p>
<p>The aim of this experiment is to identify URLs which are using SEO poisoning.</p>
<p><strong>Methodology</strong></p>
<p>Search results were collected from <a href="http://trends.google.com" target="_blank">Google Trends</a>. Once the search queries were collected, searches were performed via Google and the first  10 results were collected for each search query.</p>
<p>Each search result was analyzed to find whether the URLs displayed in the search results contained the complete search query in the exact same order. Also, it was determined whether the structure of the URL matched patterns of SEO poisoning. Furthermore, the IP associated with the URL was looked up on <a href="http://www.spamcop.net" target="_blank">Spamcop</a> to verify if the IP had been used for sending spam or had participated in zombie networks. Finally, using a geo-location API from <a href="http://ipinfodb.com" target="_blank">IPinfo DB</a>, the country of origin for the URL was determined. The test was conducted on March 23, 2010. Google trend results for the period of January 1, 2010 to March 22, 2010 were used for searches.</p>
<p><strong>Highlights</strong></p>
<ul>
<li>59.5% of search results returned by Google had URLs which contained the entire search string in the same exact order.</li>
<li>26.07% of search results returned by Google had URLs which matched SEO poisoning patterns.</li>
<li>14.1% of search results returned by Google had URLs which matched SEO poisoning patterns and contained the entire search string in the same exact order.</li>
<li>Only one IP seemed to be involved in spam related activity.</li>
<li>Some of the most popular locations for websites returned as search results are: US, Canada, Netherlands, Germany, UK, France, Czech Republic, Australia and Singapore.</li>
</ul>
<p>Note: 10,559 search results were analyzed.</p>
<div id="attachment_1558" class="wp-caption aligncenter" style="width: 352px"><img class="size-full wp-image-1558" title="Percentage of sites from different countries affected by SEO poisoning." src="http://www.stopthehacker.com/wp-content/uploads/2010/03/Screenshot-1-e1270492205955.png" alt="Percentage of sites from different countries affected by SEO poisoning." width="342" height="271" /><p class="wp-caption-text">Percentage of sites from different countries affected by SEO poisoning.</p></div>
<p>Countries which seem to have the highest number of SEO poisoned links indexed by Google:</p>
<ul>
<li>86.1% of URLs from Singapore based sites.</li>
<li>74% of URLs from Netherlands based sites.</li>
<li>30.5% of URLs from UK based sites.</li>
<li>25.1% of URLs from Germany based sites.</li>
<li>12.6% of URLs from Canada based sites.</li>
<li>12.42% of URLs from US based sites.</li>
</ul>
<div id="attachment_1555" class="wp-caption aligncenter" style="width: 453px"><img class="size-full wp-image-1555" title="Fluctuation in the number of SEO poisoned results." src="http://www.stopthehacker.com/wp-content/uploads/2010/03/Screenshot1.png" alt="Fluctuation in the number of SEO poisoned results." width="443" height="285" /><p class="wp-caption-text">Fluctuation in the number of SEO poisoned results.</p></div>
<p>Note the fluctuations in the number of search results which are SEO poisoned.</p>
<p><strong>Conclusion</strong></p>
<p>It is clear that even the world&#8217;s most popular search engine company is not secure from SEO poisoning. It is not for the lack of trying though, but instead of the myriad number of ways hackers can break into a website and take advantage of it. We have seen that large numbers of search results match SEO poisoning patterns. Furthermore, it is clear that hackers are injecting malicious URLs into compromised websites to latch onto Google trends.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/04/05/google-trends-for-seo-poisoning/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Yes, Search Engines Can Infect Your Computer</title>
		<link>http://www.stopthehacker.com/2010/03/08/can-search-engines-infect-your-computer-yes/</link>
		<comments>http://www.stopthehacker.com/2010/03/08/can-search-engines-infect-your-computer-yes/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 17:00:27 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[bing]]></category>
		<category><![CDATA[cache]]></category>
		<category><![CDATA[engine]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[pages]]></category>
		<category><![CDATA[search]]></category>
		<category><![CDATA[yahoo]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1472</guid>
		<description><![CDATA[Search engines, like Google, Yahoo and Bing offer users the ability to scour the plethora of information on the Internet. These search engines index content on websites and often maintain cached copies of these sites so that, in the event that the site is unavailable, visitors can still view the contents of the website.
Unfortunately, the [...]]]></description>
			<content:encoded><![CDATA[<p>Search engines, like <a href="http://www.google.com" target="_blank">Google</a>, <a href="http://search.yahoo.com" target="_blank">Yahoo</a> and <a href="http://www.bing.com" target="_blank">Bing</a> offer users the ability to scour the plethora of information on the Internet. These search engines index content on websites and often maintain cached copies of these sites so that, in the event that the site is unavailable, visitors can still view the contents of the website.</p>
<p>Unfortunately, the idea of page caching has not been implemented well. In fact, page caching has opened up new opportunities for malware. The primary problem being that, from a security perspective, when search engines cache copies of websites, they are storing any malware that is present on the site on their own infrastructure as well.</p>
<h3>Hackers Exploit Search Engine Page Caches</h3>
<p>Most large search engines use some kind of malware analysis to determine if a website is compromised or not. Google for example, has a well tuned system with high accuracy. In our meeting with the Google malware team, some months ago, we were glad to find that they were already aware of this problem. In the weeks following our interaction, cached copies of infected websites were no longer easily available via searches.</p>
<p>Not so long ago, we wrote an article about <a href="http://www.stopthehacker.com/2009/11/25/yahoo-hosting-malware-are-you-serious/" target="_blank">our efforts to alert Yahoo</a> of the presence of malware in the cached versions of various web pages served up by their search engine. Our efforts were not successful, although the occurrence of malware in Yahoo cached pages seems to have gone down significantly. Perhaps our messages were not entirely ignored.</p>
<p>Recently, an article came up on <a href="http://isc.sans.org/diary.html?storyid=7768&amp;" target="_blank">ISC SANS</a> discussing this very same issue.</p>
<p>Recently, we have found instances of Bing serving up malware in their cached pages. It seems that Bing&#8217;s malware detection methods are not able to reliably detect malware on cached web pages. This keeps Bing from securing cached pages which contain malware for its users. We have provided screen shots below as an example of the issue. In this particular case, the strain of malware found in Bing cached pages has been around since 2009.</p>
<h3>Search Engines Ignore the Problem</h3>
<p>Consider the case where a malicious individual deliberately infects a website with malware and Bing (or another search engine) indexes it. The malicious individual can then send out hyperlinks pointing to the cached web pages hosted by Bing. Any kind of &#8220;reputation-checking&#8221; for the cached link will confirm that the page is hosted by a reputable company, in this case, Bing (Microsoft). However, the malware will still be able to deliver its payload. Just in case you&#8217;re thinking, &#8220;my antivirus will protect me from the malware on the cached page,&#8221; you may like to <a href="http://www.stopthehacker.com/2009/12/11/catch-me-if-you-can-antivirus-poor-at-detecting-web-malware/" target="_blank">read this article</a>.</p>
<p>It is surprising to see that search engines like Bing, which claim to implement malware detection, cannot correctly determine if a cached copy of a web page hosts malware! In these cases, Bing ends up an excellent attack vector for malicious individual.</p>
<p>It remains to be seen if search engine companies will continue to serve up cached pages laced with malware at the same time as they are touting active scan and detection mechanisms. Let&#8217;s hope this article can get attention in the upper echelons of management at these large search giants and they start to pay attention to this problem.</p>
