<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Barracuda Labs Internet Security Blog &#187; Web Security</title>
	<atom:link href="http://www.barracudalabs.com/wordpress/index.php/tag/web-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.barracudalabs.com/wordpress</link>
	<description></description>
	<lastBuildDate>Thu, 02 Feb 2012 14:24:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>Human Rights Group Used to Spy on Activists</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/12/22/authoritarian-regime-uses-human-rights-group-to-spy-on-activists/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/12/22/authoritarian-regime-uses-human-rights-group-to-spy-on-activists/#comments</comments>
		<pubDate>Thu, 22 Dec 2011 17:44:25 +0000</pubDate>
		<dc:creator>Paul Royal</dc:creator>
				<category><![CDATA[Current Events]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[spear-phishing]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=2216</guid>
		<description><![CDATA[By Paul Royal, Research Consultant Amnesty International&#8217;s UK website has been compromised and is serving drive-by downloads. Historical data indicates the website AIUK was compromised on or before Friday, December 16. Details: Visiting hxxp://www[.]amnesty[.]org[.]uk loads hxxp://3max[.]com[.]br/cgi-bin/ai/ai.html via an iframe. 3max.com.br, which itself is a legitimate but compromised Brazilian automotive website, loads malicious Java content (stolen [...]]]></description>
			<content:encoded><![CDATA[<p><em>By Paul Royal, Research Consultant<br />
</em></p>
<p>Amnesty International&#8217;s UK website has been compromised and is serving drive-by downloads. Historical data indicates the website AIUK was compromised on or before Friday, December 16.</p>
<p>Details:</p>
<p>Visiting hxxp://www[.]amnesty[.]org[.]uk loads hxxp://3max[.]com[.]br/cgi-bin/ai/ai.html via an iframe. 3max.com.br, which itself is a legitimate but compromised Brazilian automotive website, loads malicious Java content (stolen from the <a href="https://metasploit.com/svn/framework3/trunk/external/source/exploits/CVE-2011-3544/Exploit.java">Metasploit project</a>), which targets CVE-2011-3544. If the exploit is successful, malware is installed on the visitor&#8217;s system.</p>
<p>Details of Vulnerability Targeted by the Exploit<br />
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3544">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3544</a><br />
VirusTotal Detections for Exploit<br />
<a href="http://www.virustotal.com/file-scan/report.html?id=1cc214cee10f02d37359c0e3d04fd57899333c4b1eaa81489c74e5c2fa17c3a8-1324068153">http://www.virustotal.com/file-scan/report.html?id=1cc214cee10f02d37359c0e3d04fd57899333c4b1eaa81489c74e5c2fa17c3a8-1324068153</a><br />
VirusTotal Detections for Exploit Payload<br />
<a href="http://www.virustotal.com/file-scan/report.html?id=0e53832e1c36d34a3d05c05f73ebab22a74ade95c5f3b7d9f74fad4f56d10023-1324067892"> http://www.virustotal.com/file-scan/report.html?id=0e53832e1c36d34a3d05c05f73ebab22a74ade95c5f3b7d9f74fad4f56d10023-1324067892</a></p>
<p>The exploit payload possesses properties of targeted malware but is being served by an exploit of a popular, public website. The working theory for this anomaly relates to Amnesty International as a human rights non-governmental organization. To explain, certain countries use zero day exploits and other techniques to gain electronic information about the activities of human rights activists. Of course, a subset of these activists are too smart to click on links in even well-worded spearphishing emails. But what if you compromised a website frequented by these activists (e.g., Amnesty International)? Then your targets come to you. The context-specific damage potential is significant.</p>
<p>Amnesty International UK has been notified about the compromise.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F12%2F22%2Fauthoritarian-regime-uses-human-rights-group-to-spy-on-activists%2F&amp;title=Human%20Rights%20Group%20Used%20to%20Spy%20on%20Activists" id="wpa2a_2"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/12/22/authoritarian-regime-uses-human-rights-group-to-spy-on-activists/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Google+ Gets a &#8220;+1&#8243; for Browser Security</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/07/21/google-gets-a-1-for-browser-security-3/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/07/21/google-gets-a-1-for-browser-security-3/#comments</comments>
		<pubDate>Thu, 21 Jul 2011 18:13:35 +0000</pubDate>
		<dc:creator>Barracuda Labs</dc:creator>
				<category><![CDATA[Internet Security Tips]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Google+]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[social networking security]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=1743</guid>
		<description><![CDATA[by Ray Kelly, Manager of Client Side Technologies &#160; Launching a new Web app today comes with a few certainties, and one of them is, “I will be a target for hackers” for sure.  So when an app as large and as high profile as Google+ launches, it will surely be one of the top [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: left;"><span style="color: #808080;"><em>by Ray Kelly, Manager of Client Side Technologies</em></span></p>
<p>&nbsp;</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/07/Gplus1.jpg"><img class="size-full wp-image-1778 alignright" title="+1" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/07/Gplus1.jpg" alt="+1" width="128" height="128" /></a>Launching a new Web app today comes with a few certainties, and one of them is, “I will be a target for hackers” for sure.  So when an app as large and as high profile as Google+ launches, it will surely be one of the top targets for malicious activity.  This happened to Facebook the more popular it grew and it still is a favorite platform for malicious activity.  I did some analysis of the HTTP traffic between Google+ and the browser and found that Google is off to a good start in regards to browser security. Below are several take-aways:</p>
<p><strong>Only SSL!</strong><br />
All Google+ traffic is sent over SSL and non SSL is not even an option.  This protects users’ traffic from getting sniffed and their sessions from being hijacked.  It is good to know that Google understands that sensitive information is being shared and SSL is really the only option for transmitting data.</p>
<p><strong>Secure Headers</strong><br />
Here is what a typical response looks like from Google+:<br />
<code><br />
HTTP/1.1 200 OK<br />
Content-Type: text/html; charset=UTF-8<br />
Content-Length: 184942<br />
Set-Cookie: ULS=somehash; Path=/; Secure; HttpOnly<br />
Date: Fri, 15 Jul 2011 14:29:05 GMT<br />
Expires: Fri, 15 Jul 2011 14:29:05 GMT<br />
Cache-Control: private, max-age=0<br />
X-Content-Type-Options: nosniff<br />
X-Frame-Options: SAMEORIGIN<br />
X-XSS-Protection: 1; mode=block<br />
Server: GSE<br />
</code><br />
There are a few headers in this response that are specific to browser security, for example:  <strong> </strong></p>
