Welcome to the Proxy Update, your source of news and information on Proxies and their role in network security.

Wednesday, October 6, 2010

Macs are vulnerable to spyware too!

This morning on Facebook, my cousin posted that his Gmail account had gotten hacked (the IP traced to one in China), and that bogus emails were sent to everyone in his address book. The bogus emails included a link to a malicious website. I felt pretty confident in clicking on the link, since I was using Blue Coat's free web filtering program K9, and sure enough, it blocked me from getting to the URL, claiming the site was "Illegal/Questionable".

In the comments to my cousin's post on Facebook, I mentioned to him he should scan his computer for spyware, as that was likely the culprit that caused his Gmail account to get compromised. His response? "Impossible, I'm using a Mac". I think his response is a classic one that many Mac users give, when discussing spyware, malware, viruses and trojans. A basic, "it can't happen to me" attitude. Unfortunately, it can happen on Macs, and spyware, and even malware exists on Macs. Spyware is easier to implement since it can just be embedded into javascript on a website, and the browser makes you vulnerable.

Consider this post a friendly reminder, that just because you're using a Mac doesn't make you immune to spyware, malware and viruses. If you're not browsing behind a proxy that's protecting you with anti-malware and URL filtering, consider installing a free web filtering program like K9 (www.getk9.com).

Thursday, September 30, 2010

Web 2.0 Breaches Cost Businesses $1.1 Billion

Recently in the news, an article on how much Web 2.0 breaches are costing companies.

From: http://www.informationweek.com/news/storage/disaster_recovery/showArticle.jhtml?articleID=227500731&subSection=News


While conceding its value to corporate initiatives, many business professionals have voiced their concerns about security threats associated with Web 2.0. This concern is perhaps with good reason, since more than 60% of those surveyed reported losses associated with Web 2.0 averaging $2 million, a new McAfee-commissioned study found.

One main reason for these breaches, which collectively totaled $1.1 billion, was employee use of social media, according to the report, which was conducted by research firm Vanson Bourne and authored by faculty affiliated with the Center for Education and Research in Information Assurance and Security (CERIAS) at Purdue University.

In their efforts to reduce Web 2.0-related risks, almost half the organizations surveyed block Facebook, and one-third restrict employee use of social media, the study said. One-quarter monitor use and 13% completely block all social media access, the McAfee study found.

Half of the 1,000 global decision makers polled said they were concerned about the security of Web 2.0 applications such as social media, microblogging, collaborative platforms, web mail, and content sharing tools. And 60% voiced concerns about the potential loss of reputation as a result of Web 2.0 misuse, found the report, "Web 2.0: A Complex Balancing Act -- The First Global Study on Web 2.0 Usage, Risks, and Best Practices."

"Web 2.0 technologies are impacting all aspects of the way businesses work," said George Kurtz, chief technology officer for McAfee, which Intel recently acquired. "As Web 2.0 technologies gain popularity, organizations are faced with a choice -- they can allow them to propagate unchecked, they can block them, or they can embrace them and the benefits they provide while managing them in a secure way."

In fact, more than 75% of businesses are using Web 2.0: About half of those surveyed use Web 2.0 applications for IT functions; about one-third have adopted these technologies for sales, marketing, or customer service; and 20% are using Web 2.0 apps for human resource or public relations. Three-quarters of respondents who use Web 2.0 believe the technology could create new revenue streams for their organizations, 40% to 45% of businesses said Web 2.0 improves customer service, and 40% said it enhances effective marketing.

Despite security challenges and concerns, about 33% of companies surveyed do not have a social media policy and almost 50% lack a policy for Web 2.0 use on mobile devices, the study found.

Of those that have addressed security worries, 79% increased firewall protection, 58% added greater levels of web filtering, and 53% implemented more web gateway protection since introducing Web 2.0 applications to their companies, according to the report. Forty percent of respondents budget specifically for Web 2.0 security solutions, the study said.

"The best protections are those that don't get in the way of getting work finished, because users are not tempted to circumvent those controls. As not all information needs to be protected in the same way, and not all users are going to interact with Web 2.0 technologies in the same manner, defenses should be tailored to fit the circumstances of use," said Eugene Spafford, founder and executive director of the Center for Education and Research in Information Assurance and Security (CERIAS) at Purdue University.

Wednesday, September 29, 2010

News Sites, Searches May Be Riskier Than Porn

A few news articles came out today on a new study that shows you're not more than two clicks away from malware and that News sites and searches are riskier than porn.