<p><strong>Screen shots follow below:</strong></p>

<a href='http://www.stopthehacker.com/2010/03/08/can-search-engines-infect-your-computer-yes/bing_cache_malware_1/' title='Cache page served up Bing: contains Malware'><img width="150" height="150" src="http://www.stopthehacker.com/wp-content/uploads/2010/03/bing_cache_malware_1-150x150.jpg" class="attachment-thumbnail" alt="" title="Cache page served up Bing: contains Malware" /></a>
<a href='http://www.stopthehacker.com/2010/03/08/can-search-engines-infect-your-computer-yes/malware/' title='Malware in source code of cached page served by Bing'><img width="150" height="150" src="http://www.stopthehacker.com/wp-content/uploads/2010/03/malware-150x150.png" class="attachment-thumbnail" alt="" title="Malware in source code of cached page served by Bing" /></a>

]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/03/08/can-search-engines-infect-your-computer-yes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;Online Pharmacy&#8221; Spam Stalks Internet Forums/Boards</title>
		<link>http://www.stopthehacker.com/2010/01/26/analyzing-online-pharmacy-spam/</link>
		<comments>http://www.stopthehacker.com/2010/01/26/analyzing-online-pharmacy-spam/#comments</comments>
		<pubDate>Tue, 26 Jan 2010 17:00:20 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[Company]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[online pharmacy spam]]></category>
		<category><![CDATA[safebrowsing]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1143</guid>
		<description><![CDATA[Malicious hackers have, for many years, been offering services to unscrupulous individuals and companies for monetary compensation. With the growth of Email Spam advertising everything from medical supplements to cars and lottery tickets, email scrubbers and filters have taken the game up a notch by implementing ever increasing layers of complexity to cut down on [...]]]></description>
			<content:encoded><![CDATA[<p>Malicious hackers have, for many years, been offering services to unscrupulous individuals and companies for monetary compensation. With the growth of Email Spam advertising everything from medical supplements to cars and lottery tickets, email scrubbers and filters have taken the game up a notch by implementing ever increasing layers of complexity to cut down on such spam. In turn, hackers have started to focus on advertising spam, such as medication and fraudulent scams by compromising web-based message boards and forums.</p>
<p><strong>Hackers employ two basic techniques:</strong></p>
<ul>
<li>Creating large numbers of users on forums. These accounts are then used to post spam on the message boards.</li>
<li>Exploiting Web Application vulnerabilities in the software used to run the forum.</li>
</ul>
<p>Approximately two weeks ago, <a href="http://zeltser.com/" target="_blank">Lenny Zeltser</a>, from <a href="http://isc.sans.org" target="_blank">ISC SANS</a>, posted an informative <a href="http://isc.sans.org/diary.html?storyid=8032" target="_blank">article</a> about online pharmacy ads popping up on message boards. In this vein we have conducted a limited experiment with about 14,000 websites which contain spam announcing online pharmacies.</p>
<p><strong>The aim of the experiment:</strong></p>
<ul>
<li>What percentage of websites which advertise online pharmacies are message boards and Internet forums?</li>
<li>What Web Applications, e.g. CMS packages, are used on the message boards that are compromised?</li>
</ul>
<p>We believe this will provide us with a rough estimate of how focused are hackers toward using message boards and forums on the Internet to advertise spam. From another perspective, it will provide us some idea of how vulnerable websites are if it hosts a message board or forum from being abused by hackers.</p>
<p><strong>Testing methodology:</strong></p>
<p>We have used <a href="http://www.google.com" target="_blank">Google</a> to mine the websites which contain certain keyword patterns such as &#8220;buy zocor online&#8221;, or &#8220;buy brand kamagra online&#8221; etc. Once the links suggested by <a href="http://www.google.com/" target="_blank">Google</a> were mined, each of the websites was tested against <a href="http://www.google.com/tools/firefox/safebrowsing/" target="_blank">Google&#8217;s Safe Browsing List</a> to determine if they had hosted malware (according to Google). Next, an analysis was done to determine if the link(s) mined from <a href="http://www.google.com/" target="_blank">Google</a> pointed to a forum or message board. This was done by identifying the presence of multiple strings inside a link. For example, if a link has the keywords &#8220;topic&#8221;, &#8220;view&#8221;, &#8220;thread&#8221; or similar keywords, including characters associated with dynamic page generation, it is probably hosting a message board or forum.</p>
<p>The test was conducted between January 21st and January 23rd, 2010.</p>
<div id="attachment_1150" class="wp-caption aligncenter" style="width: 427px"><img class="size-full wp-image-1150" title="Popular software packages installed on compromised forums and message boards." src="http://www.stopthehacker.com/wp-content/uploads/2010/01/pharmacy_spam_cms.jpeg" alt="Popular software packages installed on compromised forums and message boards." width="417" height="389" /><p class="wp-caption-text">Popular software packages installed on compromised forums and message boards.</p></div>
<p><strong>We present the most interesting results below:</strong></p>
<ul>
<li>47.9% of websites displaying &#8220;online pharmacy&#8221; spam are message boards and forums.</li>
<li>None of the websites advertising &#8220;online pharmacy&#8221; spam were listed on <a href="http://www.google.com/tools/firefox/safebrowsing/" target="_blank">Google Safe Browsing List</a>.</li>
<li>20.28% of forums displaying &#8220;online pharmacy&#8221; spam were using Jquery.</li>
<li>15.73% of forums displaying &#8220;online pharmacy&#8221; spam were using phpBB.</li>
<li>11.54% of forums displaying &#8220;online pharmacy&#8221; spam were using WordPress.</li>
<li>10.84 % of forums displaying &#8220;online pharmacy&#8221; spam were using Mootools.</li>
</ul>
<p>These results and other software packages, helper-scripts, tracking-code are depicted in the graph presented above.</p>
<p>This small experiment shows that a high percentage of websites displaying online spam campaigns are message boards or forums. This indicates that there are many unsecured software installations and older software packages still in use which are often exploited by malicious individuals to post spam. Further, it seems that most sites which were hacked are using jQuery. This supports <a href="http://www.stopthehacker.com/2009/12/09/when-benign-scripts-attack-v/" target="_blank">our previous observations</a> regarding jQuery scripts being used to push malware to unsuspecting visitors.</p>
<p><span id="more-1143"></span><br />
<strong>Below we present some sample links which lead to &#8220;online pharmacy&#8221; spam ads:</strong></p>
<p>We strongly suggest that you do not visit the below sites.</p>
<pre class="brush: plain;">
hxxp://agingparents.com/blog/wp-comments.php?id_comments=1041
hxxp://agnitech.net/forums/viewtopic.php?f=2&amp;t=426
hxxp://altlingo.com/community/members/zocor+online+24q.aspx
hxxp://aslansin.com/members/zocor-package-insert-26i/default.aspx
hxxp://beanbol.com/purchase-zocor-(simvastatin)-40-mg.html
hxxp://beanbol.com/zocor-(simvastatin)-20-mg.html
hxxp://blog.firestats.cc/
hxxp://blog.firestats.cc/49
hxxp://blogs.bet.com/music/soundOff/about/?cp=13
hxxp://blogs.greenpeace.ca/?proto=713
hxxp://blogs.greenpeace.ca/?proto=715
hxxp://blogs.inquirer.net/happynest/2009/10/09/just-sing/
hxxp://boards.tx-outdoors.com/viewtopic.php?f=2&amp;t=467
hxxp://buy-cheap-zocor.hi5.com/
hxxp://cheapzocor.com/
hxxp://cheapzocor.com/about/
hxxp://coilhouse.net/?deppsa=710
hxxp://coilhouse.net/?deppsa=715
hxxp://community.burton.com/members/zocor+interaction+10a.aspx
hxxp://en.netlog.com/clan/BuyZocorOnline
hxxp://en.netlog.com/clan/zocor
hxxp://eostrava.cz/post-80523-cheap-zocor/
hxxp://f5fest.com/?p=50
hxxp://fans.askaninja.com/profiles/blogs/buy-zocor-no-prescription-buy
hxxp://feedblogger.net/members/cost-zocor-68l.aspx
hxxp://foros.canaljuegos.com/index.php?topic=1067891.0
hxxp://foro.toplatino.net/viewtopic.php?f=3&amp;t=17031
hxxp://forsale.oodle.com/view/buy-zocor-online-and-treat-the-cholesterol-problems/1763399272-seattle-wa/
hxxp://forum.asian-autoparts.eu/viewtopic.php?p=4234&amp;sid=82d1fc8ea8bf7189150dda0674d1d9b0
hxxp://forum.atiz.com/index.php?topic=362.msg665;topicseen
hxxp://forum.autonews.fr/index.php?showtopic=43369&amp;view=getlastpost
hxxp://forum.jiwang.org/index.php?showtopic=44638