<p><strong>Set-Cookie Secure</strong> – This tells the browser to only send cookies over a secure (SSL) connection.  So if the site happens to hit a page that is not SSL, then the cookie will not be sent.</p>
<p><strong>Set-Cookie HttpOnly</strong> – This prevents the cookie from being accessed by client side script.</p>
<p><em>Both of these cookie attributes help to prevent  session hijacking by only sending cookies when appropriate.</em></p>
<p><strong>X-Content-Type-Options: nosniff</strong> – This prevents “mime” based attacks. The header instructs the browser not to override the response content type.  For example, some browsers try to be smart by deciding for themselves if the content is really is text/html or an image.  So with the nosniff option, if the server says the content is text/html, then the browser needs to render it as text/html.  <strong> </strong></p>
<p><strong>X-Frame-Options: SAMEORIGIN – </strong>This tells the browser to only render frame pages from the URL hosting the main page.  This prevents Clickjacking attacks against the user.  Clickjacking is a browser-based attack that tricks the user into clicking on one thing but then performs a different action, such as following a user on Twitter.</p>
<p><strong>X-XSS-Protection: 1; mode=block</strong> – This allows the browser to detect a cross site reflection attack.  If the browser sees a potential reflection attack, it will prevent the page from rendering in the browser.  Instead, you will see something similar to this depending on the browser:</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/07/xss.jpg" target="_blank"><img style="border: 1px solid black;" title="xss" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/07/xss.jpg" alt="" width="450" height="43" /></a></p>
<p>&nbsp;</p>
<p><strong>What about Facebook?</strong><br />
While these preventions are by no means ground breaking or new, the fact that Google is thinking about and using them is a good step.  In contrast, let’s look at a typical Facebook response:</p>
<p style="text-align: left;"><code>HTTP/1.1 200 OK<br />
Cache-Control: public, max-age=604800<br />
Content-Type: application/x-javascript; charset=utf-8<br />
Expires: Fri, 22 Jul 2011 14:46:37 GMT<br />
P3P: CP="Facebook does not have a P3P policy. Learn why here: http://fb.me/p3p"<br />
X-Frame-Options: DENY<br />
Set-Cookie: _e_syaN_0=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.facebook.com; httponly<br />
X-FB-Server: 10.52.238.45<br />
X-Cnection: close<br />
Date: Fri, 15 Jul 2011 14:46:37 GMT<br />
Content-Length: 24032</code></p>
<p>It is surprising that Facebook has not taken the same simple precautions that Google+ has taken. Here, we can see the differences:  <span style="color: white;"> </span></p>
<table border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr bgcolor="Gray">
<td style="text-align: left;" width="91" valign="top"></td>
<td width="91" valign="top"><span style="color: #ffffff;">Secure Cookie</span></td>
<td width="91" valign="top"><span style="color: #ffffff;">Nosniff</span></td>
<td width="91" valign="top"><span style="color: #ffffff;">XSS Protection</span></td>
<td width="91" valign="top"><span style="color: #ffffff;">X-Frame</span></td>
<td width="91" valign="top"><span style="color: #ffffff;">HttpOnly Cookie</span></td>
<td width="91" valign="top"><span style="color: #ffffff;">SSL</span></td>
</tr>
<tr>
<td width="91" valign="top">Google+</td>
<td width="91" valign="top">Yes</td>
<td width="91" valign="top">Yes</td>
<td width="91" valign="top">Yes</td>
<td width="91" valign="top">Sameorigin</td>
<td width="91" valign="top">Yes</td>
<td width="91" valign="top">Yes</td>
</tr>
<tr>
<td width="91" valign="top">Facebook</td>
<td width="91" valign="top">No</td>
<td width="91" valign="top">No</td>
<td width="91" valign="top">No</td>
<td width="91" valign="top">Deny</td>
<td width="91" valign="top">Yes</td>
<td style="text-align: left;" width="91" valign="top">Optional and not default</td>
</tr>
</tbody>
</table>
<p><span style="color: white;"><span style="color: #333333;">In fact, just yesterday Microsoft’s Vulnerability Research team released advisory MSVR11-007: “Clickjacking Vulnerability in Facebook.com Could Allow Account Compromise”.   According to the advisory, Facebook has resolved the issue.  I did another check of the headers and still did not see any change to the response.  It is possible that Facebook closed the hole on the server side with input validation in order to prevent the malicious data from entering their database, but they still did not implement the simple browser precautions that Google+ has.   Here is the link to the official MSVR advisory:</span><br />
<a href="http://www.microsoft.com/technet/security/advisory/msvr11-007.mspx">http://www.microsoft.com/technet/security/advisory/msvr11-007.mspx</a></span></p>
<p>The folks from SecTheory/WhiteHat Security have an excellent write-up on Clickjacking.  For detailed information on this vulnerability visit:<br />
<a href="http://www.sectheory.com/clickjacking.htm">http://www.sectheory.com/clickjacking.htm</a></p>
<p>&nbsp;</p>
<p><strong>Conclusion</strong><br />
Unfortunately, not all of these headers are supported in all browsers, meaning any of you still using IE6 won’t be able to take advantage of these headers.  What’s this mean for you? Make sure you are using an up-to-date browser to take full advantage of these protections.</p>
<p>Do these security measures make Google+ impervious to malicious activities?  Absolutely not.  Is it a good start?  Yes, it is. And further, it is good to see an app make its debut with security in mind.  It actually gives us Infosec folks a bit of hope that developers are listening and doing the right thing.</p>
<p><code> </code></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F07%2F21%2Fgoogle-gets-a-1-for-browser-security-3%2F&amp;title=Google%2B%20Gets%20a%20%26%238220%3B%2B1%26%238243%3B%20for%20Browser%20Security" id="wpa2a_4"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/07/21/google-gets-a-1-for-browser-security-3/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Fake AntiVirus Scams Add MacOS Support</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/05/19/fake-antivirus-target-m/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/05/19/fake-antivirus-target-m/#comments</comments>
		<pubDate>Thu, 19 May 2011 22:09:57 +0000</pubDate>
		<dc:creator>Dave Michmerhuizen</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[SEO Poisoning]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Rogue AV]]></category>
		<category><![CDATA[search engine malware]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=1486</guid>
		<description><![CDATA[by Luis Chapetti &#38; Dave Michmerhuizen &#8211; Security Researchers Fake antivirus scams are designed to scare innocent computer users with exaggerated displays of virus activity in the hope that they will hand over their credit card numbers to make it go away.   They&#8217;ve been around for years and the most prevalent ones use a [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #808080;"><em>by Luis Chapetti &amp; Dave Michmerhuizen &#8211; Security Researchers</em></span></p>