Good reason to make sure your Secure Web Gateway's malware protection is updated, and you're using proactive layered defenses! Here's one of the articles:

From: http://www.informationweek.com/blog/main/archives/2010/09/news_sites_sear.html;jsessionid=BRHLKA15WRWBVQE1GHOSKH4ATMY32JVN

Steer clear of gambling, porn and other known risky sites and related searches and you and your employees -- and your business -- are safer, right? Not according to a new Websense study which found that leading news and pop culture sites, and hot-trend search terms may be more dangerous than some of the ones you're steering clear of.

If you and your employees stick to the most popular news, game, social network sites and message boards, you're still never more than two clicks away from malware, the Websense study reports.

In other words, when it comes to protecting yourself by proscribing your company's surfing and searching habits, you're damned if you don't, but you may also be damned if you do.

The cause is a combination of increased automation and thus ubiquity on the part of the malware community, and the increased use of partner sites and links -- often not previewed, obviously -- by legit sites.

According to Websense, no more than two clicks away from malware or other dangerous content are:

"More than 70 percent of top news and media sites
More than 70 percent of the top message boards and forums
More than 50 percent of social networking sites"

Here's a startling one: more than 60% of sites linking to games also contain links to toxic sites, while less than 25% of sex-related sites contain malicious links.

(Not that this is any reason to alter your policies related to objectionable material, of course.)

Search-poisoning is just as bad. Celebrity and other hot topics have always been malware-attractors, but less newsworthy searches are becoming riskier as well. Do a search for baby bedding in London, Websense found, and a full 30% of the results returned will be poisonous.

It's not exactly breaking news that spammers and malware creators are following hot trends and popular topics, zapping the zeitgeist as it were, with toxic links. But the Websense study shows just how pervasively the bad guys are going after you and your employees via your supposedly safe surfing and searching habits.

Whatever your company's policies are regarding employee Web usage, these finding are a good reminder to remind your employees that just because a link is on a reputable site, there's no guarantee that the link isn't compromised.

Even when they're surfing and searching safely, they have more reason than ever to be careful. To be, in fact, wary, and take one or two very deep breaths before clicking anything.

And certainly before that second click.

Tuesday, September 28, 2010

DLP in a Proxy World

DLP (Data Leakage Protection) seems to be gaining more steam in the last year. While DLP was relegated to those organizations that had requirements for DLP due to government compliance issues (like HIPAA, Sarbanes-Oxley, Graham-Leach-Bliley, and others), today many organizations are starting to look at DLP to prevent data theft, accidental data loss, and just the prevention of possibly embarrassing incidents.

It's impossible to implement DLP without bringing the proxy or Secure Web Gateway into the picture. That's because the proxy handles all the outbound web traffic in a typical network architecture. DLP relies on the proxy to determine what outbound traffic needs to be relayed to the DLP device for inspection to determine if the data is sensitive or if it's okay to be sent out of the organization. This conversation between the DLP device and the proxy occurs over the ICAP protocol discussed here. Unlike anti-malware which inspects inbound web traffic, DLP is primarily interested in outbound traffic, also known as request-mod in ICAP.

DLP of course isn't limited to the proxy and outbound web traffic. There's also outbound email traffic, IM traffic, other outbound network traffic and physical device security, typically implemented as a client on PCs and laptops. There's also Network Discovery to determine what and where sensitive information is stored on the network. Each organization is going to differ in which of these pieces of DLP is more important, but it's important to recognize that a complete DLP solution requires a bit of thought, and implementing and integrating with multiple existing services, including the web proxy.

Monday, September 27, 2010

Browse the Web Using Encryption

In case you missed it, this past May of 2010, Google rolled out the beta of SSL Search. At first they put it at https://www.google.com, but it quickly caused problems for schools and other organizations that were trying to enforce web browsing policies, so they created a separate website, https://encrypted.google.com and had https://www.google.com redirect to the new site. This allowed the school admins and other sites that weren't running an SSL proxy to just block https://encrypted.google.com.

According to Google, SSL Search is just beta for now, but it could move to the mainstream and even replace the basic search mechanism, except for the fact that most IT admins probably aren't ready for it. Meaning that encrypted search would probably break all their web browsing policies on their Secure Web Gateway or their proxy, because they haven't yet implemented an SSL proxy on their Secure Web Gateway.

The very fact that Google has introduced an SSL search should be a wake up call to any IT admin that is running a Secure Web Gateway with browsing policies that it's time to implement an SSL proxy (and associated malware protection that's necessary as we discussed in a previous article), otherwise the IT admin caught unaware is going to be letting users bypass their policies, and also let in malware through the SSL backdoor.