hxxp://forum.lugarcerto.com.br/viewtopic.php?f=13&amp;t=1022
hxxp://forum.ronatvan.com/index.php?action=printpage;topic=3171.0
hxxp://forum.ronatvan.com/index.php?topic=3171.0
hxxp://forums.solmetra.com/viewtopic.php?f=2&amp;t=67911
hxxp://forums.solmetra.com/viewtopic.php?f=3&amp;t=48102
hxxp://forum.tag-board.com/showthread.php?p=70359
hxxp://forum.tarad.com/index.php?action=printpage;topic=23901.0
hxxp://forum.vachealait.com/viewtopic.php?f=3&amp;t=123806
hxxp://forum.vachealait.com/viewtopic.php?f=5&amp;t=124103
hxxp://forum.vladimirmedvedev.com/index.php?topic=190.0
hxxp://forum.vortue.com/showthread.php?p=114540
hxxp://gallopinghillcaterers.com/?page=buy-online-zocor&amp;f=1262906101
hxxp://gameinformer.com/blogs/members/b/buy_zocor_warnings_blog/archive/2009/12/18/buy-zocor-warnings-pu4.aspx
hxxp://gameinformer.com/members/zocor_2D00_online/default.aspx
hxxp://gfestival.com/?pages=157
hxxp://gfestival.com/?pages=65
hxxp://grabhot.com/index.php?topic=2537.0
hxxp://groups.adobe.com/posts/534b2ec31b
hxxp://harvardcitizen.com/?zine=1144
hxxp://harvardcitizen.com/?zine=4200
hxxp://historias.masoportunidades.com.ar/?page_navg=3879
hxxp://ibls.com/cs/members/zocor+pricing+44n.aspx
hxxp://identi.ca/andres250
hxxp://identi.ca/zachery328
hxxp://innfromthenight.com/forum/viewtopic.php?f=28&amp;t=57971&amp;p=60406
hxxp://jackpenate.com/forum/viewtopic.php?pid=16485
hxxp://leegibbons.com/formbuilder/web/pharmacy/zocor/p=tricor-zocor.html
hxxp://letterheadforemail.com/Zocor.html
hxxp://mabonline.net/tablets-zocor-(simvastatin)-5-mg.html
hxxp://mabonline.net/zocor-(simvastatin)-for-sale.html
hxxp://matadornetwork.com/
hxxp://my.superbasket.gr/viewtopic.php?f=4&amp;t=1562&amp;p=2139
hxxp://naturalpet-com.safepages.com/showthread.php?t=1071
hxxp://networking.bizjournals.com/Jonny2
hxxp://noprescriptiononlinepharmacy.ca/zocor.html
hxxp://pastebin.ca/1743811
hxxp://pornknight.com/zocor-depression-t14855.html
hxxp://posterous.com/people/37qTcxHC297r
hxxp://punkrock.org/buyzocoronline1075&amp;v=comments
hxxp://ranahan.dephan.go.id/forum/viewtopic.php?f=2&amp;t=6803
hxxp://responsiblemarketing.com/blog/?generic=3880
hxxp://room.vicman.net/viewtopic.php?f=2&amp;t=147874
hxxp://room.vicman.net/viewtopic.php?f=4&amp;t=147047
hxxp://technorati.com/blogs/zocorlinks.blogspot.com
hxxp://thebristolfestival.org/README.php?tbf=746
hxxp://theevonyforum.com/online-zocor-purchase-buy-cheap-zocor-t433.html?sid=c64462e6e1214d18ea22e365c76aa13d
hxxp://thisis50.ning.com/forum/topics/buy-zocor-from-a-usa-pharmacy
hxxp://tk-twk.nets.hk/viewtopic.php?f=42&amp;t=11427
hxxp://tohanschik.ru/viewtopic.php?t=1380&amp;view=previous&amp;sid=5ccac30f7095c3421d89b8a3c16a23a4
hxxp://twit88.com/home/node/10289
hxxp://virb.com/rushots/posts/text/6881665
hxxp://visualstudiogallery.msdn.microsoft.com/it-IT/4ec90b81-93e4-4435-b627-4410e6028af9?persist=True
hxxp://webradiocharts.eu/forum/viewtopic.php?f=4&amp;t=376
hxxp://wiki.pylonshq.com/display/~heetley/BUY+Zocor+LOWEST+prices+NOW
hxxp://wiki.pylonshq.com/display/~heetley/BUY+Zocor+LOWEST+prices+NOW?showComments=true&amp;showCommentArea=true
hxxp://www.247-pharmacy.com/buy/zocor.php
hxxp://www.abbeyproperties.co.uk/config.php?set_user=1&amp;s=1264
hxxp://www.abbeyproperties.co.uk/config.php?set_user=1&amp;s=1996
hxxp://www.aldaracreamonline.co.uk/buy-zocor.htm
hxxp://www.antidepressantscheaper.com/
hxxp://www.aperitto.com/support/forum/12-emr-suite/511-meridian-two-bit-pharmacy-appraiser-it
hxxp://www.articlesbase.com/health-articles/online-pharmacy-offers-the-most-competitive-prices-on-zocor-869351.html
hxxp://www.atalasoft.de/cs/members/zocor+400+mg+53b.aspx
hxxp://www.avatarpress.com/2010/01/22/post-80540-buy-zocor/
hxxp://www.blogged.com/topics/zocor/
hxxp://www.bowlofcereal.net/viewtopic.php?f=5&amp;t=99
hxxp://www.brbooks.co.uk/zocor-(simvastatin)-10-mg-free-shipping.html
hxxp://www.canadianhealthcaremall.net/drug-zocor123.shtml
hxxp://www.canamericaglobal.com/products/Zocor/20/
hxxp://www.chemistdirect.co.uk/zocor-simvastatin-10-mg-tablets_4_12038.html
hxxp://www.chemistdirect.co.uk/zocor-simvastatin-40-mg-tablets_4_12040.html
hxxp://www.chop.edu/forum/user/profile/12110.page
hxxp://www.clockworkpharmacy.com/zocor-heart-pro-tablets-10mg.html
hxxp://www.copykatchat.com/
hxxp://www.cruisersforum.com/forums/members/inxgwo32-30799.html
hxxp://www.daanbantayan.gov.ph/dbforums/viewtopic.php?f=26&amp;t=43370
hxxp://www.daanbantayan.gov.ph/dbforums/viewtopic.php?f=28&amp;t=43373
hxxp://www.divingleisurelondon.co.uk/forum/online-zocor
hxxp://www.drugs-s.com/product-35-prd_12.html
hxxp://www.elakiri.com/forum/showthread.php?p=6341304
hxxp://www.europeanirish.com/index.php?med_id=buy-zocor-(simvastatin)-10-mg
hxxp://www.europeanirish.com/index.php?med_id=buy-zocor-(simvastatin)-40-mg
hxxp://www.fastcompany.com/tag/pharmacy
hxxp://www.feld.com/blog/archives/2007/02/buy-zocor-online.html
hxxp://www.feld.com/blog/archives/2007/02/online-buy-zocor-without-a-prescription.html
hxxp://www.fioricetpharmacy.info/product.php?prod=Zocor
hxxp://www.flexyx.com/Z/Zocor.html
hxxp://www.folkd.com/go/zocor+lipitor
hxxp://www.forkncork.com/?p=80540
hxxp://www.forkncork.com/?p=80544
hxxp://www.freecodesource.com/user/profile-354708.html
hxxp://www.freecodesource.com/user/profile-354802.html
hxxp://www.genbrand-rx.com/Zocor.html
hxxp://www.genericmedsfromcanada.com/
hxxp://www.genericmedsfromcanada.com/ZOCOR_80_mg_GENERIC_SIMVASTATIN_80_mg_28_Tabs_p/sim0753b.htm
hxxp://www.genericsmed.com/buy-cheap-generic-zocor-simvastatin-p-21.html
hxxp://www.genv.net/en-us/node/10875
hxxp://www.giustiziere.org/viewtopic.php?f=7&amp;t=10277
hxxp://www.globaltrainingcenter.com/news.php?node=1412
hxxp://www.globaltrainingcenter.com/news.php?node=682
hxxp://www.goprocamera.com/admin/_js/tiny_mce/themes/advanced/files/buying-zocor-legally.html
hxxp://www.goprocamera.com/admin/_js/tiny_mce/themes/advanced/files/buy-zocor-without-a-prescription.html
hxxp://www.gradcats.org/index.php?option=com_content&amp;view=section&amp;layout=blog&amp;id=1&amp;Itemid=2&amp;node=2156
hxxp://www.gradcats.org/index.php?option=com_content&amp;view=section&amp;layout=blog&amp;id=1&amp;Itemid=2&amp;node=3753
hxxp://www.gripenet.pt/blog/?p=80521
hxxp://www.gripenet.pt/blog/?p=80528
hxxp://www.hcs.harvard.edu/~salient/site/?menus=715
hxxp://www.hip-hop.net/profile/buyzocorG9FG
hxxp://www.hip-hop.net/profile/Fredmd
hxxp://www.hkcd-team.net/viewtopic.php?f=7&amp;t=284
hxxp://www.ibiblio.org/agray/brushd/cheapest-price-for-zocor-40-mg.html
hxxp://www.ibiblio.org/agray/brushd/does-effect-have-libido-womens-zocor.html
hxxp://www.inansurucukursu.com/inan/forum/index.php?topic=2153.0;wap2
hxxp://www.inyoursuburb.com.au/forum/viewtopic.php?f=25&amp;t=12069
hxxp://www.ipetitions.com/petition/buy_ambien_online_480/
hxxp://www.kucasnova.net/index.php?topic=1911.0
hxxp://www.kucasnova.net/index.php?topic=2378.0
hxxp://www.last.fm/user/zocor7103
hxxp://www.lerpg.com/forum/index.php?topic=1716.0
hxxp://www.livestrong.com/zocor-side-effects/
hxxp://www.mahalo.com/answers/drugs/where-can-you-buy-lipitor-online-is-it-cheaper
hxxp://www.makingthings.com/wiki/document.zocor-online-order
hxxp://www.masterseek.com/q/Zocor/0/1/Zocor.htm
hxxp://www.mathleagueforum.com/viewtopic.php?f=2&amp;t=41
hxxp://www.menieresforum.com/?q=node/132
hxxp://www.michwine.com/index.php?Itemid=148&amp;option=com_jcalpro&amp;Subitem=3562
hxxp://www.michwine.com/index.php?Itemid=148&amp;option=com_jcalpro&amp;Subitem=773
hxxp://www.mister-wong.com/topics/zocor/
hxxp://www.mombu.com/hdtv/hdtv/t-buy-lipitor-online-no-prescription-needed-3828654.html
hxxp://www.mypage.com/buyzocor862/extendedprofile
hxxp://www.nfu.org/forum/archive/index.php?t-20956.html
hxxp://www.numberstemplates.com/forums/showthread.php?t=977
hxxp://www.offshorerx.com/drug/buy_generic_zocor.htm
hxxp://www.online-drugstore-usa.com/cheap_cardiovascular_prices/buy_generic_zocor_pills
hxxp://www.onlinepillspro.com/buy/zocor.html
hxxp://www.oxygenoverkill.com/forum/viewtopic.php?f=2&amp;t=15
hxxp://www.pharmacyescrow.com/s3737-s-ZOCOR.aspx
hxxp://www.pharmacyescrow.com/s41524-s-ZOCOR.aspx
hxxp://www.photography-now.net/help/index?no-rx=1475
hxxp://www.photography-now.net/katja_oluscha_grunther/index?no-rx=3348
hxxp://www.pillsforall.com/cholesterol-lowering/zocor-40mg-generic-x-60/prod_57.html
hxxp://www.pillwatch.com/product/zocor/
hxxp://www.postnewsline.com/2009/04/the-post-new-website.html
hxxp://www.praktikum.de/forum/online-zocor-purchase-prescription-zocor-t12436.html
hxxp://www.psicologico.cl/?favorite=4356
hxxp://www.pyzam.com/profile/3304209
hxxp://www.pyzam.com/profile/3304382
hxxp://www.rfidtalk.com/showthread.php?p=19119
hxxp://www.rottentomatoes.com/vine/showthread.php?p=16528906
hxxp://www.rottentomatoes.com/vine/showthread.php?t=709353
