Greedy ISPs Expose Users to Unsecure Websites
By Alice Turner
22:11, April 19th 2008
45 votes
Vote this story
Greedy ISPs Expose Users to Unsecure Websites

Greedy ISPs in the U.S. and other parts of the world are cashing in on their customers' mistyped web addresses, exposing them to security risks. IOActive security researcher Dan Kaminsky has warned several large ISPs that their practice of redirecting users to ad pages when they try to access pages that don't exist has created massive security holes.

"The ISPs will say they're doing wonderful favors for users who might have to otherwise go back and type in the real name of the site they're seeking. But the reality is that anytime ISPs add yet another level of complexity to their networks, they necessarily introduce more security bugs," said John R. Levine, author of Internet for Dummies, to The Washington Post.

These Internet Service Providers are subverting the Domain Name System or DNS, which translates website names into numeric addresses, when users type a wrong web address. Instead of getting an error page, they are bounced to an ads page served up by a British company called Barefruit, which pretends to actually to be the non-existent domain when delivering the ads.

This means that, taking into account Barefruit's failure to screen for rogue JavaScript code, hackers were able to create fraud sites which appeared to be and looked exactly like eBay, for example. Earthlink, Qwest and Verizon have outsourced at least portions of their ad-serving technology to BareFruit, thus exposing their customers to massive security risks.

"This kind of practice means the security of the Web is being limited to the security of this ad server," Kaminsky told Security Fix on Friday. "My work is to secure the Web and other computer infrastructure, but this becomes near impossible when other people are injecting content into domains that I am professionally trying to secure," he said.

The British ad company has fixed their security holes after being noticed by IOActive security staff.



Image Credit: gamesforfree.net
© 2007 - 2008 - eFluxMedia
dotclear

Other News in

Microsoft Reveals Online Service Bundles

Microsoft Reveals Online Service Bundles

At its annual Worldwide Partner Conference that took place in Huston, Microsoft announced two online service bundles that are targeted to two opposite types of workers: the ones that hardly use the...

Viacom Tramples Privacy of YouTube Users with Court Help

Viacom Tramples Privacy of YouTube Users with Court Help

The ruling which demands Google to hand over the YouTube access logs, which are to show the actual extent of copyright infringement going on the popular site, has sparked widespread outrage from...

Microsoft Discovers IE Vulnerability

Microsoft Discovers IE Vulnerability

Microsoft warns its users about a recently discovered attack on one of its browser components. The reports received by the company, refer to a flaw in an ActiveX control for Snapshot Viewer, active...

Apple To Launch Its MobileMe On Wednesday, July 9th

Apple To Launch Its MobileMe On Wednesday, July 9th

Apple has officially unveiled the launch date of its MobileMe service, announced last month at WWDC 2008. The users of www.mac.com were notified that the site will be taken offline on Wednesday, July...

Unexpected New “Words” Make Their Way Into The Merriam-Webster

Unexpected New “Words” Make Their Way Into The Merriam-Webster

Did you ever think you’ll find words like “fanboy,” “pretexting” or “pescatarian” in the dictionary any time soon? Well, for you, and even for those who’ve never heard of them but probably will...

dotclear
Latest videos in Technology
YouTube ruling spurs privacy...
Google ordered: hand over...
Microsoft after Gates
Mobile precautions urged
What Yahoo turned down

dotclear
Technology You are here: Technology
» Technology   » Gadgets   » Video Games   
E-mail To A Friend Print RSS Text size: Decrease font size Increase font size
dotclear
dotclear
dotclear
Most Popular in Technology
Update: Viacom-YouTube Ruling Triggers Far-Reaching Privacy ConcernsUpdate: Viacom-YouTube Ruling Triggers Far-Reaching Privacy Concerns

» read full story
dotclear

Interested In This Topic?

News Alert will keep you informed. Find out more.
dotclear
Photos Gallery
dotclear
Today's Latest News
FDA Wants Black Box on Antibiotics, Epilepsy DrugsFDA Wants Black Box on Antibiotics, Epilepsy Drugs

» read full story
dotclear