<p>Fake antivirus scams are designed to scare innocent computer users with exaggerated displays of virus activity in the hope that they will hand over their credit card numbers to make it go away.   They&#8217;ve been around for years and the most prevalent ones use a freely available JavaScript design that mimics the Windows user interface, as seen here:</p>
<div id="attachment_1487" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/mfav_windows.jpg" target="_blank"><img class="size-full wp-image-1487 " title="Fake Antivirus that mimics Windows" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/mfav_windows.jpg" alt="Fake Antivirus that mimics Windows" width="450" height="324" /></a><p class="wp-caption-text">Fake Antivirus that mimics Windows</p></div>
<p>&nbsp;</p>
<p>When these pages pop up on Macintosh computers, it&#8217;s immediately obvious that something isn&#8217;t right.</p>
<p>Last quarter, Apple set a new record (3.47 million sold in the quarter) with a growth rate of  33% over the prior year’s quarter.  Apple has about 10% of the computer market in the United States, and that doesn&#8217;t even include iPads.</p>
<p>That market share has been noticed by the fake antivirus scammers, and this week they have added a new JavaScript design that mimics the Macintosh interface, as seen here:</p>
<div id="attachment_1492" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/mfav_applesecurity.jpg" target="_blank"><img class="size-full wp-image-1492 " title="Fake antivirus that mimics Macintosh " src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/mfav_applesecurity.jpg" alt="Fake antivirus that mimics Macintosh " width="450" height="600" /></a><p class="wp-caption-text">Fake antivirus that mimics Macintosh </p></div>
<p>&nbsp;</p>
<p>Drive-by download sites now serve up this page if they detect access from a MacOS computer while Windows users still see a Windows style page.   The example above is called &#8220;Apple Security Center&#8221; but similar templates have been seen named MacDefender.</p>
<p>Since this is just JavaScript, the correct move at this point is to refuse the download and browse elsewhere.  Accepting the download and running it installs &#8220;Mac Protector&#8221; which displays pornographic images and promises to remove them for a credit card payment.</p>
<p>The initial infection vector is poisoned entries in Google search results.  We&#8217;ve talked extensively about <a title="Search Result Malware" href="http://www.barracudalabs.com/wordpress/index.php/2011/03/03/email-spam-drops-by-half-while-search-engine-malware-increases-50-percent-and-twitter-crime-rate-rises-20-percent-during-2010/" target="_blank">poisoned search results</a> and this represents another example of where otherwise normal Web sites are compromised and made to serve up bogus pages that are well ranked by Google. When one of these links is clicked, the compromised Web site detects a visit from Google search results and sends the visitor to a server that presents the fake antivirus. The recent change in Google content ranking has not stymied these attacks &#8211; the malicious link we tested was on page 1 of our search results:</p>
<div id="attachment_1497" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/mfav_google.jpg" target="_blank"><img class="size-full wp-image-1497 " title="Malicious link in Google results" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/05/mfav_google.jpg" alt="Malicious link in Google results" width="450" height="600" /></a><p class="wp-caption-text">Malicious link in Google results</p></div>
<p>&nbsp;</p>
<p>Past Search Engine Optimization campaigns targeted very popular search terms such as celebrity sightings or breaking news events.  The poisoned links mentioned in this post are more likely to show up in the results for more mundane search terms so as to attract less attention, but they&#8217;re still getting <a href="http://www.zdnet.com/blog/bott/an-applecare-support-rep-talks-mac-malware-is-getting-worse/3342" target="_blank">plenty of traffic</a>.</p>
<p>This is turning out to be a <a href="http://www.betanews.com/article/Microsoft-helps-stop-malware-while-Apple-blows-off-malware-victims/1305741363" target="_blank">big problem</a> for Apple. It has been conventional wisdom for years that one of the simplest Internet security solutions is to &#8220;just buy a Mac&#8221; and stop worrying.  Now that the most common drive-by attack vectors are serving up malware, unwary Mac users are being exposed to the <a href="http://www.barracudalabs.com/wordpress/index.php/2010/10/19/malicious-microsoft-imposter-lock-up-your-desktop/" target="_blank">harsh world</a> that Windows users have dealt with for years, and are going to have to learn the same lessons.  Don&#8217;t believe everything that pops up on your screen, and don&#8217;t run any software unless you know where it came from and what it will do.</p>
<p><a href="http://www.barracudanetworks.com/">Barracuda Networks</a> <a title="Web Filter" href="http://www.barracudanetworks.com/ns/products/web-filter-overview.php" target="_blank">Barracuda Web Filters</a> and the <a title="Cloud-based Web Security" href="http://www.barracudanetworks.com/ns/products/web_security_flex_overview.php" target="_blank">Barracuda Web Security <em>Flex</em></a> stop the download of this threat.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F05%2F19%2Ffake-antivirus-target-m%2F&amp;title=Fake%20AntiVirus%20Scams%20Add%20MacOS%20Support" id="wpa2a_6"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/05/19/fake-antivirus-target-m/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Learning the Importance of WAF Technology &#8211; the Hard Way</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/04/11/learning-the-importance-of-waf-technology-the-hard-way/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/04/11/learning-the-importance-of-waf-technology-the-hard-way/#comments</comments>
		<pubDate>Tue, 12 Apr 2011 01:10:17 +0000</pubDate>
		<dc:creator>Barracuda Labs</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Web Application Security]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[Internet Security]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=1260</guid>
		<description><![CDATA[Posted by:  Michael Perone, EVP &#38; CMO Wow.  What a weekend.  In case you haven&#8217;t heard, Barracuda Networks was the latest victim of a SQL injection attack on our corporate Web site that compromised lead and partner contact information.  The good news is the information compromised was essentially just names and email addresses, and no [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #888888;"><em>Posted by:  Michael Perone, EVP &amp; CMO</em></span></p>
<p>Wow.  What a weekend.  In case you haven&#8217;t heard, <a href="http://www.barracudanetworks.com/">Barracuda Networks</a> was the latest victim of a SQL injection attack on our corporate Web site that compromised lead and partner contact information.  The good news is the information compromised was essentially just names and email addresses, and no financial information is even stored in those databases. Further, we have confirmed that some of the affected databases contained one-way cryptographic hashes of salted passwords.  However, all active passwords for applications in use remain secure.</p>