hxxp://www.scribd.com/doc/25364786/buy-cheap-Generic-Zocor-Simvastatin-20mg-online-without-prescription
hxxp://www.server2go-web.de/forumng/index.php?topic=111147.0
hxxp://www.spurs11.com/forum/showthread.php?t=69947
hxxp://www.teamhallpass.com/2010/01/post-80522-buy-zocor/
hxxp://www.teamhallpass.com/2010/01/post-80527-about-zocor/
hxxp://www.technieuws.org/?p=83598
hxxp://www.technieuws.org/?p=83620
hxxp://www.tempuspharmacy.org/zocor-drug-information.html
hxxp://www.theartofthepossible.net/?p=83620
hxxp://www.theunforsaken.com/viewtopic.php?f=3&amp;t=7668&amp;p=8971
hxxp://www.thisis50.com/xn/detail/784568:Topic:18648223?xg_source=activity
hxxp://www.travelersnation.com/forum/post774.html
hxxp://www.tumblr.com/tagged/saints+&amp;amp%3B+sinners
hxxp://www.twit88.com/home/node/10117
hxxp://www.valuepharmaceuticals.com/medicine/index.php
hxxp://www.wehopres.org/?p=83620
hxxp://www.wikio.com/article/122956318
hxxp://www.wikio.com/sports/football/football_players/michael_koenen
hxxp://www.wizard101.pl/forum/buy-zocor-drugs-online-zocor-t296.html
hxxp://www.world-drugs.net/order_generic_zocor.php
hxxp://www.xlpharmacy.com/
hxxp://www.xlpharmacy.com/generic-zocor/
hxxp://www.zenpharmacy.com/Zocor/buy-prescription-Zocor-online.html
hxxp://zocoronline130.typepad.com/blog/2010/01/buy-zocor-estrogen.html
hxxp://36poker.ru/forum/index.php?topic=2188.0
hxxp://ad-bu.chavalar.com/forum/index.php?topic=124.0
hxxp://alexatutor.com/viewtopic.php?f=2&amp;t=838&amp;p=915
hxxp://articlet.com/article7179.html
hxxp://bb.obscurusfio.com/index.php?topic=279.msg406
hxxp://bb.peak2010.org/viewtopic.php?f=2&amp;t=31619
hxxp://bbs.qqcipher.com/viewtopic.php?f=2&amp;t=51
hxxp://benthanhgold.com/forum/viewtopic.php?f=8&amp;t=1487
hxxp://biblioteca.uniminuto.edu/index.php/biblioteca-en-cifras/1297?task=view&amp;page=975
hxxp://bigcuzinent.com/forum/index.php?topic=29.0
hxxp://blog.see3.net/?p=484
hxxp://blogs.inquirer.net/m-ph/2008/08/29/nikon-d90-official-1st-dslr-with-hd-video-recording/
hxxp://boards.tx-outdoors.com/viewtopic.php?f=2&amp;t=343
hxxp://buycheapviagra.ca/kamagra.html
hxxp://buycialis20mg.com/buy-kamagra-soft-tabs.htm
hxxp://buy-kamagra-online.net/
hxxp://carolinadelnorte.jomc.unc.edu/?optin=com_pharma&amp;rr=buy-kamagra-viagra-india.php
hxxp://carolinaweek.jomc.unc.edu/?option_pharma=viagra-uk-kamagra.php
hxxp://centovacast.com/viewtopic.php?f=9&amp;t=182
hxxp://centovacast.com/viewtopic.php?f=9&amp;t=218
hxxp://chemisaxli.gov.ge/forum/viewtopic.php?id=76060
hxxp://citkim.phpbboy.com/viewtopic.php?f=2&amp;t=734&amp;p=734
hxxp://community.bonnaroo.com/service/displayKickPlace.kickAction?u=13803616&amp;as=12058
hxxp://community.essence.com/forum/topics/how-to-buy-online-kamagra
hxxp://cooperation-of-benzin.de/viewtopic.php?f=2&amp;t=3726
hxxp://district9140ng.org/index.php?topic=11.0
hxxp://ekkanisayoluganda.org.uk/furum/index.php?topic=19289.0
hxxp://essenceonline.ning.com/forum/topics/buy-kamagra-drugsorder-chep
hxxp://fahrerservice.org/viewtopic.php?f=2&amp;t=1830
hxxp://fanclub.darabubamara.eu/viewtopic.php?f=3&amp;t=2701
hxxp://fanclub.darabubamara.eu/viewtopic.php?f=4&amp;t=2687
hxxp://feelmaldives.com/forum/viewtopic.php?f=2&amp;t=36
hxxp://foorum.kundaliniyoga.ee/viewtopic.php?f=2&amp;t=5526
hxxp://fora.an-archos.com/viewtopic.php?t=134335&amp;sid=f3287141aaa40ea1970e3e8d53279b27
hxxp://forocientifico.com/viewtopic.php?f=2&amp;t=179
hxxp://foros.comfusion.es/index.php?topic=675.0
hxxp://forum.acme.nu/index.php?topic=12.0
hxxp://forum.ampirstyle.ru/viewtopic.php?f=6&amp;t=53
hxxp://forumas.vtv.lt/index.php?topic=4192.0
hxxp://forum.atlaspronet.net/showthread.php?t=80150
hxxp://forum.autonews.fr/index.php?showtopic=42109&amp;view=getlastpost
hxxp://forum.auto.ro/showthread.php?t=505005
hxxp://forum.cudaswiata.pl/viewtopic.php?f=6&amp;t=488
hxxp://forum.cudaswiata.pl/viewtopic.php?f=7&amp;t=485
hxxp://forum.dayment.com/viewtopic.php?f=14&amp;t=19
hxxp://forum.delifisek.net/index.php?topic=6.0
hxxp://forum.djlanka.com/viewtopic.php?f=2&amp;t=20547
hxxp://forum.egypt.com/enforum/programming-languages-f84/buy-cheap-generic-kamagra-online-kamagra-no-prescription-39580.html
hxxp://forum.faazmagazine.com/index.php?topic=153.0
hxxp://forum.familyguy.cz/viewtopic.php?f=6&amp;t=1215
hxxp://forum.fsbw.de/viewtopic.php?f=1&amp;t=543
hxxp://forum.geotorrents.com/index.php?showtopic=455183&amp;view=getnewpost
hxxp://forum.gwteambuilder.de/index.php?topic=1516.0
hxxp://forum.im1music.net/index.php?topic=13695.0
hxxp://forum.jurutera.net/viewtopic.php?f=5&amp;t=6
hxxp://forum.jzip.com/archive/index.php/t-194030.html
hxxp://forum.livetoride.cz/viewtopic.php?f=2&amp;t=5
hxxp://forum.masseriadelpino.it/viewtopic.php?f=2&amp;t=850
hxxp://forum.matura.pl/viewtopic.php?f=4&amp;t=17054
hxxp://forum.matura.pl/viewtopic.php?f=7&amp;t=17150
hxxp://forum.montages-electroniques.com/viewtopic.php?t=5824&amp;sid=a19708674cddb891449e7c154a5fbaaa
hxxp://forum.muzsweet.com/viewtopic.php?f=4&amp;t=3502&amp;p=23454
hxxp://forum.opensourceassets.com/index.php?topic=10.0
hxxp://forum.parrucchieritalia.it/viewtopic.php?f=3&amp;t=1374
hxxp://forum.plovdivairport.com/index.php?topic=8792.0
hxxp://forum.pngarnet.ac.pg/viewtopic.php?f=2&amp;t=36593
hxxp://forum.pngarnet.ac.pg/viewtopic.php?f=2&amp;t=36701
hxxp://forum.polymus.ru/index.php?topic=2345.0;wap2
hxxp://forum.rimsketoplice.net/viewtopic.php?f=5&amp;t=721
hxxp://forums.beerke.nl/viewtopic.php?f=4&amp;t=4319
hxxp://forums.deviationsonline.com/viewtopic.php?f=7&amp;t=407
hxxp://forums.deviationsonline.com/viewtopic.php?f=7&amp;t=421
hxxp://forum.sibautobroker.ru/viewtopic.php?f=5&amp;t=4
hxxp://forums.salug.org/index.php?action=printpage;topic=286.0
hxxp://forums.stevengould.org/viewtopic.php?t=37126&amp;sid=964c4c68b15e636529dbd54f2ab791a3
hxxp://forum.ti.itb.ac.id/index.php?topic=2844.0
hxxp://forum.toniderassi.com/viewtopic.php?f=5&amp;t=25
hxxp://forum.transimagovideo.com/index.php?topic=34.0
hxxp://forum.ultravnc.fr/index.php?topic=2274.0
hxxp://forum.wayfinder.com/index.php?topic=40.0;wap2
hxxp://generics-sale.com/product/kamagra-soft-flavoured.html
hxxp://generic-viagra-kamagra.com/
hxxp://generic-viagra-kamagra.com/kamagra.php
hxxp://habbo-aktuell.net/forum/viewtopic.php?f=5&amp;t=1640
hxxp://heldentaten-gilde.com/viewtopic.php?f=6&amp;t=41
hxxp://innfromthenight.com/forum/viewtopic.php?f=14&amp;t=52817
hxxp://jeepinohio.com/forum/viewtopic.php?f=8&amp;t=3712
hxxp://khaz.de/viewtopic.php?f=2&amp;t=1051
hxxp://knolstuff.com/forum/topics/buy-kamagra-online-1
hxxp://laissezfaire.ru/viewtopic.php?f=3&amp;t=4282
hxxp://laser-inkjet-labels.com/viewtopic.php?f=2&amp;t=228
hxxp://laser-inkjet-labels.com/viewtopic.php?f=2&amp;t=57
hxxp://legalrxlist.com/
hxxp://letterheadforemail.com/Kamagra.html
hxxp://medicine.bizrate.co.uk/oid651048929.html
hxxp://medicine.bizrate.co.uk/oid651048949.html
hxxp://messageboard.wrolc.org/index.php?action=printpage;topic=2811.0
hxxp://messageboard.wrolc.org/index.php/topic,2811.msg2826.html
hxxp://my.superbasket.gr/viewtopic.php?f=4&amp;t=1592
hxxp://online-pill-store.com/
hxxp://paintballtokod.hu/forum/viewtopic.php?f=2&amp;t=6
hxxp://permai.gov.my/forum/viewtopic.php?f=3&amp;t=22558
hxxp://picpost.rootsee.com/index.php?topic=150.0
hxxp://pokerqc.ca/viewtopic.php?f=4&amp;t=667
hxxp://poradny.rodinaaja.cz/viewtopic.php?f=4&amp;t=703
hxxp://pravoedelo-spb.ru/forum/viewtopic.php?f=2&amp;t=5
hxxp://program.kralchat.net/kamagra.html
hxxp://realmomsguide.sheknows.com/?q=kamagra
hxxp://redrum-demos.net/forum/index.php?topic=672.0;wap2
hxxp://registrar.fiu.edu/typo3_cache/a/index.html
hxxp://rozbeans.com/forum/viewtopic.php?p=15276
hxxp://sietereinos.com/viewtopic.php?f=8&amp;t=10
hxxp://sitagu.info/community/index.php?topic=49.0
hxxp://slowebdev.net/viewtopic.php?f=4&amp;t=6
hxxp://snsdfan.com/forum/viewtopic.php?f=2&amp;t=4
hxxp://socbaytravel.com/forum/viewtopic.php?f=4&amp;t=603
hxxp://socbaytravel.com/forum/viewtopic.php?f=4&amp;t=697
hxxp://sonsofanarchyboards.com/viewtopic.php?f=2&amp;t=12
hxxp://sorsogon.gov.ph/discussion/viewtopic.php?f=2&amp;t=47576
hxxp://southernorcleague.com/forums/index.php?topic=149.0
hxxp://spainleds.com/viewtopic.php?f=2&amp;t=965
hxxp://tatilyorum.net/viewtopic.php?f=2&amp;t=7
hxxp://techexchange.packeteer.com/viewtopic.php?f=4&amp;p=18467
hxxp://theevonyforum.com/post1915.html
hxxp://thememoryhole.org/?s=kandu+v
hxxp://thewallsoflove.com/forums/viewtopic.php?f=4&amp;t=8
hxxp://thisis50.ning.com/xn/detail/784568:Topic:18422720?xg_source=activity
hxxp://thisis50.ning.com/xn/detail/784568:Topic:18869853?xg_source=activity
hxxp://tra.tools4noobs.com/support-f2/where-buy-kamagra-online-the-lowest-drugs-online-offers-t88.html
hxxp://twit88.com/home/node/9933
hxxp://velociteen.com/forum/index.php?action=printpage;topic=1643.0
hxxp://virb.com/cialiss91m
hxxp://vitsearkiv.net/viewtopic.php?f=9&amp;t=34
