Showing posts with label HTTPS. Show all posts
Showing posts with label HTTPS. Show all posts

Wednesday, 5 September 2018

Google Chrome Will No Longer Show 'Protected' At HTTPS Sites



To celebrate the tenth anniversary of Google Chrome, a new version of the browser has appeared that does not show the word 'secured' at https sites, makes using Flash Player more difficult, introduces an improved password manager and fixes 40 security vulnerabilities.

On 2 September 2008 , Google launched its own browser, which has since become the dominant browser. According to StatCounter, Chrome has a market share of almost 68 percent on the desktop . In the Netherlands, around 54 percent of desktop users would browse with Chrome. Yesterday evening the 69th version of Chrome appeared that contains all kinds of new features and improvements.

This allows Chrome 69 to enter passwords, address details and credit card numbers more accurately. It is data stored in the user's Google account and accessible directly from the Chrome toolbar. The browser also has an improved password manager that can generate unique passwords for websites and accounts. Saved passwords are then available to users with a Google account on both the computer and mobile devices.

Furthermore, Chrome 69 does not show the word "secured" on websites with a secure connection. Only the lock icon indicates that a secure connection is being used. Eventually the lock icon will also disappear. Google decided in July to display the message "Unprotected" at all http sites. The internet giant wants https sites to be the norm and users will only see a notification at http sites.

Also, in the browser measures have been taken to make the use of Adobe Flash Player more difficult. Previously, users could whitelists websites that wanted to access the built-in Flash Player. That has now changed. Users must allow this separately each time a website wants to enable Flash content, regardless of whether they have done so in previous sessions.

In addition, Google has fixed 40 vulnerabilities in the browser that prevented an attacker from stealing or modifying data from other websites in the worst case scenario. Updating to Chrome 69.0.3497.81 will happen automatically on most systems. For Android users, Chrome 69.0.3497.76 has been made available.

Sunday, 10 December 2017

Strong Increase Of Phishing Sites That Use Https



Not only legitimate websites use https more and more, phishing sites also have more and more access to a secure connection. There is even a strong increase in the number of https phishing sites, according to security company PhishLabs . In the third quarter of this year almost 25 percent of the observed phishing sites had a https connection.

A quarter earlier was still about 12 percent, while a year ago less than 3 percent of the phishing sites had a ssl certificate. According to the security company, there are two reasons why there is an increase in https usage among phishing sites. The first reason is that phishing sites are regularly offered via hacked, legitimate websites. When a legitimate website with a ssl certificate is hacked, the phishing page that is offered via the website will also have a secure connection.


The second reason according to PhishLabs is that criminals register domains for their phishing site and then enable https themselves. This then happens via certificate authorities that offer free ssl certificates, such as Let's Encrypt and Comodo. In this way, the phishing site looks more legitimate, says Crane Hassold of PhishLabs. Chrome automatically displays the "Safe" message at https sites. This refers to the secure connection, but end users think the website they are visiting is safe, Hassold notes.

"The misunderstanding about the meaning of https among the general public and the confusing appointment of https websites in browsers are the main reasons why it is a popular preference of phishers in hosting phishing sites," Hassold continues. "Combined with the rapid growth of https among website owners, we expect the number of https phishing sites to grow further."

Sunday, 18 October 2015

EFF Advises Against Eavesdropping HTTPS And VPN By NSA


This week, researchers presented information showing that the NSA may be able to store some encrypted connections, such as HTTPS, SSH and VPN, eavesdrop. Users can, however, take steps to prevent this, according to the American civil rights movement EFF.

The problem is that is used when an encrypted connection for instituting an algorithm for exchanging the key. In many cases, used for this purpose is the Diffie-Hellman algorithm. It forms the basis for modern cryptography and is used for VPNs, HTTPS, email, and other protocols. Because of the way the algorithm is implemented users run the risk of being bugged by the secret services, researchers said Alex Halderman and Nadia Heninger.

The problem is that a client, for example, a browser, and a server which use Diffie-Hellman must first agree on a prime number with a certain shape. Many applications thereby appear to use standardized 'hardcoded' primes. A secret service that any one particular prime number is able to "crack", then can eavesdrop all connections that use this particular prime number. It is in this case 1024-bit prime numbers.

