Greedy ISPs Expose Users to Unsecure Websites

By Alice Turner
22:11, April 19th 2008
83 votes
Vote this story
Greedy ISPs Expose Users to Unsecure Websites

Greedy ISPs in the U.S. and other parts of the world are cashing in on their customers' mistyped web addresses, exposing them to security risks. IOActive security researcher Dan Kaminsky has warned several large ISPs that their practice of redirecting users to ad pages when they try to access pages that don't exist has created massive security holes.

"The ISPs will say they're doing wonderful favors for users who might have to otherwise go back and type in the real name of the site they're seeking. But the reality is that anytime ISPs add yet another level of complexity to their networks, they necessarily introduce more security bugs," said John R. Levine, author of Internet for Dummies, to The Washington Post.

These Internet Service Providers are subverting the Domain Name System or DNS, which translates website names into numeric addresses, when users type a wrong web address. Instead of getting an error page, they are bounced to an ads page served up by a British company called Barefruit, which pretends to actually to be the non-existent domain when delivering the ads.

This means that, taking into account Barefruit's failure to screen for rogue JavaScript code, hackers were able to create fraud sites which appeared to be and looked exactly like eBay, for example. Earthlink, Qwest and Verizon have outsourced at least portions of their ad-serving technology to BareFruit, thus exposing their customers to massive security risks.

"This kind of practice means the security of the Web is being limited to the security of this ad server," Kaminsky told Security Fix on Friday. "My work is to secure the Web and other computer infrastructure, but this becomes near impossible when other people are injecting content into domains that I am professionally trying to secure," he said.

The British ad company has fixed their security holes after being noticed by IOActive security staff.



Image Credit: gamesforfree.net
© 2007 - 2008 - eFluxMedia
dotclear

Other News in

Microsoft is Boasting the Black Friday Sales

Microsoft is Boasting the Black Friday Sales

This last weekend's start of the holiday shopping season beat all expectations indeed, as US consumers spent 3 percent more than last year despite the long debated financial crisis. And as far as the...

Britney beats Obama in web search race

Britney beats Obama in web search race

San Francisco - Britney Spears was more popular than US president-elect Barack Obama among internet searches through 2008, according to web portal Yahoo. The results came from ranking billions of...

TV, Our Children’s Parent?

The U.S. National Institutes of Health, Yale University and the California Pacific Medical Center reviewed a number of 173 researches that study the impact of mass-media on children’s development and...

Apple Recommends For Mac Users Antivirus Software

Apple Recommends For Mac Users Antivirus Software

On November 21, Apple Incorporated posted on their support website a recommendation to Mac users, which read that the company encouraged the use of multiple antivirus services on their...

Britney Did It Again

Britney Did It Again

As it happens every year, Yahoo revealed the top ten most popular searches on their portal. Much to everyone’s surprise, searches related to Britney Spears outdid the ones related to the...

dotclear
Latest videos in Technology
Beauty and the PC
Nokia goes multi-sensory with...
Search for insight through...
The human face of robotics
'Karma' For Plug-In Hybrid

dotclear
Technology You are here: Technology
» Technology   » Gadgets   » Video Games   
E-mail To A Friend Print RSS Text size: Decrease font size Increase font size
dotclear
dotclear
dotclear
Most Popular in Technology
Facebook Connect Is Ready To Conquer The WebFacebook Connect Is Ready To Conquer The Web

» read full story
dotclear

Interested In This Topic?

News Alert will keep you informed. Find out more.
dotclear
Photos Gallery
dotclear
Today's Latest News
Swedish Researchers Can Swap Bodies

» read full story
dotclear