hxxp://waltham2.financialchat.com/blogs/online-generic-kamagra-without-prescription
hxxp://web.kc.ac.th/viewtopic.php?f=2&amp;t=1454
hxxp://web.kc.ac.th/viewtopic.php?f=2&amp;t=1578
hxxp://www.365pharmacy.co.uk/
hxxp://www.3tabs.com/viagra/kamagra.html
hxxp://www.acauch.com/foro/viewtopic.php?f=2&amp;t=4
hxxp://www.alismed.com/
hxxp://www.arvuroma.it/forum/viewtopic.php?f=2&amp;t=2131
hxxp://www.bacila.com/forum/viewtopic.php?f=3&amp;t=3925
hxxp://www.backyardsteamtrains.com/viewtopic.php?f=2&amp;t=659
hxxp://www.bellspharmacy.com/
hxxp://www.bellspharmacy.com/category/4/kamagra.html
hxxp://www.bestpharmacy4u.com/kamagra/
hxxp://www.blogcatalog.com/topic/buy+kamagra+oral+jelly+uk/
hxxp://www.blogcatalog.com/topic/kamagra+100mg/
hxxp://www.britishsteelcollection.org.uk/index.php?option=com_contact&amp;view=contact&amp;id=6:community&amp;catid=45:sponsors&amp;Itemid=59
hxxp://www.bvkportal.com/phpbb3/viewtopic.php?f=4&amp;t=20
hxxp://www.carolinamartialartsforum.com/viewtopic.php?f=7&amp;t=39
hxxp://www.caverta-silagra.com/
hxxp://www.cheapest-prescription-drugs.biz/
hxxp://www.classicrockmagazine.com/forum/viewtopic.php?f=4&amp;t=733&amp;p=8913
hxxp://www.classicrockmagazine.com/forum/viewtopic.php?f=9&amp;p=8914
hxxp://www.clubprivedesire.com/forum/viewtopic.php?f=6&amp;t=257
hxxp://www.coffeeshopnieuwvennep.nl/viewtopic.php?f=2&amp;t=471
hxxp://www.columbusunderground.com/wonder-bread-bakery-in-italian-village-to-close
hxxp://www.daanbantayan.gov.ph/dbforums/viewtopic.php?f=9&amp;t=1419
hxxp://www.devourofmugthol.com/forums/index.php?topic=109.0
hxxp://www.drontlen.com/forum/viewtopic.php?f=4&amp;t=253&amp;p=374
hxxp://www.drontlen.com/forum/viewtopic.php?f=4&amp;t=259
hxxp://www.ekaport.ru/forum/showthread.php?t=14099
hxxp://www.ekaport.ru/forum/showthread.php?t=14127
hxxp://www.family-online-pharmacy.com/purchase_men___s_health_generic/
hxxp://www.family-online-pharmacy.com/purchase_men___s_health_generic/buy_cheap_brand_kamagra_oral_jelly_online.html
hxxp://www.folkd.com/go/kamagra+ajanta+pharma
hxxp://www.forodevinos.com/viewtopic.php?f=3&amp;t=55
hxxp://www.forum4voip.com/viewtopic.php?f=1&amp;t=38125
hxxp://www.forum.tripudiolatino.it/viewtopic.php?f=2&amp;t=165
hxxp://www.freewebs.com/costaescorts/
hxxp://www.geistheiler24.de/forum/viewtopic.php?f=11&amp;p=5217
hxxp://www.generatedata.com/forums/index.php?topic=2351.msg2495
hxxp://www.getdarker.com/forums/viewtopic.php?f=3&amp;t=5797&amp;start=0
hxxp://www.gourmet.com/forums/message.jspa?messageID=1481
hxxp://www.healthpharmarx.com/
hxxp://www.hollywood.com/Forums/Home.aspx?plckForumPage=ForumDiscussion&amp;plckDiscussionId=Cat%3ACelebsForum%3A41Discussion%3Ac7c7096b-9895-497f-bb0d-a79fd53fc8f1
hxxp://www.homegrow.me/where-to-buy-mestinon-online-fast-worldwide-shipping-the-m-t504.html
hxxp://www.hunglay.com/webboard/index.php?action=printpage;topic=26.0
hxxp://www.hunglay.com/webboard/index.php?topic=26.0
hxxp://www.infotop.ro/forum/viewtopic.php?f=2&amp;t=4
hxxp://www.inox.tarrea.cl/foro/index.php?showtopic=68&amp;view=old
hxxp://www.ireallywantviagra.com/2009/11/cheap-kamagra-oral-jelly.html
hxxp://www.jamespot.com/a/188474-Buy-Kamagra-Online.html
hxxp://www.jobsstack.com/forum/index.php?action=printpage;topic=4405.0
hxxp://www.jomc.unc.edu/
hxxp://www.joomlatemplatesearcher.com/forum/index.php?action=printpage;topic=7362.0
hxxp://www.joomlatemplatesearcher.com/forum/index.php?topic=7362.msg%msg_id%
hxxp://www.kamagra.in/India-Kamagra.htm
hxxp://www.kamagra-online.co.uk/aurogratablets.asp
hxxp://www.kamagrastore.co.uk/
hxxp://www.kamagratop.com/
hxxp://www.led-tv-fernseher.de/forum/viewtopic.php?f=4&amp;t=4
hxxp://www.makinem.net/forum/index.php?topic=952.0
hxxp://www.malerxpharmacy.com/product/sildenafil-kamagra.html
hxxp://www.minco.com/community/members/Dr+Levitra.aspx
hxxp://www.mister-wong.com/topics/buy+cheapest/
hxxp://www.mister-wong.com/topics/kamagra/
hxxp://www.mypage.com/viagralive/weblog
hxxp://www.nnenyy-cs.info/viewtopic.php?f=8&amp;t=943
hxxp://www.oktmilya.ru/viewtopic.php?p=13782
hxxp://www.onlinemedicalstore.net/
hxxp://www.online-pharmacy-usa.com/men___s_health_drugs/buy_propecia_online
hxxp://www.oxygenoverkill.com/forum/viewtopic.php?f=2&amp;t=4
hxxp://www.partyoffers.co.uk/forum/read.php?19,400,400
hxxp://www.pdsanlazzaro.it/forum/viewtopic.php?f=3&amp;t=2878
hxxp://www.perlenhimmel.at/viewtopic.php?p=16661
hxxp://www.photoactions.co.uk/Discount-Kamagra.htm
hxxp://www.photoactions.co.uk/Jelly_Kamagra_Liquid.htm
hxxp://www.phtclub.be/viewtopic.php?f=8&amp;t=253
hxxp://www.pills2go.com/
hxxp://www.pioneer-physicaltherapy.com/buy-generic-kamagra+soft-online.html
hxxp://www.portaldocuidador.com/forum/viewtopic.php?f=6&amp;t=4212
hxxp://www.promiana-bg.com/forum/index.php?action=printpage;topic=3072.0
hxxp://www.promiana-bg.com/forum/index.php?topic=2777.0
hxxp://www.ps3planet.it/forum/viewtopic.php?f=4&amp;t=10090
hxxp://www.pyzam.com/profile/3318196
hxxp://www.pyzam.com/profile/3318197
hxxp://www.realpharmacyrx.com/
hxxp://www.reasonfrontier.com/index.php?action=printpage;topic=2791.0
hxxp://www.redleafwands.com/ehsrp/index.php?action=printpage;topic=14534.0
hxxp://www.rfidtalk.com/showthread.php?p=18965
hxxp://www.rhettmiller.com/forum/viewtopic.php?f=3&amp;t=1449
hxxp://www.rottentomatoes.com/vine/showthread.php?p=16465556
hxxp://www.rugbyveneto.org/phpbb//viewtopic.php?t=59630
hxxp://www.scribd.com/doc/23935277/Buy-Kamagra-Online-Without-Prescription-Best-Place-to-Buy-Kamagra
hxxp://www.scribd.com/doc/25069184/buy-Brand-Kamagra-oral-jelly-Sildenafil-citrate-100mg-online-without-prescription
hxxp://www.sharpmeds.com/
hxxp://www.simpy.com/user/mastsiagoel/tag/generic4all
hxxp://www.skaly.sk/viewtopic.php?f=6&amp;t=3009
hxxp://www.skydsl.org/forum/viewtopic.php?p=12035&amp;sid=594e5b80965d00e1ae83a04c1ee6eb5c
hxxp://www.skydsl.org/forum/viewtopic.php?t=5999&amp;sid=2254d3872dbd467413cde299664fd2a8
hxxp://www.somalinet.com/forums/viewtopic.php?f=8&amp;t=231252
hxxp://www.songstowearpantsto.com/forum/viewtopic.php?f=3&amp;t=118055
hxxp://www.ssteve.nl/forum/viewtopic.php?f=2&amp;t=105
hxxp://www.stalkerzone.de/forum/viewtopic.php?f=3&amp;t=2568
hxxp://www.stalkerzone.de/forum/viewtopic.php?f=5&amp;t=2642&amp;p=22695
hxxp://www.surcentro.com/en/info/www.kamagrarx.com
hxxp://www.tebene.de/Members/Kamagra/buy-kamagra-online-paypal-payment
hxxp://www.thegeneric-viagra.net/
hxxp://www.thegreatpotdebate.com/forum/topic48.html?sid=ac9e1defb50abca2e1cff33a76d91bdb
hxxp://www.theviagrastore.com/kamagra-generic-store-1095.html
hxxp://www.thewealthacademy.co.uk/index.php?topic=1135.0
hxxp://www.tuneando.es/index.php?action=printpage;topic=1705.0
hxxp://www.tuneando.es/index.php?topic=1705.0
hxxp://www.vertifight.com/forum/viewtopic.php?f=3&amp;p=63126
hxxp://www.vibeystars.nl/index.php?topic=35.0
hxxp://www.vinilkosmo-mp3.com/forum/index.php?topic=201.0
hxxp://www.wbahealth.com/product_brand_kamagra_soft_online.html
hxxp://www.wordcountbuddies.com/wcb_forum_test/viewtopic.php?f=4&amp;p=286
hxxp://www.worstpreviews.com/forums/showthread.php?p=42881
hxxp://www.xlpharmacy.com/ed-jelly/
hxxp://www.xlpharmacy.com/Kamagra/
hxxp://www.xmaspharmacy.com/kamagra-oral-jelly-100mg-p-59.html
hxxp://www.xmaspharmacy.com/resource/index.html
hxxp://www.your-best-drugstore.com/
hxxp://www.zeroegg.cn/viewtopic.php?f=4&amp;t=10674
</pre>
<p>UPDATE: On 3/9/2010, hxxp://runbetterpoker.com/viewtopic.php?f=4&#038;t=887 was removed from the list at the owner&#8217;s request. Software used to run the forum whose vulnerability led to the recent abuse has been removed.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/01/26/analyzing-online-pharmacy-spam/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>Website-Reputation Services Agree to Disagree</title>
		<link>http://www.stopthehacker.com/2010/01/17/website-reputation-services-agree-to-disagree/</link>
		<comments>http://www.stopthehacker.com/2010/01/17/website-reputation-services-agree-to-disagree/#comments</comments>
		<pubDate>Sun, 17 Jan 2010 21:17:34 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[bing]]></category>
		<category><![CDATA[comodo]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[mcafee]]></category>
		<category><![CDATA[norton]]></category>
		<category><![CDATA[safebrowsing]]></category>
		<category><![CDATA[safeweb]]></category>
		<category><![CDATA[siteadvisor]]></category>
		<category><![CDATA[website reputation]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1014</guid>
		<description><![CDATA[We have recently published statistics comparing various website reputation services and have received good feedback over private channels regarding our article. In this sequel we add Microsoft&#8217;s Bing, malware filter along with comparison to other website reputation services.