<p>So, the bad news is that we made a mistake.  The <a href="http://www.barracudanetworks.com/ns/products/web-site-firewall-overview.php">Barracuda Web Application Firewall</a> in front of the Barracuda Networks Web site was unintentionally placed in passive monitoring mode and was offline through a maintenance window that started Friday night (April 8 ) after close of business Pacific time.  Starting Saturday night at approximately 5pm Pacific time, an automated script began crawling our Web site in search of unvalidated parameters.  After approximately two hours of nonstop attempts, the script discovered a SQL injection vulnerability in a simple PHP script that serves up customer reference case studies by vertical market.  As with many ancillary scripts common to Web sites, this customer case study database shared the SQL database used for marketing programs which contained names and email addresses of leads, channel partners and some Barracuda Networks employees.  The attack utilized one IP address initially to do reconnaissance and was joined by another IP address about three hours later.  We have logs of all the attack activity, and we believe we now fully understand the scope of the attack.</p>
<p>This latest incident brings home some key reminders for us, including that:</p>
<ul>
<li>You can&#8217;t leave a Web site exposed nowadays for even a day (or less)</li>
<li>Code vulnerabilities can happen in places far away from the data you&#8217;re trying to protect</li>
<li>You can&#8217;t be complacent about coding practices, operations or even the lack of private data on your site &#8211; even when you have WAF technology deployed</li>
</ul>
<p>Before responding prematurely to the press or to anyone else, we wanted to make sure we had time to sift through our logs and do a bit of communication.  We&#8217;re glad that the impact will be very minimal, but we&#8217;re not happy about the amount of bandwidth we&#8217;ve spent assessing what happened, responding to affected parties and putting in place the steps to prevent it in the future.</p>
<p>We are working to notify everyone whose email addresses were exposed, and we apologize for the inconvenience.</p>
<p>&nbsp;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F04%2F11%2Flearning-the-importance-of-waf-technology-the-hard-way%2F&amp;title=Learning%20the%20Importance%20of%20WAF%20Technology%20%26%238211%3B%20the%20Hard%20Way" id="wpa2a_8"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/04/11/learning-the-importance-of-waf-technology-the-hard-way/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Facebook like-jacking trades in celebrities for T&amp;A</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/03/28/facebook-like-jacking-trades-in-celebrities-for-ta/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/03/28/facebook-like-jacking-trades-in-celebrities-for-ta/#comments</comments>
		<pubDate>Mon, 28 Mar 2011 23:49:47 +0000</pubDate>
		<dc:creator>Barracuda Labs</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[social networking security]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=1201</guid>
		<description><![CDATA[by David Michmerhuizen – Security Researcher Two weeks ago Facebook saw a wave of celebrity like-jacking attacks which Barracuda Labs detailed in a post describing their Open Graph underpinnings.  Those attacks used teen celebrities as their bait &#8211; Justin Bieber and Miley Cyrus were prominent themes. After a slight hiatus, the scammers are back with [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #808080;"><em>by David Michmerhuizen – Security Researcher</em></span></p>
<p>Two weeks ago Facebook saw a wave of celebrity like-jacking attacks which Barracuda Labs detailed in a <a href="http://www.barracudalabs.com/wordpress/index.php/2011/03/11/how-to-use-facebooks-opengraph-api-to-spread-malware/" target="_blank">post </a>describing their Open Graph underpinnings.  Those attacks used teen celebrities as their bait &#8211; Justin Bieber and Miley Cyrus were prominent themes.</p>
<p>After a slight hiatus, the scammers are back with the same software but a different approach.  They&#8217;re targeting a tried and true Internet meme &#8211; T &amp; A.</p>
<div id="attachment_1215" class="wp-caption alignnone" style="width: 483px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/03/clickjack11.jpg"><img class="size-full wp-image-1215" title="like-jack posts in friends feed" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/03/clickjack11.jpg" alt="like-jack posts in friends feed" width="473" height="310" /></a><p class="wp-caption-text">like-jack posts in friends feed</p></div>
<p>Clicking on one of these links in a friend feed takes you away from Facebook to another site.  In the previous campaign, these throw-away sites were registered with names like girl-gets-caught.info or daddy-bustedonline.info, and the scam pages were formatted to look like YouTube videos.</p>
<p>Now that they&#8217;ve added more salacious come-ons, at least some of the pages are formatted to look like gossip sites.</p>
<div id="attachment_1203" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/03/clickjack2.jpg" target="_blank"><img class="size-full wp-image-1203" title="Like-jack attack page" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/03/clickjack2.jpg" alt="" width="450" height="359" /></a><p class="wp-caption-text">Like-jack attack page</p></div>
<p>Just as <a href="http://www.barracudalabs.com/wordpress/index.php/2011/03/11/how-to-use-facebooks-opengraph-api-to-spread-malware/" target="_blank">before</a>, this Web page uses the Open Graph API to construct a large &#8216;like&#8217; button that appears to be a movie preview pane.   Clicking on the preview pane does two things: it posts a &#8216;like&#8217; message to your own news feed and then serves up a set of scammy surveys and questionable product offerings under the guise of a &#8216;security check&#8217;.</p>
<div id="attachment_1205" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/03/clickjack3.jpg" target="_blank"><img class="size-full wp-image-1205" title="clickjack3" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/03/clickjack3.jpg" alt="Survey delivery dialog" width="450" height="359" /></a><p class="wp-caption-text">Survey delivery dialog</p></div>
<p>If you click all the way through any of these offerings, the like-jack page creators are paid a fee.   Entering personal information into any of these &#8216;surveys&#8217; is a great way to get on spam lists.   Many of them solicit your cell phone number and then sign you up for unwanted premium SMS services which are placed on your cell phone bill each month.</p>
<p>Barracuda Networks recommends you exercise special care when visiting links posted in your friends&#8217; news feeds.   <a title="Web Filter" href="http://www.barracudanetworks.com/ns/products/web-filter-overview.php" target="_blank"> Barracuda Web Filters</a> and the <a title="Web Filtering Service" href="http://www.barracudanetworks.com/ns/products/purewire_web_security_service_overview.php" target="_blank">Barracuda Web Filtering Service</a> block access to these sites.</p>
<p><em><br />
