Welcome to the Proxy Update, your source of news and information on Proxies and their role in network security.

Tuesday, January 12, 2010

2010: Is it all hype?

When it turned the year 2000, there was all this worry that computers would crash, and our infrastructure would have problems from date rollover. Nothing significant happened. But we surprised ourselves as the year 2010 came around, and there were actually news reports of computers having problems with the date change.

Some of the reported problems included:

Symantec's "Endpoint Protection" business anti-virus solution started the new year by labelling signatures dated 01/01/2010 or newer as "out of date" even though the signatures are current. Symantec is reportedly working to fix the flaw. Until an update has become available, the vendor will date any further new signatures December 31, 2009 and only increase the revision number. Affected products include Symantec Endpoint Protection v11.x and Symantec Endpoint Protection Small Business Edition v12.x.

The Internet Storm Center reports that Cisco's Content Switching Module (CSM) has problems with its load balancing feature. The default cookie expiration in the load balancer is reportedly set to 01/01/2010 and has, therefore, expired. As a result, connections to programs such as web applications are reportedly being continuously "rebalanced".


I guess it's never too late to check to make sure your code is date compliant.

Illegal downloads at work skyrocket

From: http://www.computerweekly.com/Articles/2010/01/12/239924/Illegal-downloads-at-work-skyrocket-says-ScanSafe.htm

Illegal software and music downloadson corporate networks have increased 55% in the past three months, according to web security firmScanSafe.

The increase was revealed in data gathered across more than 100 countries and millions of employees.

Employees tend to assume they can use the internet at work in exactly the same way as they use it at home, said Spencer Parker, product management director at ScanSafe.

"Inappropriate internet use in the workplace can put the employer at risk for legal liabilities," he said.

Downloading illegal content is a "double whammy" for employers as it puts them at risk legally and puts the company network at risk, said Parker.

"Free illegal downloading websites are often riddled with malware, which could infect corporate networks," he said.

Organisations should implement a comprehensive web security system to block employees from accessing illegal websites, said Parker.

Security consultants have identified employee education as a top priority for businesses in 2010.

Businesses should also ensure internet usage policies are up to date and that employees are aware of what they are not allowed to do at work.

Increased use of consumer devices such as iPhones is another key reason businesses should keep their IT polices and standard up to date, said William Beer, information security director at PricewaterhouseCoopers.

"Employees need to be aware of how their actions can impact on the organisation they work for, but not many businesses have a comprehensive set of policies and an education programme in place," he said.

Friday, January 8, 2010

Facebook Beats Google on Xmas

From: http://www.thebigmoney.com/blogs/feeling-lucky/2009/12/31/facebook-beats-google-xmas

Could Facebook supplant Google (GOOG) as the most-visited Web site in the country in 2010? That question's been on everyone's lips ever since an official at the research firm Hitwise tweeted that on Christmas Day, more people used Facebook than Google or any of its related products.

Search Engine Journal contributor Arnold Zafra thinks that the Christmas triumph may be something of an outlier; Christmas, after all, is a time when people reconnect with their friends and family, and Facebook is uniquely positioned to help them do just that. Nevertheless, Zafra adds, it may indicate that Facebook may have outpaced e-mail as a communications medium. "Email is a thing of the past during these days, as Facebook and perhaps other social sites like Twitter are the more preferred ways of communicating online especially during special occasions," he writes.

And in another sign of Facebook's ubiquity, the security firm McAfee warned that hackers and malware distributors are increasingly focused on poisoning the site with spam. "Malware authors love following the social networking buzz and hot spots of activity; that will continue in 2010," the company warned. Apparently, popularity has its price.

Thursday, January 7, 2010

Cybercriminals may target Social Networking Sites, says McAfee

According to a latest report released by McAfee Inc, the Cybercriminals may target social networking sites such as Facebook, Twitter and FriendFeed in 2010. McAfee said that these social networking sites could become easy targets because of their vulnerability.

In the past, Facebook had witnessed serious hacking problems and same thing might happen again. Usually, people trust their friends and the links sent by them on such socialnetworking sites. That may work as an advantage for the Cybercriminals.

Currently, 350 million people across the globe use Facebook. McAfee and Symantec have cautioned the users about the shortened URLs that come in a different format and makes it difficult for the users to view the url without clicking on it.

Wednesday, January 6, 2010

Hybrid Apps Will Be Next Hacker Target

From InfoSecurity: http://www.infosecurity-us.com/view/6184/mcafee-hybrid-apps-will-be-hacker-target/

Applications that blur the boundaries between online and offline software will be a primary hacker target this year, according to McAfee.

In its 2010 Threat Predictions Report, McAfee said that the advent of HTML 5 - a yet-to-be-ratified, enhanced version of the HTML language used to create web pages - is blurring the line between the internet and the desktop. New functionality in the language makes web apps act more like desktop computer software than ever before. The hacker community will be drawn to this phenomenon, McAfee predicted.

An example of a HTML 5-based application is Google Wave, which reinvents email, combining it with instant messaging-like functionality to create online conversations that can be embedded in other web pages. The anti-virus vendor singled out Google's Chrome OS as a technology that will complement the new language to draw interest from hacker groups.

Chrome OS, an open-source operating system that was released to developers in November, is designed for use on netbooks and other small footprint devices that rely almost exclusively on internet-based applications for their operation. The system is scheduled for end-user release later this year.

"Google Chrome OS is intended for use with netbooks, and HTML5 enables not only a rich internet experience, but also offline applications. Another motivation for attackers is HTML 5’s anticipated cross-platform support, which will allow attackers to eventually reach users of many mainstream browsers", McAfee continued.