At StopTheHacker.com (Jaal LLC) we have conducted tests of 721 URLs, all of which have been reported as [...]]]></description>
			<content:encoded><![CDATA[<p>We have recently published <a href="http://www.stopthehacker.com/2009/12/21/how-good-are-website-reputation-services/" target="_blank">statistics</a> comparing various website reputation services and have received good feedback over private channels regarding our article. In this sequel we add Microsoft&#8217;s <a href="http://www.bing.com" target="_blank">Bing</a>, malware filter along with comparison to other website reputation services.</p>
<p>At StopTheHacker.com (Jaal LLC) we have conducted tests of 721 URLs, all of which have been reported as malicious by volunteers of various blacklists. We follow a similar format for presentation of results as in the <a href="http://www.stopthehacker.com/2009/12/21/how-good-are-website-reputation-services/" target="_blank">last post</a>.</p>
<div id="attachment_1015" class="wp-caption aligncenter" style="width: 584px"><img class="size-full wp-image-1015" title="av-comparison-ii" src="http://www.stopthehacker.com/wp-content/uploads/2010/01/av-comparison-ii.jpeg" alt="Website Reputation services: agree to disagree." width="574" height="336" /><p class="wp-caption-text">Website Reputation services: agree to disagree.</p></div>
<p><em>Note: All 721 domains/URLs, were reported as malicious, and were collected from malware.com.br on January 14, 2010. The blue column (maximum 100) indicates the percentage of sites that the website-reputation service correctly identified as unsafe. The orange column (maximum 100) indicates the percentage of sites that the website-reputation services incorrectly identified as safe.</em></p>
<p><strong>The aim of the test:</strong></p>
<ol>
<li>Identify the accuracy of the website reputation service</li>
<li>Identify the overlap in terms of safe/unsafe websites</li>
</ol>
<p>We present the most interesting results in this article. First we detail the parameters of the testing procedure to provide an idea of how the test was set up.</p>
<p>First, 721 URLs were collected from <a href="http://malware.com.br" target="_blank">malware.com.br</a> (mbr) on January 14, 2010. These URLs are reported for listing by one or more of the following: individuals, organizations, agencies and software products or services.  For the purposes of this test we assume that all the URLs obtained from the &#8220;regular&#8221; list on mbr are malicious and hence deemed &#8220;unsafe&#8221; to visit.</p>
<p>We compare the reputation provided by each website-reputation service and observe how many websites are marked unsafe, safe, untested, maybe-unsafe/caution/potentially-unsafe, and unreachable.</p>
<p><strong>Website-reputation services tested:</strong></p>
<ul>
<li><a href="http://siteadvisor.com" target="_blank">McAfee SiteAdvisor</a></li>
<li><a href="http://safeweb.norton.com" target="_blank">Norton Safe Web</a></li>
<li><a href="http://www.google.com/tools/firefox/safebrowsing/" target="_blank">Google Safe Browsing</a></li>
<li><a href="http://www.bing.com/community/blogs/webmaster/archive/2009/06/17/bing-keeps-the-web-safe-with-malware-filter.aspx" target="_blank">Microsoft Bing</a></li>
<li><a href="http://siteinspector.comodo.com" target="_blank">Comodo SiteInspector</a></li>
</ul>
<p>Note, that when analyzing a domainname/URL, for checking with the Google safebrowsing API, we have calculated the MD5 hash of the website name to match with the malware hash list. The date that we conducted this test was: January 15, 2010. The list of domain names tested are presented below and a graph representing the statistics for the 721 sites tested is above.</p>
<p><strong>We identify the most interesting results below:</strong></p>
<ol>
<li>McAfee SiteAdvisor marked 36.75% of domains as Unsafe, 27.18% as Safe, 32.32% as Untested and 3.74% as Potentially-Unsafe.</li>
<li>Norton Safe Web marked 41.75% of domains as Unsafe, 45.49% as Safe, 4.3% as Untested and 8.32% as Potentially-Unsafe.</li>
<li>Google Safe Browsing marked 5.96% of domains as Unsafe, 94.04% as Safe.<br /><em>Note: The presence of the hash of the domain name  being tested, on the google malware hash list, is interpreted as &#8220;unsafe&#8221; while the absence is interpreted as &#8220;safe.&#8221;</em></li>
<li>Microsoft Bing marked 0.69% of domains as Unsafe, 34.26% as Safe, and 65.05% as Untested</li>
<li>Comodo SiteInspector marked 0.19% of domains as Unsafe, 95.82% as Safe, and 4.08% as Unreachable.</li>
</ol>
<p>This follow-up experiment also shows that the variance between website reputation services that are currently being offered by large Internet-services/security companies continues to be very large indeed.</p>
<p>After discussions with representatives of the companies mentioned in this article, and getting a better idea of their behind the scenes methodologies. It seems that these website reputation services will continue to &#8220;agree to disagree.&#8221; We welcome their comments.</p>
<p><strong>A note on differences between website reputation services:</strong></p>
<p>Some of the services scan pages and some scan parts of a site. Some scan for potential &#8220;signs&#8221; of an infection, while others scan for the &#8220;postmortem&#8221; effect of an infection, such as an exploit being launched. Furthermore, the time difference between one of the services testing a web page or site versus when another one tests the same web page can also complicate issues. At StopTheHacker.com we recognize the current limitations of website reputation services that being offered by the industry.</p>
<p>In conclusion, while website reputation services have come a long way, they still have an even longer path to tread in order to become something that users should trust implicitly.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/01/17/website-reputation-services-agree-to-disagree/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Profiling Autonomous Systems Hosting Blacklisted Websites</title>
		<link>http://www.stopthehacker.com/2010/01/01/profiling-autonomous-systems-hosting-blacklisted-websites/</link>
		<comments>http://www.stopthehacker.com/2010/01/01/profiling-autonomous-systems-hosting-blacklisted-websites/#comments</comments>
		<pubDate>Fri, 01 Jan 2010 21:16:06 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AS]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[injection]]></category>
		<category><![CDATA[malicious websites]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=898</guid>
		<description><![CDATA[An Autonomous Systems or AS is a routing construct that represents a group of networks under  the control of an organization (credit for edit :Max@badwarebusters.org). These form the &#8220;structure&#8221; of the Internet. These organizations can be thought of as web-hosting companies, large Internet-based companies or resellers of bandwidth and IP addresses. These are usually [...]]]></description>
			<content:encoded><![CDATA[<p>An Autonomous Systems or AS is a routing construct that represents a group of networks <em>under  the control of</em> an organization (<em>credit for edit :Max@<a href="http://www.badwarebusters.org" target="_blank">badwarebusters.org</a></em>). These form the &#8220;structure&#8221; of the Internet. These organizations can be thought of as web-hosting companies, large Internet-based companies or resellers of bandwidth and IP addresses. These are usually large organizations for whom simply getting an Internet connection and hosting a company for their website is not enough.</p>
<p>In recent months, the trend of benign websites being affected by code injection clearly show that attacks to inject malware into unsuspecting websites is on the rise. It is important to understand the profile of the ASes which are actually providing transit to infected websites hosted within their systems. Since each AS provides bandwidth and resources supporting the downloading of malware to computers which belong to unsuspecting visitors of a compromised website. ASes, more specifically hosting companies and other network operators (rather than ASes) should play a pivotal role in addressing compromised websites.</p>
<p>At StopTheHacker.com, we have conducted extensive experiments to analyze and profile over 20,000 ASes to identify which ASes are the worst offenders in terms of hosting Blacklisted websites.  We have used <a href="http://www.google.com/tools/firefox/safebrowsing/index.html" target="_blank">Google safebrowsing</a> data, also accessible via <a href="http://stopbadware.org/reports/asn/" target="_blank">StopBadware.org</a>, (which sources data from Google and <a href="http://www.sunbeltsoftware.com" target="_blank">Sunbelt</a>)to identify and trend which ASes are responsible for the proliferation of badware on the Internet. We have correlated AS size with <a href="http://www.caida.org/research/topology/#asrank" target="_blank">data</a> available from <a href="http://www.caida.org" target="_blank">CAIDA</a> to determine whether larger ASes are more at fault or not.</p>
<p><strong>We present some brief results below:</strong></p>
<ol>
<li>The average percentage of blacklisted websites in
<ul>
<li>Top 10 ASes (according to number of sites noted by Google) is 3.5%</li>
<li>ASes with Ranks 11-23 (according to number of sites noted by Google) is 3.75%</li>
<li>ASes with Ranks 24-40 (according to number of sites noted by Google) is 5.01%</li>
</ul>
</li>
<li>The AS with the highest percentage of blacklisted sites, is AS 16557 (Colo Solutions, Inc.), with close to 60% of 10,000 sites blacklisted.</li>
<li>The Top 50 ASes, which host more than 10,000 sites each and have at least 6% of websites blacklisted, host 151,000 blacklisted sites, combined.</li>
</ol>
<p><strong>Interesting observations:</strong></p>
<ol>
<li>AS 16557 (Colo Solutions, Inc.), is well known for popping up on blacklists related to peer-to-peer networks [<a href="http://www.cs.ucr.edu/~anirban/Anir-networking07.pdf" target="_blank">Is someone tracking P2P users</a>]. <em>It seems that this AS, which is not really concerned about P2P traffic emanating from within its systems, traffic which is potentially used to exchange copyrighted material, is also not interested in paying attention to malware infected websites hosted within its networks.</em></li>
<li>AS 15169 (Google Inc.), had 590734 sites analyzed and 6046 of them were found to contain malware.</li>
<li>AS 14173 (Photobucket), had zero sites infected out of 399424 sites analyzed.</li>
<li>The Largest AS (Level 3 Communications) according to connection degree, see <a href="http://www.caida.org" target="_blank">CAIDA&#8217;s AS listing</a>, was hosting 571 infected sites out of 136305 sites analyzed by Google.</li>
<li>AS 7018 (AT&amp;T), was hosting 97 infected sites out of 7947 sites analyzed by Google.</li>
<li>AS 701 (Verizon), was hosting 117 infected sites out of 7248 sites analyzed by Google.</li>
<li>AS 1239 (Sprint), was hosting 117 infected sites out of 3958 sites analyzed by Google.</li>
</ol>
<h3>Making Sense of the Results</h3>
<p>Below we present some graphs to highlight the percentage of blacklisted websites hosted by the top few ASes. Note that all AS rankings below are based on the number of websites analyzed by Google. An AS with rank 1 hosts more websites, analyzed by Google than an AS with rank 2.</p>
<div class="gallery">
<div id="attachment_912" class="wp-caption aligncenter" style="width: 310px"><a rel="attachment wp-att-912" href="http://www.stopthehacker.com/wp-content/uploads/2010/01/greater-than-10k-and-greater-than-6-percent.jpeg"><img class="size-medium wp-image-912" title="ASes hosting greater than 10,000 sites and with moe than 6% of them Blacklisted" src="http://www.stopthehacker.com/wp-content/uploads/2010/01/greater-than-10k-and-greater-than-6-percent-300x139.jpg" alt="Nearly 50 ASes host at least 600 blacklisted sites each" width="300" height="139" /></a><p class="wp-caption-text">Nearly 50 ASes host at least 600 blacklisted sites each</p></div>
<div id="attachment_903" class="wp-caption aligncenter" style="width: 310px"><a rel="attachment wp-att-903" href="http://www.stopthehacker.com/wp-content/uploads/2010/01/top-10-as.jpeg"><img class="size-medium wp-image-903" title="Percentage of blacklisted sites hosted by the 10 largest ASes " src="http://www.stopthehacker.com/wp-content/uploads/2010/01/top-10-as-300x206.jpg" alt="Top 10 ASes host lage percentages of blacklisted sites" width="300" height="206" /></a><p class="wp-caption-text">Top 10 ASes host lage percentages of blacklisted sites</p></div>
</div>
<p><span id="more-898"></span></p>
<h3>ASes hosting more than 10,000 sites (each having more than 6% infected sites)</h3>
<p>Below follows the list of ASes, which host more than 10,000 sites each. Of those, at least 6% (600) are blacklisted by Google. Perhaps more attention needs to be focused on fighting malware from within these ASes. There are quite a few prominent web-hosting companies in this list. Note that all ASes below are ranked based on the number of websites analyzed by Google. An AS which appears earlier in the list hosts more websites, analyzed by Google than an AS which appears later on in the list.</p>