</em></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F03%2F28%2Ffacebook-like-jacking-trades-in-celebrities-for-ta%2F&amp;title=Facebook%20like-jacking%20trades%20in%20celebrities%20for%20T%26%23038%3BA" id="wpa2a_10"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/03/28/facebook-like-jacking-trades-in-celebrities-for-ta/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Gawker Compromise, Password Lessons</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2010/12/14/gawker-compromise-password-lessons/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2010/12/14/gawker-compromise-password-lessons/#comments</comments>
		<pubDate>Tue, 14 Dec 2010 15:14:34 +0000</pubDate>
		<dc:creator>Barracuda Labs</dc:creator>
				<category><![CDATA[ID Theft]]></category>
		<category><![CDATA[Internet Security Tips]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[#Gawker]]></category>
		<category><![CDATA[Internet Security]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=1007</guid>
		<description><![CDATA[by Daniel Peck, Research Scientist Today any news/blog site remotely technical most likely has a blurb about about the recent Gawker media compromise.  Most people are making a big deal out of the release of the password files, but honestly, there&#8217;s not a lot to that part.  These were clearly very low priority passwords for [...]]]></description>
			<content:encoded><![CDATA[<p><em><span style="color: #888888;">by Daniel Peck, Research Scientist</span></em></p>
<p>Today any news/blog site remotely technical most likely has a blurb about about the recent Gawker media compromise.  Most people are making a big deal out of the release of the password files, but honestly, there&#8217;s not a lot to that part.  These were clearly very low priority passwords for almost everyone using them. While there was probably some amount of password reuse between Gawker sites and the users&#8217; email addresses, the overlap is still relatively small.</p>
<p>But everyone loves a few stats, so here we go&#8230; Out of 188,281 passwords (this is from the parsed_db.txt file in the torrent floating around) the top passwords used are:</p>
<p>3057 &#8211; 123456<br />
1955 &#8211; password<br />
1119 &#8211; 12345678<br />
661 &#8211; lifehack<br />
418 &#8211; qwerty<br />
333 &#8211; abc123<br />
311 &#8211; 111111<br />
300 &#8211; monkey<br />
273 &#8211; consumer<br />
253 &#8211; 12345<br />
247 &#8211; letmein<br />
241 &#8211; trustno1<br />
233 &#8211; dragon<br />
213 &#8211; baseball<br />
208 &#8211; superman<br />
202 &#8211; iloveyou<br />
202 &#8211; 1234567</p>
<p>Additionally,</p>
<p>~50k of the accounts had a Gmail address, ~45k had a Yahoo address, and ~29k had a Hotmail account.</p>
<p>855 of the passwords contained one of George Carlin&#8217;s 7 Dirty Words.</p>
<p>930 contained Love.</p>
<p>And honestly, I&#8217;m a bit surprised that that many people who comment on blog sites are into baseball enough to have it as a password.</p>
<p>The bigger story should be about how complete the compromise appears to be.  All of the source code Gawker owns appears to have been released, and that is a very large piece of intellectual property out there for anyone to take apart.  Not only does it allow others to find problems in the source code, but it also allows them to see what Gawker is planning for in the future, what capabilities they have but haven&#8217;t unlocked, and of course allows any hacker worth his salt to find vulnerabilities in the code for future attacks.  All around, this is not a good situation for any company to be in and will likely lead to a major code rewrite/audit in order to deal with this effectively.</p>
<p>So in light of recent events, now is as good of a time as any to share some good password advice:</p>
<p>1. Developers &#8211; Hash your passwords using salt.  It seems (though, I haven&#8217;t verified this yet) that this database was simply DESing the passwords without doing any sort of salt using a username/etc.  This is bad since it means that a simple rainbow table can be looked up, and that collisions are much easier to come by.</p>
<p>2.  Users &#8211; Don&#8217;t use easy-to-guess passwords (if your password is in the Gawker list, that&#8217;s bad.)   An easy way to make a strong password is to start with an easy-to-remember phrase, like &#8220;The quick brown Fox jumped over the lazy Dog.&#8221;  Then take the first letter from each word, like so &#8211; &#8220;TqbFjotlD&#8221;.   Add in a number such as your age and you have a fairly strong password that&#8217;s still easy for you to recall.</p>
<p>3.  Users &#8211; Don&#8217;t share passwords between sites.  Instead, use the technique in item 2 to create a strong password &#8220;root&#8221; which you can reuse on sites by appending a special character such as @ and a two or three letter mnemonic for the site.  For example, the above password root could be &#8220;TqbFjotlD32@GM&#8221;  for Gmail,  &#8220;TqbFjotlD32@HM&#8221; for a home computer, and even &#8220;TqbFjotlD32@GK&#8221; for Gawker media.</p>
<p>I&#8217;m sure we will be hearing more about the Gawker compromise over the next few days, and will keep you updated if anything interesting pops up.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2010%2F12%2F14%2Fgawker-compromise-password-lessons%2F&amp;title=Gawker%20Compromise%2C%20Password%20Lessons" id="wpa2a_12"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2010/12/14/gawker-compromise-password-lessons/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malicious Microsoft Imposter Locks Your Desktop</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2010/10/19/malicious-microsoft-imposter-lock-up-your-desktop/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2010/10/19/malicious-microsoft-imposter-lock-up-your-desktop/#comments</comments>
		<pubDate>Tue, 19 Oct 2010 15:29:05 +0000</pubDate>
		<dc:creator>Barracuda Labs</dc:creator>
				<category><![CDATA[Internet Security Tips]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[Anti-Spam]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=852</guid>
		<description><![CDATA[By Dave Michmerhuizen, Security Researcher Barracuda Labs researchers have recently seen a particularly nasty variant of Trojan.FakeAV  spreading in the wild.  We have seen this fake antivirus malware delivered both by way of  drive-by exploits and by way of direct links embedded in enticing spam emails.  The first sign of infection is the display of [...]]]></description>
			<content:encoded><![CDATA[<p><em>By Dave Michmerhuizen, Security Researcher</em></p>
<p>Barracuda Labs researchers have recently seen a particularly nasty variant of Trojan.FakeAV  spreading in the wild.  We have seen this fake antivirus malware delivered both by way of  drive-by exploits and by way of direct links embedded in enticing spam emails.  The first sign of infection is the display of a very convincing copy of a <a href="http://www.microsoft.com/security_essentials/" target="_blank">Microsoft Security Essentials</a> alert.   The malware then prevents the victim from running most programs on their desktop.</p>
<p>When the <em>real </em>Microsoft Security Essentials antivirus program  encounters malware on a computer it displays an alert such as this one:</p>