Friday, September 24, 2010

What You See Isn't Always What You Get

In any discussion about proxies or Secure Web Gateways, there's always a discussion about how effective and complete a vendor's URL categorization happens to be. This is important because an organization's policy enforcement, and the prevention of malware into the company is dependent on this categorization. It's not surprising then, that various vendors continually seek out ways to show up one another in the URL filtering realm, with missed URLs or incorrectly classified URLs.

It's hard not to be taken in when you're shown a popular URL and then told, by the way a particular vendor doesn't classify it correctly. Recently I was told that Blue Coat mis-categorized the URL, "http://www.facebook.com/playboy#!/playboy?ref=ts" as only Social Networking and missed the category Adult/Mature Content, but of course correctly identified "http://www.facebook.com/playboy" as both categories.

While it's true if you plug in just the URL "http://www.facebook.com/playboy#!/playboy?ref=ts" into a test for Blue Coat's URL categorization, you'd only get Social Networking, you actually have to dig a little deeper to see the truth behind this statement. If an end-user actually tried to visit this URL through a browser, that's not really the site they would visit, that's because when you go to this URL, you're actually visiting (courtesy of AJAX) "http://www.facebook.com/playboy?ref=search&__a=4&ajaxpipe=1&quickling[version]=293384%3B0", a URL that is categorized correctly (and blocked correctly if you have Adult/Mature Content blocked), even though the address bar will continue to show "http://www.facebook.com/playboy#!/playboy?ref=ts".

All this just goes to show, you need to take what one competitor says about another with a grain of salt and do your own testing to make sure the solution you pick fits your needs.

Wednesday, September 22, 2010

Country-coded Malware

From: http://www.bluecoat.com/blog/country-coded-malware

Late last week, we were tracking a spike in exploit server activity. The majority of traffic was being driven by compromised OpenX ad servers (sound familiar?)... This is most likely due to a critical security flaw in current and older versions of this software. (For details on the flaw, see here.)

An examination of the malicious JavaScript code injected by the compromised server shows that:

1. Cookies must be enabled for the browser to be relayed to the attack site. [Not too exciting. --C.L.]
2. If the user's language has a two-letter region code that is on a "safe" list, then the malicious iFrame that points to the attack site is NOT created. [But this is cool! --C.L.]

As the Bad Guys are normally indiscriminate in the selection of their victims, their decision to give some users a break merits further examination.

Language is often a key feature in tailoring an attack to potential victims. No sense showing a fake AV site in Russian to an English-speaker, or vice-versa. However, as this particular exploit server invisibly attempts to compromise the user's browser while they are busy looking at a legitimate site, language-tailoring does not seem to be the motivation in this case.

One variant of the conficker malware famously checked for a Ukrainian-language keyboard on the victim's computer, and refrained from infecting that system if it was found. The general presumption at the time was that they did this to keep the local police off their case -- it's always harder to catch and prosecute a computer criminal in another country. Again, that doesn't seem to be the case here, since the list is so large.

So we're open to suggestions!

Here's the list of "do not attack" countries:


ae UNITED ARAB EMIRATES
al ALBANIA
az AZERBAIJAN
ba BOSNIA AND HERZEGOVINA
be BELGIUM
bg BULGARIA
bo BOLIVIA
br BRAZIL
by BELARUS
ci COTE D'IVOIRE
cn CHINA
cr COSTA RICA
cz CZECH REPUBLIC
dk DENMARK
do DOMINICAN REPUBLIC
dz ALGERIA
ec ECUADOR
ee ESTONIA
eg EGYPT
ge GEORGIA
gf FRENCH GUIANA
gp GUADELOUPE
gr GREECE
gt GUATEMALA
hk HONG KONG
hr CROATIA
hu HUNGARY
id INDONESIA
il ISRAEL
iq IRAQ
ir IRAN
jo JORDAN
kw KUWAIT
lk SRI LANKA
lt LITHUANIA
lv LATVIA
ma MOROCCO
md MOLDOVA
mk MACEDONIA
mt MALTA
my MALAYSIA
om OMAN
pa PANAMA
pk PAKISTAN
pl POLAND
pr PUERTO RICO
ps PALESTINIAN TERRITORY
pt PORTUGAL
qa QATAR
re REUNION
ro ROMANIA
rs SERBIA
ru RUSSIAN FEDERATION
sa SAUDI ARABIA
si SLOVENIA
sk SLOVAKIA
sv EL SALVADOR
th THAILAND
tn TUNISIA
tr TURKEY
tt TRINIDAD AND TOBAGO
tw TAIWAN
ua UKRAINE
uy URUGUAY
vn VIET NAM