<pre class="brush: plain;">
ASN             Name
21844           ThePlanet.com Internet Services, Inc.
4837            CNC
11798           Bluehost Inc. US
4812            CABLENETSWISS-HITTNAU Cablenetswiss	CH
26347           New Dream Network, LLC	US
29629           INETWORK-AS IEUROP AS	FR
32244           Liquid Web, Inc.	US
16265           LEASEWEB LEASEWEB AS	NL
3786            LGDACOM LG DACOM Corporation	KR
3595            Global Net Access, LLC	US
32392           Ecommerce Corporation	US
32613           iWeb Technologies Inc.	CA
4847            CNIX
33182           HostDime.com, Inc.	US
21788           Network Operations Center Inc.	US
38356           TIMENET BeiJing Sincerity-times Network Technology Project Ltd.	CN
15244           Lunar Pages	US
25074           INETBONE-AS INET-People Provider Services	DE
25532           MASTERHOST-AS .masterhost autonomous system	RU
30496           Colo4Dallas LP	US
12824           HOMEPL-AS home.pl autonomous system	PL
9929            CNCNET-CN China Netcom Corp.	CN
28753           NETDIRECT AS NETDIRECT Frankfurt, DE
11388           Peer 1 Dedicated Hosting	US
9121            TTNET TTnet Autonomous System	TR
13237           LAMBDANET-AS European Backbone of LambdaNet	EU
9931            CAT-AP The Communication Authoity of Thailand, CAT	TH
46475           Limestone Networks, Inc.	US
29671           SERVAGE Servage GmbH	DE
15685           Casablanca INT Autonomous system	CZ
39392           SUPERNETWORK-AS SuperNetwork s.r.o.	CZ
8342            RTCOMM-AS RTComm.RU Autonomous System	RU
34104           TELETEK-AS TELETEK TELEKOMINIKASYON HIZMETLERI A.S	TR
42910           SADECEHOSTING-COM Sadecehosting-Com	TR
8358            INTERWARE-AS InterWare Autonomus System	HU
25653           FortressITX	US
26277           A+ Hosting, Inc.	US
12363           DADA-AS DADA S.p.a.	IT
23352           Server Central Network	US
17964           DXTNET Beijing Dian-Xin-Tong Network Technologies Co., Ltd.	CN
24400           CMNET-V4SHANGHAI-AS-AP Shanghai Mobile Communications Co.,Ltd.	CN
30176           Priority Colo	CA
4750            CSLOXINFO-ISP-AS-AP CSLOXINFO Public Company Limited.	TH
32181           GigeNET	US
27823           Dattatec.com	AR
16557           Colo Solutions, Inc.	US
5617            TPNET Polish Telecom's commercial IP network	PL
39561           AGAVA Agava JSC AS number	RU
19318           NEW JERSEY INTERNATIONAL INTERNET EXCHANGE LLC	US
9848            GNGAS Enterprise Networks	KR
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/01/01/profiling-autonomous-systems-hosting-blacklisted-websites/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>How Good Are Website-Reputation Services?</title>
		<link>http://www.stopthehacker.com/2009/12/21/how-good-are-website-reputation-services/</link>
		<comments>http://www.stopthehacker.com/2009/12/21/how-good-are-website-reputation-services/#comments</comments>
		<pubDate>Tue, 22 Dec 2009 01:17:13 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[comodo]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[mcafee]]></category>
		<category><![CDATA[norton]]></category>
		<category><![CDATA[safebrowsing]]></category>
		<category><![CDATA[safeweb]]></category>
		<category><![CDATA[siteadvisor]]></category>
		<category><![CDATA[website reputation]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=859</guid>
		<description><![CDATA[Websites on the Internet have now become the standard modus operandi for spreading malicious software to infect personal and corporate environments.  A large number of benign and well-meaning websites are compromised everyday by hackers inserting malicious code to, in turn, infect the computers used by visitors to the hacked site. One of the ways [...]]]></description>
			<content:encoded><![CDATA[<p>Websites on the Internet have now become the standard modus operandi for spreading malicious software to infect personal and corporate environments.  A large number of benign and well-meaning websites are compromised everyday by hackers inserting malicious code to, in turn, infect the computers used by visitors to the hacked site. One of the ways to combat this is to develop a website reputation mechanism which can warn of potential threats before visiting a compromised site.</p>
<div id="attachment_864" class="wp-caption aligncenter" style="width: 517px"><img class="size-full wp-image-864" title="Comparing Website-reputation services" src="http://www.stopthehacker.com/wp-content/uploads/2009/12/av-comparison-services1.jpeg" alt="Website-reputation services vary wildly in their opinions" width="507" height="314" /><p class="wp-caption-text">Website-reputation services vary wildly in their opinions.</p></div>
<p><em>Note that all 350 domains, were reported as malicious, and were collected from malware.com.br on December 18, 2009. The blue column (maximum 350) indicates the number of sites that the website-reputation service correctly identified reported bad sites. The orange column (maximum 350) indicates the number of sites that the website-reputation services incorrectly identified reported malicious sites as safe.</em></p>
<p>Website reputation services have been around for nearly 5-7 years now. Initially developing as a niche product line which could serve to provide an opinion of a site&#8217;s reputation to full fledged offerings which provide advisories about websites, whether they are distributing malware, and if they are, what kind, and using which Autonomous Systems.</p>
<p>At StopTheHacker.com (Jaal LLC) we have conducted tests with 350 domain names, all of which have been reported as malicious by volunteers of various blacklists.</p>
<p><strong>The aim of the test is to:</strong></p>
<ol>
<li>Identify how accurate the website reputation services are</li>
<li>What is the overlap in terms of safe/unsafe websites</li>
</ol>
<p>We have found some interesting results which we present in this article. First we detail the parameters of the testing procedure to provide an idea of how the test was set up.</p>
<p>350 URLs were collected from <a href="http://malware.com.br" target="_blank">malware.com.br</a> (mbr) on December 18, 2009. These URLs are reported to this website for listing by one or more of the following: individuals, organizations, agencies and software products or services.  We assume for the purposes of this test that all the URLs obtained from the &#8220;regular&#8221; list from mbr are malicious and hence deemed &#8220;unsafe&#8221; to visit.</p>
<p>We compare the reputation provided by each website-reputation service and observe how many websites are marked as unsafe, safe, untested, maybe-unsafe/caution/potentially-unsafe, unreachable.</p>
<ul>
<li><a href="http://siteadvisor.com" target="_blank">McAfee Siteadvisor</a></li>
<li><a href="http://safeweb.norton.com" target="_blank">Norton Safeweb</a></li>
<li><a href="http://www.google.com/tools/firefox/safebrowsing/" target="_blank">Google SafeBrowsing</a></li>
<li><a href="http://siteinspector.comodo.com" target="_blank">Comodo Siteinspector</a></li>
</ul>
<p>Note, that when analyzing a domain name, for checking with the Google safebrowsing API, we have had to calculate the MD5 hashes of the website names to match with the malware hash list. The date that we conducted this test was: December 21, 2009. The list of domain names tested are presented below and a graph representing the statistics for the first 350 sites tested is above.</p>
<p><strong>We have identified some of the most interesting results below:</strong></p>
<ol>
<li>McAfee Siteadvisor marked 32.5% of Domains as Unsafe, 22% as Safe, 43% as Untested and 1.7% as Potentially-unsafe.</li>
<li>Norton Safeweb marked 50.86% of Domains as Unsafe, 43.71% as Safe, 2.29% as Untested and 3.14% as Potentially-unsafe.</li>
<li>Google SafeBrowsing marked 10.86% of Domains as Unsafe, 89.14% as Safe. <em>Note: the presence of the hash of the domain name  being tested, on the google malware hash list, is interpreted as &#8220;unsafe&#8221; while the absence in interpreted as &#8220;safe&#8221;.</em></li>
<li>Comodo Siteinspector marked 0.29% of Domains as Unsafe, 98.86% as Safe and 0.86% as Unreachable. <em>Note: after feedback from Comodo, a retest was conducted, accuracy changed from 0.29% -&gt; 1.2%.</em></li>
</ol>
<p>This limited test is a first step towards showing how much variance there is website reputation services that are currently being offered by large Internet-services/security companies. To highlight this point we present immediately below the relatively few domains (~6% of the total domains tested) that were marked as bad by all three major services, Norton, McAfee, and Google.</p>
<p><strong>In brief:</strong></p>
<ul>
<li>6% of domains tested were marked as &#8220;unsafe&#8221; by all 3, McAfee, Norton and Google</li>
<li>10% of domains tested were marked as &#8220;unsafe&#8221; by Norton and Google</li>
<li>22% of domains tested were marked as &#8220;unsafe&#8221; by Norton and McAfee</li>
<li>5.7% of domains tested were marked as &#8220;unsafe&#8221; by Google and McAfee</li>
</ul>
<p>Update: December 28, 2009</p>