<div id="attachment_855" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/10/hotfix2.jpg" target="_blank"><img class="size-full wp-image-855" title="Valid Microsoft Security Essentials alert" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/10/hotfix2.jpg" alt="Valid Microsoft Security Essentials alert" width="450" height="238" /></a><p class="wp-caption-text">Valid Microsoft Security Essentials alert</p></div>
<p>A computer that has been attacked by this strain of Trojan.FakAV immediately displays the following very similar alert:</p>
<div id="attachment_858" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/10/hotfix1.jpg" target="_blank"><img class="size-full wp-image-858" title="Fake alert" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/10/hotfix1.jpg" alt="Fake alert" width="450" height="241" /></a><p class="wp-caption-text">Fake alert</p></div>
<p>The difference is that the second alert will continue to reappear even if the user closes it.   Any attempt to run Outlook or Internet Explorer, open a command window or even run the Task Manager will be intercepted and the alert will re-display. The inability to run most common programs on the computer leaves the uninformed user with no alternative but to explore the alert.   Choosing &#8220;Clean Computer&#8221; or &#8220;Apply Actions&#8221; brings up an interesting scan dialog:</p>
<div id="attachment_859" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/10/hotfix3.jpg" target="_blank"><img class="size-full wp-image-859" title="&quot;Online Scan&quot; results" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/10/hotfix3.jpg" alt="&quot;Online Scan&quot; results" width="450" height="338" /></a><p class="wp-caption-text">&quot;Online Scan&quot; results</p></div>
<p>A large list of  antivirus product trademarks is displayed.  Unfortunately, none of the well-known products seem to be able to find any problems. Cleverly interspersed with the reputable programs are images for five bogus antivirus &#8216;products&#8217; including:</p>
<p style="padding-left: 30px;">AntiSpy Safeguard<br />
Major Defense Kit<br />
Peak Protection<br />
Pest Detector<br />
Red Cross</p>
<p>Of course, no scanning ever happened, and the programs listed above are all built directly into the malware. They all appear identical except for a name change.   If the user installs the first one, this is displayed:</p>
<div id="attachment_862" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/10/antispysafeguard1.jpg" target="_blank"><img class="size-full wp-image-862" title="Fake AV &quot;Install&quot; dialog" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/10/antispysafeguard1.jpg" alt="Fake AV &quot;Install&quot; dialog" width="450" height="352" /></a><p class="wp-caption-text">Fake AV &quot;Install&quot; dialog</p></div>
<p>We were particularly amused by the wholesale theft of the GNU &#8220;free software&#8221; license agreement.  Behind the scenes, the installation of any of these bogus &#8216;products&#8217; sends messages across the Internet to IPs  85.234.191.174 and 85.234.191.180, both of which are located in Latvia.  The first is the home of a malicious fake porn site and the second hosts a site whose main page simply reads &#8220;There is nothing here&#8221;.</p>
<p>Once &#8216;installed&#8217; the program goes right to work fixing &#8216;problems&#8217;.   Unfortunately some of those problems require a missing &#8220;heuristic module&#8221;.</p>
<div id="attachment_864" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/10/antispysafeguard3.jpg" target="_blank"><img class="size-full wp-image-864" title="Fake AV &quot;scan&quot;" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/10/antispysafeguard3.jpg" alt="Fake AV &quot;scan&quot;" width="450" height="236" /></a><p class="wp-caption-text">Fake AV &quot;scan&quot;</p></div>
<p>Ignoring this requirement results in an error message. Outlook, Internet Explorer, Task Manager &#8211; the most basic Windows programs still will not run. Eventually the user might be tempted to click the purchase button for that module:</p>
<div id="attachment_866" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/10/antispysafeguard5.jpg" target="_blank"><img class="size-full wp-image-866" title="FakeAV &quot;money screen&quot;" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/10/antispysafeguard5.jpg" alt="FakeAV &quot;money screen&quot;" width="450" height="338" /></a><p class="wp-caption-text">FakeAV &quot;money screen&quot;</p></div>
<p><br style="”height: 4em”;" /></p>
<hr />
<h4>Fixing the Problem</h4>
<p>While it is not possible to open many programs, it is possible to open the  file explorer.  The malware file is found in the users Application Data folder, which is hidden by default.  Once the file is renamed it will no longer be loaded on reboot, and the machine can be cleaned using a reputable antivirus program.</p>
<p><a title="Web Filter" href="http://www.barracudanetworks.com/ns/products/web-filter-overview.php" target="_blank">Barracuda Web Filters</a> and the <a title="Web Filtering Service" href="http://www.barracudanetworks.com/ns/products/purewire_web_security_service_overview.php" target="_blank">Barracuda Web Filtering Service</a> stop the download of this threat.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2010%2F10%2F19%2Fmalicious-microsoft-imposter-lock-up-your-desktop%2F&amp;title=Malicious%20Microsoft%20Imposter%20Locks%20Your%20Desktop" id="wpa2a_14"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2010/10/19/malicious-microsoft-imposter-lock-up-your-desktop/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Barracuda Labs 2010 Midyear Security Report</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2010/07/28/barracuda-labs-2010-midyear-security-report/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2010/07/28/barracuda-labs-2010-midyear-security-report/#comments</comments>
		<pubDate>Wed, 28 Jul 2010 16:00:39 +0000</pubDate>
		<dc:creator>Barracuda Labs</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[ID Theft]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[search engine malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SEO Poisoning]]></category>
		<category><![CDATA[social networking security]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[Web Security]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=565</guid>
		<description><![CDATA[ Today Barracuda Labs released our 2010 Midyear Security Report, revealing data from two key areas: search engine malware  and Twitter use and crime rate. Our study shows that attackers have serious efforts devoted towards getting in front of the billions of eyeballs that are using search engines everyday and the millions of users that are [...]]]></description>
			<content:encoded><![CDATA[<p><strong> </strong>Today Barracuda Labs released our 2010 Midyear Security Report, revealing data from two key areas: search engine malware  and Twitter use and crime rate.</p>