The document also suggested that the hacker community may switch its emphasis from Microsoft to Adobe. "In 2010, we anticipate Adobe software, especially Acrobat Reader and Flash, will take the top spot", it said. Adobe has already seen several zero-day attacks from hacker groups targeting these two.

Other, perhaps more obvious, predictions from the report include more sophisticated hacker threats targeting social networking applications, as their user numbers increase, and cleverer banking trojans (it's generally a safe bet to assume that the hacker underground won't become dumber, and simpler, and neither will its products).

Tuesday, January 5, 2010

Major Christmas e-Card Spam Campaign

From the Blue Coat Security Blog: http://www.bluecoat.com/blog/major-christmas-e-card-spam-campaign

During the holidays, the Blue Coat Web Filter™ team continues to keep an eye on things, both the results of the various WebPulse™ automated processes and the various data streams that the human analysts monitor. One trend worth remarking on has been a flood of "e-Card" spam in our honeypots. This began a few days before Christmas, and is still continuing.

As it turns out, this will also give me a chance to talk a little bit about a category of software we call "Potentially Unwanted Software". (Or "PUS" for short.)

The spam e-mails' subject line varies, but it's typically something like "[name], Someone sent you a Christmas Card".

The actual body of the e-mail doesn't contain a card, but instead invites you to "Send Cards for Christmas[...] Everyone has email, send them an eCard they'll love, save money on postage."

The spam comes from a variety of constantly changing domains (e.g., familyvalues1b.com, lifepartner1d.com...), and clicking the link inside routes you through about four hidden-relay sites to eventually reach the e-card site.

WebPulse™ already knew about most of the spam relay sites (I've added the new ones), and also has some interesting information about the e-card site.... It turns out to have been on Santa's "Naughty List" for more than six months, when one of our analysts noted that the Toolbar it wants you to install garnered a lot of hits in virus scanners. The majority of those hits were categorized as Adware/Spyware type software, which fits in with our P.U.S. category. This analysis was confirmed by a second analyst a couple of months later, who took a deeper look.

We define the P.U.S. category as "Sites that distribute software that is not malicious but may be unwanted within an organization such as intrusive adware and hoaxes." (Where "not malicious" means something like "doesn't deliberately harm/crash your computer, or steal your banking passwords" -- that would clearly be Malware.)

Adware is software that sits on your computer, watches where you go on the internet, and serves you extra ads beyond those normally found on the web sites, often in the form of pop-up or pop-under ads. (This is something different from web-ad sites that use "beacons" on multiple client sites to track your visits and decide which ads you see as part of the pages you visit. While these may still be a privacy concern for you, if they don't install software on your computer, they're not P.U.S.) Adware may sometimes be a legitimate method of "payment" for "free" versions of software. More often, it's an intrusive privacy risk.

P.U.S. is also frequently criticized for "bloating" your computer (consuming too many resources) and slowing it down.

Due to the annoyance, performance hit, privacy concerns, and an overall "shadiness factor", I always recommend that our customers block the P.U.S. category. (Exceptions may always be made, of course, by "whitelisting" particular sites where you've checked out the software and EULA, and feel that the benefits outweigh the risks -- the customer is always in control of what gets blocked.)

This month, due to their behind-the-scenes involvement in a deceptive and unwanted spam campaign, with fake/junk domains and a series of shady relays, we've added a Suspicious rating to the parent site as well. (Just call it a little "Christmas e-Card" of our own.)

Monday, January 4, 2010

Websense and Google warn of scam adverts

From: http://www.securecomputing.net.au/News/163223,websense-and-google-warn-of-scam-adverts.aspx

Scam uses classic 'get rich quick' hook.

A new scam has been detected which uses Google's name in a get rich quick scheme.

Websense Security Labs detected the ‘making easy money with Google' scam as circulating for some time, and in the last few weeks, a new wave of such scams has emerged using Google's reputation to sell 'working from home' kits that claim Google is hiring people.

It said that the primary way of propagation and to increase exposure of those kits is through legitimately-bought advertising space, and the marketing of the fake kits is designed to work with affiliates. For every kit sold the affiliate gets a cut of the profits.

Carl Leonard, senior manager of Websense Security Labs, said: “This aggressive campaign, which preys on a population weakened by the economic downturn, demonstrates how cybercrime has moved on from the spotty teenage hacker in his bedroom to a sophisticated business run with all the trimmings.”

It is not only Google that has been affected, as other brands such as Yahoo, Microsoft and Dell have been exploited with the average user affected and confused. This has also led Google to look into taking legal action against the group/company behind the campaign, and also some related individuals.

In a blog post on December 8, Google said that to fight back it had filed a suit against Pacific WebWorks and ‘several other unnamed defendants'.

Jason Morrison, support engineer (search quality team), and Stacey Wexler, senior litigation counsel at Google, said: “Google hasn't created or endorsed any of the sites like those described in our complaint. Misleading ads try to take advantage of consumers in the midst of a difficult economy, and as the economic situation has worsened, the problem has only grown. As far as we can tell, thousands of people have been tricked into sending payment information and being charged hidden fees by questionable operations.

“Even as we're taking legal action to try to cut these sites off at the source, we're still working constantly to remove scammy URLs from our index, and we'll permanently disable AdWords accounts that provide a poor or harmful user experience, whether or not they use Google's trademarks illegally. That said, we can't guarantee that schemes like these won't pop up, like the proverbial ‘Whack-A-Mole', someplace else online - either on a different network or under a different name.

“We can solve only part of the problem - the rest is up to you. Just as you should be careful about giving out financial information in the real world, you should be sceptical and review any offers online before sending any information, and always be on guard when presented with an offer that seems too good to be true.”