<p><em>After receiving helpful feedback from representatives at Comodo, we were informed that Comodo&#8217;s service could provide more accurate answers if complete web page locations were checked instead of just the domain name. We followed the advice and saw a definite increase in Comodo&#8217;s accuracy. Comodo marked 1.2% of the website/pages as malicious. Prior to this re-test, the same service marked 0.2% of the websites as unsafe. The graph at the beginning of this article does not represent the results of this re-test.</em><br />
<span id="more-859"></span></p>
<h3>Below we list the websites from which we extract the statistics above</h3>
<p><strong>Websites marked as &#8220;unsafe&#8221; by Norton, McAfee and Google</strong></p>
<pre class="brush: plain;">
219.148.34.10
219.148.34.9
4gameranking.com
77.245.61.232
aiongamemeca.com
durantilumi1cao.com.br
golary.cn
hagnuor.cn
igivor.cn
igoudix.cn
igouhxe.cn
ihaegup.cn
ihaerxi.cn
ihagoin.cn
ihoekag.cn
ihouvi.cn
ihuere.cn
ihuqoyr.cn
ijaheuw.cn
ikyigy.cn
iloefe.cn
</pre>
<p><strong>Websites marked as &#8220;unsafe&#8221; by Google and Norton</strong></p>
<pre class="brush: plain;">
212.99.87.130
219.148.34.10
219.148.34.9
4gameranking.com
61.164.108.213
77.245.61.232
aimeblog.com
aiongamemeca.com
bhactuant.com
durantilumi1cao.com.br
findreaso1ble.org
for23.3322.org
golary.cn
gyfvuxe.cn
hagnuor.cn
ifueme.cn
igivor.cn
igoudix.cn
igouhxe.cn
iguyzmo.cn
ihaegup.cn
ihaerxi.cn
ihagoin.cn
ihoekag.cn
ihogedi.cn
ihouvi.cn
ihuere.cn
ihuqoyr.cn
ijaheuw.cn
ijakony.cn
ijazofy.cn
ijeife.cn
ijelodi.cn
ikyigy.cn
iloefe.cn
</pre>
<p><strong>Websites marked as &#8220;unsafe&#8221; by McAfee and Google</strong></p>
<pre class="brush: plain;">
219.148.34.10
219.148.34.9
4gameranking.com
77.245.61.232
aiongamemeca.com
durantilumi1cao.com.br
emes.com.br
golary.cn
hagnuor.cn
igivor.cn
igoudix.cn
igouhxe.cn
ihaegup.cn
ihaerxi.cn
ihagoin.cn
ihoekag.cn
ihouvi.cn
ihuere.cn
ihuqoyr.cn
ijaheuw.cn
ikyigy.cn
iloefe.cn
</pre>
<p><strong>Websites marked as &#8220;unsafe&#8221; by McAfee and Norton</strong></p>
<pre class="brush: plain;">
163.fuckunion.com
206.161.127.72
208.75.230.43
209.205.196.16
218.93.205.250
219.148.34.10
219.148.34.9
4gameranking.com
61.235.117.72
70.148.212.252
77.245.61.232
82.98.235.173
85.92.157.141
91.213.126.100
97feihu.com
adobeflashupdates.com
adwareprotectionsite.com
aiongamemeca.com
amforum.lua.pl
antivirus-live.com
artistinove.it
centralspa.ca
comerciocentral.net
densmail.com
diadoamigo0.myartsonline.com
dimorphothec.com
dl.get-torrent.com
dl.targetsaver.com
dudi11.off.co.il
durantilumi1cao.com.br
ebestsite.co.kr
elogios0.myartsonline.com
exeype.cn
fuck-celebrities-movie.com
gclass.it
generalantivirus.com
ghterwa.com
gokzed.cn
golary.cn
google.netcdn.com
gorazyn.cn
hagnuor.cn
hahdyti.cn
hgtr3.com
hiqtacy.cn
hjyuw2.com
icepot.cn
idoafy.cn
idoape.cn
igafep.cn
igakuot.cn
igeuvat.cn
igivor.cn
igoudix.cn
igouhxe.cn
igycoat.cn
ihaegup.cn
ihaerxi.cn
ihagoin.cn
ihoekag.cn
ihouvi.cn
ihuere.cn
ihuqoyr.cn
ijaheuw.cn
ijepiyq.cn
ijesiam.cn
ijobuaw.cn
ijuebka.cn
ikoiwe.cn
ikorate.cn
ikuaxge.cn
ikyadeh.cn
ikyigy.cn
ileufby.cn
ilixyeq.cn
ilodux.cn
iloefe.cn
iluefot.cn
i1gyve.cn
</pre>
<p>Interestingly, Comodo&#8217;s service marked only 1 website, 218.146.255.156 as malicious. This domain was also marked malicious by Norton, &#8220;Untested&#8221; by McAfee and was not found on the Google malware hash list. Below follows the complete list of domains that were tested.</p>
<p><strong>Complete list of domains tested</strong></p>
<pre class="brush: plain;">
001.bbexe.cn
113.105.175.138
114.207.112.169
119.147.114.163
12.10.157.6
12.24.238.229
12.25.151.68
121.12.127.230
121.205.91.142
121.205.91.145
123.244.30.118
123.244.30.66
123.bbexe.cn
147.163.1.77
148.208.196.2
163.fuckunion.com
174.36.233.59
192.220.110.228
193.104.27.139
193.169.234.27
200.111.155.122
200.242.43.250
200.63.5.78
200.67.103.187
200.69.124.17
202.105.183.104
202.114.181.5
204.12.43.43
204.232.131.12
206.161.127.72
208.75.230.43
209.131.200.246
209.172.35.144
209.205.196.16
209.43.123.143
210.166.220.240
210.206.8.254
210.51.166.217
211.39.130.196
211.78.87.42
212.31.234.155
212.63.132.215
212.88.178.22
212.97.63.156
212.99.87.130
216.24.165.4
216.240.148.175
217.116.46.139
218.146.255.156
218.16.120.253
218.188.0.5
218.6.15.135
218.63.200.196
218.86.118.98
218.93.202.115
218.93.205.250
219.146.128.242
219.146.128.245
219.148.34.10
219.148.34.9
220.90.213.158
220.95.232.28
221.1.204.243
221.143.43.200
222.66.209.98
222.76.243.53
24.1188d.cn
24.65.70.52
3.1188d.cn
3310.net.cn
38.99.91.47
3s.8i9i.com
46.1188d.cn
46.3388a.cn
4gameranking.com
5.1188d.cn
53.1188d.cn
58.147.27.69
58.215.79.176
6.1188d.cn
60.191.39.6
61.108.173.3
61.110.21.192
61.164.108.213
61.235.117.72
62.193.229.83
64.160.216.20
65.109.240.130
65.183.178.92
66.116.229.233
66.152.93.119
66.220.17.157
66.45.235.228
67.19.9.234
67.43.224.77
68.153.57.9
70.148.212.252
72.10.166.195
72.20.6.106
72.237.212.57
72.35.84.6
72.64.146.16
731273265.520815.com
76.162.68.70
76.73.42.43
77.245.61.232
77.92.158.122
78.159.127.254
78.46.151.179
80.153.182.80
81.223.40.244
81.252.31.148
82.114.87.46
82.98.235.173
83.103.59.84
83.206.113.161
83.240.174.136
83.245.62.87
84.20.251.223
85.17.136.139
85.25.81.140
85.92.157.141
91.207.7.116
91.213.126.100
93.174.95.140
95.211.98.136
97feihu.com
98.126.34.250
a.amg777.com
a1964.g.akamai.net
absi2008.netfirms.com
acripino7878.110mb.com
admin.bbexe.cn
adobeflashupdates.com
adwareprotectionsite.com
aha-autoimage.com
aimeblog.com
aiongamemeca.com
album.pagi1s.sapo.pt
alison.wz.cz
alkeichah.com
amforum.lua.pl
amoravela.com.sapo.pt
antivirus-live.com
antivirusadvanced.com
arathas.de
arcade.ya.com
arkbroadcasters.org
artdeli.co.kr
artistinove.it
atencaousuario.webcindario.com
atualizaca-juridica.sitesled.com
ausamedia.berepublic.com
avr-download.com
b.amg777.com
backstaroup.home.sapo.pt
bb.bbexe.cn
bbs.pxtang.cn
bcfpb.com
bchokies.com
bdesata.com
belezademulher.org
best-sale.us
bevaccine.com
bgcomstock.com
bhactuant.com
blog20fc2.com
blogaofotos8.com.sapo.pt
blogfotos2008.com.sapo.pt
blogpesoalpessoal.com.sapo.pt
bmz.horizon.net.pl
brasilterra.com.sapo.pt
c.amg777.com
caixa-cefinstall.sitesled.com
caixaeconomica-gov.sitesled.com
cancelamentt0.googlepages.com
carbys.no.sapo.pt
card2009.com.sapo.pt
cardamorhtml.no.sapo.pt
cardpaixao.esmartdesign.com
cartao8578.com.sapo.pt
cartaoamizade000.com.sapo.pt
cartaoespecial9.com.sapo.pt
cartaovirtual2006.no.sapo.pt
cartoesnovos.250x.com
cartoesuol.com.sapo.pt
cartoeswebapaxo1do.no.sapo.pt
casasbahia.com.sapo.pt
cau.ac.kr
centralspa.ca
chaiyapruekpethospital.com
chamadavideo-1.my3gb.com
chi1oilfactory.cn
chinesefreewebs.com
ciduninstall.com
cinema-film-4you.ru
club.telepolis.com
comerciocentral.net
comunidade777.110mb.com
config.koreamessenger.com
correiosweb.com.sapo.pt
cprzafra.juntaextremadura.net
d.amg777.com
d.kkkmfdy.com
d4.kkkmfdy.com
damnkt.logi1pp.com
db.ms.kr
denizlisurucukursu.com.tr
densmail.com
diadoamigo0.myartsonline.com
dimorphothec.com
di1r-cs.real-host.ru
dindindopv.bravehost.com
ditto.arpa.org
dl.get-torrent.com
dl.qvodir.cn
dl.targetsaver.com
dl.woyo8g.com
dl02.softdown-load.com.cn
dollardream.ru
donghae.ms.kr
dorota288.w8w.pl
down.1vysoft.org
down.woyo8g.com
down.yellowsoft.org
download.gameztar.com
download.iobit.com
download.leeboo.com
download.softpedia.com
downlopaginvisualiz.com.sapo.pt
dtvprosoft.hotbox.ru
dudi11.off.co.il
durantilumi1cao.com.br
dw.idchecker.co.kr
dx.woyo8g.com
e-airkoryo.com
e.amg777.com
ebestsite.co.kr
edirrelojoeiro.com.br
elogios0.myartsonline.com
emes.com.br
empresarial0001.pisem.su
energy-sol.com
exeype.cn
extex-events.ru
f-forge.com
fhblack.com
fideizm.ru
fileanchor.com
findreaso1ble.org
flashplaginsmirror.com
flashplayer.home.sapo.pt
fondbaybakova.ru
for23.3322.org
forrodotchaka.com.br
forum.factor8guild.com
fotoalbumbr.flog.br
fotoemsg.110mb.com
fotosbalada10x.fileave.com
fotoslinks439856.com.sapo.pt
franciszkankiswklary.ofm.pl
freefilehosting.net
freeweb.siol.net
fuck-celebrities-movie.com
galeon.com
gclass.it
generalantivirus.com
ghterwa.com
gizemguvenfa1tikleri.googlepages.com
glla.net
gokzed.cn
golary.cn
goldeninka.ii1a.net
google.netcdn.com
gorazyn.cn
govsaude.110mb.com
grwww.info
gtpq.info
gtz-legalproject.az
gyfsanimados2009.com.sapo.pt
gyfvuxe.cn
gymarqe.cn
hagnuor.cn
hahdyti.cn
haimadhav.googlepages.com
hakaymobilya.com
hgtr3.com
hiqtacy.cn
hjwx3.com
hjyuw2.com
hohu.spacequadrat.de
homecards11.no.sapo.pt
hosting.free2w.com
hotmailtorpedos2008.com.sapo.pt
humano.ya.com
icepot.cn
idfc2.info
idoafy.cn
idoape.cn
ies.bbexe.cn
ifueme.cn
ifypeod.cn
igafep.cn
igakuot.cn
igayzde.cn
igeuvat.cn
igivor.cn
igoudix.cn
igouhxe.cn
iguyzmo.cn
igycoat.cn
ihaegup.cn
ihaerxi.cn
ihagoin.cn
ihoekag.cn
ihogedi.cn
ihouvi.cn
ihuere.cn
ihuqoyr.cn
ijaheuw.cn
ijakony.cn
ijazofy.cn
ijeife.cn
ijelodi.cn
ijepiyq.cn
ijesiam.cn
ijobuaw.cn
ijuebka.cn
ijyadpi.cn
ijyoxri.cn
ikayvo.cn
ikeuqe.cn
ikeysi.cn
ikioda.cn
ikoiwe.cn
ikorate.cn
ikuaxge.cn
ikyadeh.cn
ikyigy.cn
ildapadilha.110mb.com
ileufby.cn
ilipyw.cn
ilixyeq.cn
ilodux.cn
iloefe.cn
iluefot.cn
img242.imageshack.us
img503.imageshack.us
img522.imageshack.us
i1gyve.cn
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2009/12/21/how-good-are-website-reputation-services/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