<p>Our study shows that attackers have serious efforts devoted towards getting in front of the billions of eyeballs that are using search engines everyday and the millions of users that are connecting on social networks like Twitter. These research efforts allow us to continue to analyze their approaches and build new techniques to find them and protect users. Highlights of the study are below, and you can download the full report off the BarracudaLabs.com homepage.</p>
<p><strong>Searching for Malware</strong></p>
<p>We conducted a study across Bing, Google, Twitter and Yahoo! over a roughly two-month period. The analysis reviews more than 25,000 trending topics and nearly 5.5 million search results. The purpose of the study was to analyze trending topics on popular search engines to understand the scope of the problem and to identify the types of topics used by malware distributors.  Key highlights:</p>
<ul>
<li>Overall, Google takes the crown for malware distribution – turning up more than twice the amount of malware as Bing, Twitter and Yahoo! combined when searches on popular trending topics were performed. Google presents at 69 percent; Yahoo! at 18 percent; Bing at 12 percent; and Twitter at one percent.</li>
<li>The average amount of time for a trending topic to appear on one of the major search engines after appearing on Twitter varies tremendously: 1.2 days for Google, 4.3 days for Bing, and 4.8 days for Yahoo!</li>
<li>Over half of the discovered malware had originated between the hours of 4:00 a.m. and 10:00 a.m. GMT.</li>
<li>The top 10 terms used by malware distributors include the name of a NFL player, three actresses, a Playboy Playmate and a college student who faked his way into Harvard.</li>
</ul>
<p><strong>The Dark Side of Twitter</strong></p>
<p>As part of an ongoing study to data we released in <a title="Twitter's Dirty Little Secret" href="http://www.barracudalabs.com/wordpress/index.php/2009/06/08/twitters-dirty-little-secret/" target="_blank">June 2009</a> and subsequently in <a title="Twitter Red Carpet Era: Celebrities &amp; Criminals" href="http://www.barracudalabs.com/wordpress/index.php/2010/03/09/twitters-red-carpet-era-celebrities-and-criminals/" target="_blank">March 2010</a>, we analyzed more than 25 million Twitter accounts, both legitimate and malicious. The purpose of this part of the study was to measure and analyze account behavior on Twitter in order to model normal user behavior and identify features that are strong indicators of illegitimate account use. The study reviews several key areas including True Twitter Users<sup>1</sup>, Twitter Crime Rate<sup>2</sup>, and Tweet Number<sup>3</sup>.  Key highlights:</p>
<ul>
<li>In general, activity is increasing on Twitter: more users are coming online; True Twitter Users are tweeting more often, and even casual users are becoming more active. As users become more active, the malicious activity also increases.</li>
<li>Only 28.87 percent of Twitter users are actual True Twitter Users.</li>
<li>Half of Twitter users tweet less than once a day, yet one in 10 users tweet five or more times a day and 30 percent of Twitter accounts have never tweeted.</li>
<li>One in every eight Twitter users has at least 10 times more followers than they are following.</li>
<li>Only one in 10 users is following more than 100 users, and almost half are following less than five.</li>
<li>The Twitter Crime Rate for the first half of 2010 was 1.67 percent.</li>
</ul>
<p><strong> </strong></p>
<p>We are presenting the findings of both studies, as well as other Barracuda Labs work, at <a href="http://www.securitybsides.org/BSidesLVTalks">Security BSides Las Vegas</a> and <a href="http://www.defcon.org/html/defcon-18/dc-18-schedule.html">DefCON 18</a> this week in Las Vegas. Come see us!</p>
<p><em><strong>Security BSides Las Vegas:</strong></em></p>
<p>Wednesday July 28 at 3pm PT &#8211; The Darkside of Twitter (Dr. Paul Judge, Dave Maynor)</p>
<p>Thursday July 29 at 3pm PT &#8211; A Mechanic&#8217;s View of SQL Injection (Ray Kelly)</p>
<p><em><strong>DefCON 18:</strong></em></p>
<p>Saturday July 31 at 11am PT &#8211; Searching for Malware (Dr. Paul Judge, Dave Maynor)</p>
<p><strong></strong></p>
<p><strong>Resources:</strong></p>
<ul>
<li>Download the <a href="http://www.barracudalabs.com/research_resources.html">Barracuda Labs 2010 Midyear Security Report</a> at <a href="http://www.barracudalabs.com/research_resources.html">http://www.barracudalabs.com/research_resources.html</a>.</li>
<li>View the Barracuda Labs security research portal at <a href="http://barracudalabs.com/">http://barracudalabs.com</a>.</li>
<li>Follow Barracuda Labs on Twitter at <a href="http://twitter.com/barracudalabs" target="_blank">@barracudalabs</a>.</li>
</ul>
<p><strong>Footnotes:</strong></p>
<p>1 – ‘True Twitter User’ is defined as a user that has at least (≥) 10 followers, follows at least (≥) 10 people, and has tweeted at least (≥) 10 times.</p>
<p>2 – ‘Twitter Crime Rate’ is defined as the percentage of accounts created per month that were eventually suspended for malicious or suspicious activity, or otherwise misused.</p>
<p>3 – ‘Tweet Number’ is defined as a user’s average number of tweets per day.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2010%2F07%2F28%2Fbarracuda-labs-2010-midyear-security-report%2F&amp;title=Barracuda%20Labs%202010%20Midyear%20Security%20Report" id="wpa2a_16"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2010/07/28/barracuda-labs-2010-midyear-security-report/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Warning!  March Madness Means March Malware</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2010/03/12/warning-march-madness-means-march-malware/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2010/03/12/warning-march-madness-means-march-malware/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 04:29:53 +0000</pubDate>
		<dc:creator>vives</dc:creator>
				<category><![CDATA[Internet Security Tips]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[Rogue AV]]></category>
		<category><![CDATA[SEO Poisoning]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=336</guid>
		<description><![CDATA[By Barracuda Labs If you&#8217;re working on your Atlantic Coast Conference brackets this week, be extra careful where you click. Cybercriminals are up to their old tricks and hoping you&#8217;ll make a fast break to their Web sites. To raise the chances that you will, they&#8217;ve taken over popular search terms such as &#8220;ACC Tournament [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #888888;">By <em>Barracuda Labs </em></span></p>
<p>If you&#8217;re working on your Atlantic Coast Conference brackets this week, be extra careful where you click. Cybercriminals are up to their old tricks and hoping you&#8217;ll make a fast break to their Web sites.</p>
<p>To raise the chances that you will, they&#8217;ve taken over popular search terms such as &#8220;ACC Tournament Schedule 2010&#8243; and &#8220;ACC Tournament Bracket&#8221; and inserted poisoned links that lead to Rogue AV sites. SEO poisoning continues to pick up steam as attackers race to re-direct your browser to a Web site serving up various malicious programs. In this case, “CleanUp Antivirus&#8221; Rogue AV seems to be the flavor of choice.</p>
