Welcome to the Proxy Update, your source of news and information on Proxies and their role in network security.

Friday, September 16, 2011

Heidi Klum, More Dangerous Than You Think

McAfee recently came out with a list of the most dangerous celebrities. That is when you search for them on the Internet. Apparently searching for Heidi Klum gives you a 1 in 10 chance of landing on a malicious website. The top five most dangerous celebrities are:

1. Heidi Klum

2. Cameron Diaz

3. Piers Morgan

4. Jessica Biel

5. Katherine Heigl


All of which is a good reminder, why web security is so important, and making sure the secure web gateway or web proxy has protection against malware and phishing.

Monday, September 12, 2011

Your car, the next target for malware?

Last week McAfee released a new report talking about cars, and specifically car electronics as the likely next target for hackers who spread malware. While it still seems far-fetched today, as cars become more sophisticated, they are beginning to have complete computer systems, and while much of that is hidden from the driver, it will become more and more visible and interactive with the driver. Even my car today, has voice recognition, and interfaces with my cell phone to get me directions, news, weather stock quotes, etc, all given back to me through bluetooth, transferred directly through the radio's speaker system. So an attack if it's targeted like an APT, is certainly a possibility in the near future on car electronics.

The question though is what's in it for the hacker? As most know today, hackers today are driven by money, and creating malware is generally tied to making money in some manner. But where's the money in hacking a car? You could certainly hack a car and cause an accident, but until money or identity can be remotely retrieved from a person's vehicle, attacks on individual cars, probably remains unlikely, other than just as a curiosity.

Friday, September 9, 2011

Typo Squatting

While a lot of the mainstream press is calling this the latest attack vector, it's actually not new. Phishing attacks have long used the typo squatting method, basically relying on close, but misspelled domain names to capture personal information. The latest attack is being reported as new only because of they way the attack is implemented. Rather than imitating the domain's login page to capture login information from an unsuspecting user, the latest attack uses a pop up survey to collect personal identifying information, perhaps with the reasoning that an end-user will be less security conscious with a survey than they would with a fake login page.

As always, the best protection for threats like these is a good secure web gateway or web proxy, with the latest in malware and phishing protection. And because users aren't always on the organization's network, a good mobile or cloud solution should be available from your secure web gateway vendor as well.

Thursday, September 8, 2011

Reverse Proxy Make A Comeback

It seems the latest news in the proxy world is all about Web Application Firewalls (WAF). It just goes to show you that everything old is new again. WAFs are of course nothing more than souped up reverse proxies, which were the rage when the dot com boom came about. Reverse proxies were used to prevent overload on webservers and distributed the web load to proxy servers that not only cached content, but also protected the web servers to some degree.

In today's world the WAF, is a bit more sophisticated in that there's more malware and more cybercrime in the world. The good news is that most reverse proxy vendors out there have improved their offering to include protection against schemes like SQL injection and Cross site scripting (XSS), regardless of whether they use the fancy new WAF terminology to label themselves as such. Also today's WAF or reverse proxy supports SSL proxy, important because more and more webservers today rely on SSL as a base protocol, rather than the exception.

So if you're trying to protect your webservers, remember to check out WAFs as well as reverse proxies, since reverse proxies probably do more than you remember them doing in the past.

Tuesday, August 30, 2011

Big Drop In Fake AV

Both McAfee and Blue Coat had reported that the Fake AV scam was one of largest purveyors of malware last year. In case you're not familiar with it, basically it's a pop-up, javascript or some other injected code that notifies the end-user that their computer is infected with a virus, and offers to clean it, by paying for antivirus software, and instead of downloading a/v software, it basically downloads malware to the workstation.

Apparently by June of this year, the Fake AV sites had practically disappeared from the web. The reason for the quick drop? From ZDnet:

The event that caused the sudden plunge? A high-profile bust by Russian authorities. On June 23, a network of web sites that were distributing fake antivirus software for Windows PCs and Macs suddenly went offline when the head of the company that processed payments for the group was busted.


While the decrease is good news for end-users in general, it's expected it's only a minor hiccup in the cybercrime activity, and it's expected to ramp back up again soon, so it's no time to drop your guard in terms of protecting your end-users and network.

Monday, August 29, 2011

Google Search Results Cleaner in 2011 than 2010

There's a new report showing that Google search results are a lot better this year than last with regard to the results containing malware (SEP - Search Engine Poisoning) sites. That sounds like really good news on the face of it, as it means your web proxy or secure web gateway won't have to work as hard to protect you from these malicious search engine results. It used to be up 90% of results contained malware, and now, it's as few as only 3 malicious links in the first 10 pages of search results.

But there's bad news buried in this news as well. It turns out searches for software purchases online still contains about 90% malicious results. So there's no reason to back down from protecting your users, and if anything if you've got users out there searching for software purchases, you probably should increase your security and the protection your offering your users in your web proxy/secure web gateway.

Wednesday, August 24, 2011

Are you ready for HTTPS Everywhere?

The EFF, in collaboration with the Tor Project, launched the official 1.0 version of HTTPS Everywhere tool on Aug. 4, just past a year after the first beta version was released in June 2010. According to EFF's blog post, the extension will help secure Internet browsing by encrypting connections to more than 1,000 Web sites.

If you're an administrator of a Secure Web Gateway or web proxy, that statement alone should have you worried, or at the very least give you a momentary pause. The reason? While most organizations have deployed secure web gateways for HTTP traffic, very few have actually gone the additional step of turning on the SSL traffic for their external web traffic. The reasons are varied, but they include the overhead that encryption and decryption would have on the web proxy, the fact that most sites until recently, generally provide data and content unencrypted, and the privacy issues and concerns around inspecting SSL traffic.

But SSL is gaining traction, and most email providers and even Facebook offers options for keeping SSL turned on. This increases the likelihood that malware and other undesirable content can be brought down to the organization's network since SSL is likely bypassing the proxy.

What's the right solution? If you haven't already turned on your SSL proxy, investigate what it means to your network and your proxy if you do. Make sure your proxy can handle the additional load of SSL decryption and encryption. The easiest way to do this is to check to see if your proxy has an SSL hardware card, or the option to add one. Trying to do decryption and encryption in software will add additional load to what's probably an overloaded proxy to begin with, and in all likelihood could add latency to your web traffic, that's why hardware based SSL is the best bet.

Next set up policy so that you aren't violating your employees policy rights. That may include turning off SSL proxy for users in certain countries, and turning it off for certain categories (like banking). Run this past your HR and legal to be sure you're doing the right thing.

Once you've got those figured out, it's time to go live with the SSL proxy, and you'll be sure you're inspecting encrypted traffic for malware and undesirable content.