<p>As part of this experiment, Barracuda Labs discovered that a Google search for &#8220;ACC Tournament Schedule 2010&#8243; returned 23 malicious links within the first 50 results. Unless you know how to tell the difference between the good links and the bad ones, you stand almost a 50% chance of having your computer taken over by &#8220;Scareware&#8221; that tries to separate you from as much as $90 for the fake software.</p>
<p>We discuss Rogue AV and SEO poisoning in more detail in our <a title="Barracuda Labs 2009 Annual Report" href="http://barracudalabs.com/downloads/BarracudaLabs2009AnnualReport-FINAL.pdf" target="_blank">2009 Annual Report</a> released this week. The attacks are becoming increasingly more popular as hackers target vulnerabilities in legitimate Web sites, making it more likely for the page to be visited and the malicious content to be delivered. .</p>
<p><a title="March Madness Impacts Employee Productivity - CNBC" href="http://www.cnbc.com/id/35782187" target="_blank">CNBC sites surveys</a> that show almost 45% of American workers participate in March Madness pools at work. Much of this <a title="March Madness Impacts Employee Productivity - SFC" href="http://www.sfgate.com/cgi-bin/blogs/gettowork/detail?entry_id=58807" target="_blank">research</a> is happening on company time, causing a significant decrease in employee productivity as loyal fans follow their favorite teams. While the boss may turn a blind eye to that activity, a malware infection sure won&#8217;t help your ranking at work.</p>
<p><a title="Barracuda Web Filter" href="http://www.barracudanetworks.com/ns/products/web-filter-overview.php" target="_blank">Barracuda Web Filter</a> and <a title="Barracuda Purewire Web Security Service" href="http://www.barracudanetworks.com/ns/products/purewire_web_security_service_overview.php" target="_blank">Barracuda Web Security Service</a> customers are protected from this attack.</p>
<p>Below are screenshots that trace the attack.</p>
<p><strong>Top results for ACC Tournament Schedule 2010 from Google</strong></p>
<div id="attachment_328" class="wp-caption aligncenter" style="width: 455px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/03/accresults1.jpg"><img class="size-full wp-image-328" title="Top results for ACC Tournament Schedule 2010 from Google" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/03/accresults1.jpg" border="0" alt="Top results for ACC Tournament Schedule 2010 from Google" width="445" /></a><p class="wp-caption-text">Top results for ACC Tournament Schedule 2010 from Google</p></div>
<p><strong>Beginning at result 11, the links all lead to malicious content.</strong></p>
<div id="attachment_329" class="wp-caption aligncenter" style="width: 455px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/03/accresults2.jpg"><img class="size-full wp-image-329" title="Beginning at result 11, the links all lead to malicious content." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/03/accresults2.jpg" border="0" alt="Beginning at result 11, the links all lead to malicious content." width="445" /></a><p class="wp-caption-text">Beginning at result 11, the links all lead to malicious content.</p></div>
<p><strong>When the user clicks on a poisoned link, the following page pops up briefly.</strong></p>
<div id="attachment_330" class="wp-caption aligncenter" style="width: 455px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/03/Malware1.jpg"><img class="size-full wp-image-330" title="When you click on a poisoned link, this page pops up briefly." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/03/Malware1.jpg" border="0" alt="When you click on a poisoned link, this page pops up briefly." width="445" /></a><p class="wp-caption-text">When you click on a poisoned link, this page pops up briefly.</p></div>
<p><strong>Next, an official-looking warning appears.</strong></p>
<div id="attachment_331" class="wp-caption aligncenter" style="width: 455px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/03/Malware2.jpg"><img class="size-full wp-image-331" title="Next, an official-looking warning appears." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/03/Malware2.jpg" border="0" alt="Next, an official-looking warning appears." width="445" /></a><p class="wp-caption-text">Next, an official-looking warning appears.</p></div>
<p><strong>Followed by bad news, which is completely untrue.</strong></p>
<div id="attachment_332" class="wp-caption aligncenter" style="width: 455px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/03/Malware3.jpg"><img class="size-full wp-image-332" title="Followed by bad news, which is completely untrue." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/03/Malware3.jpg" border="0" alt="Followed by bad news, which is completely untrue." width="445" /></a><p class="wp-caption-text">Followed by bad news, which is completely untrue.</p></div>
<p><strong>The Web page wants the user to run a file.  Don&#8217;t do this!</strong></p>
<div id="attachment_333" class="wp-caption aligncenter" style="width: 455px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/03/Malware4.jpg"><img class="size-full wp-image-333" title="The Web page wants you to run a file.  Don't do this!" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/03/Malware4.jpg" border="0" alt="The Web page wants you to run a file.  Don't do this!" width="445" /></a><p class="wp-caption-text">The Web page wants you to run a file.  Don&#39;t do this!</p></div>
<p><strong>If the user does run the file, the user will become infected with CleanUp Antivirus.</strong></p>
<p><strong><br />
</strong></p>
<div id="attachment_334" class="wp-caption aligncenter" style="width: 455px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/03/Malware5.jpg"><img class="size-full wp-image-334" title="If you do run the file, you are infected with CleanUp Antivirus." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/03/Malware5.jpg" border="0" alt="If you do run the file, you are infected with CleanUp Antivirus." width="445" /></a><p class="wp-caption-text">If you do run the file, you are infected with CleanUp Antivirus.</p></div>
<p><strong>CleanUp Antivirus repeatedly sends you to this &#8216;money page&#8217; where the user is asked to submit a credit card.</strong></p>
<div id="attachment_335" class="wp-caption aligncenter" style="width: 455px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/03/Malware6.jpg"><img class="size-full wp-image-335" title="CleanUp Antivirus repeatedly sends you to this 'money page' where the user is asked to submit a credit card." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/03/Malware6.jpg" border="0" alt="CleanUp Antivirus repeatedly sends you to this 'money page' where the user is asked to submit a credit card." width="445" /></a><p class="wp-caption-text">CleanUp Antivirus repeatedly sends you to this &#39;money page&#39; where the user is asked to submit a credit card.</p></div>
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2010%2F03%2F12%2Fwarning-march-madness-means-march-malware%2F&amp;title=Warning%21%20%20March%20Madness%20Means%20March%20Malware" id="wpa2a_18"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2010/03/12/warning-march-madness-means-march-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