NSA

"Based on the evidence we have, we can not prove that the NSA does. Our proposed way to crack Diffie-Hellman is better suited to the technical details of the large-scale decryption capabilities of the NSA than any other explanation," said the researchers. The documents from whistleblower Edward Snowden that the NSA have an infrastructure to monitor VPN connections. The system is designed to collect specific data that is required specifically to attack Diffie-Hellman.

"As the use of Diffie-Hellman in this feeble way is widespread in both standards and implementations, it may take years before the problems are resolved," as the researchers warn. They argue that all major governments can carry out similar attacks, if they do not do that.
Actions

Internet users who want to protect themselves against a possible attack may take various measures. Diffie-Hellman can be in the browser are so turned off, so that with it the setting up of an encrypted connection no use is made. Users of VPN have set their software to Diffie-Hellman is used only with 2048-bit prime., As the EFF in this article explains

Saturday, 4 July 2015

Spoofing Vulnerability In Google Chrome Can Distort Address


A spoofing vulnerability in Google Chrome makes it possible for a malicious website to spoof the address bar, the browser also shows a valid SSL certificate. The attack last Tuesday on the Full Disclosure mailing list revealed by researcher David Leo.

Then was the demonstration of Leo adapted by Mustafa Al-Bassam , the HTTPS version of Facebook was spoofed. The security company which operates Leo reported the problem to Google, but the Internet giant announced that it will not fix the vulnerability, because this is actually a denial of service, even if the browser crashes.

In addition, the impact of spoofing vulnerability is limited because users can not do anything in the spoofed pop-up or page. A direct phishing attack via this vulnerability is not possible, Al-Bassam noted. Readers of Hacker News report that the spoofing problem is partly also present in Firefox, the browser only because it crashes.

Wednesday, 1 July 2015

Survey: Most VPN Services Leak IPv6 Traffic


Twenty percent of European Internet users use a VPN service to encrypt its Internet or IP address to foreclose, but many of these services leakage data users, say researchers at Queen Mary University of London (QMUL).

VPN services are among others used to visit for example censored or domestically not accessible websites, but also to encrypt traffic so for example, the home network can not monitor this. The researchers looked at the services of the 14 most popular VPN providers and found that there are 11 user information leaked, so leave them in their research report ( pdf know).This involves things like websites visited and the content of comments posted online. The problem is not with websites visited via HTTPS.

IPv6


The problem is caused by the leakage of IPv6 traffic, also referred to as "IPv6 leakage". IPv6 is the successor to IPv4, which is the standard now. The Internet Protocol is the communications protocol that is used to identify hosts on networks, and to determine their location. The advantage of IPv6 is that many more addresses are available, and provides the protocol features that are not present in IPv4. Many network operators steps now to IPv6, but many VPN services protect only IPv4 traffic.

For the study the fourteen most popular VPN providers were used and made from different devices with a Wi-Fi network connection. Attacks were carried out from this access point that could perform attackers. There was passive monitoring place where unencrypted data was stored, and "DNS hijacking, in which the users' browser was redirected to another location.

The researchers also looked at the safety of different mobile platforms when using VPN services and discovered that Apple's iOS offers more protection, but data from Android users can leak. "There are several reasons why someone wants to hide his identity and it is worrying that they are at risk, even though they use a service that is precisely designed to protect them," said QMUL researcher Gareth Tyson. He is particularly concerned about people living in repressive regimes and surfing via a VPN.

Wednesday, 27 May 2015

Avast: Virus Scanner To Scan HTTPS Traffic



As more Internet traffic over SSL is encrypted, it is important that virus scanners can inspect HTTPS traffic, even though they have here a "man-in-the-Middle" with self-signed certificates to perform. That leaves anti-virus company Avast know, the free virus scanner is one of the most widely used anti-virus programs in the world.

An SSL certificate is used to encrypt traffic between websites and visitors. Traffic is theoretically no longer available by third parties. To still analyze whether the traffic is free of malware or other malicious code, Avast installs on computers a self signed certificate that is accepted by the browser. Normally give self-signed certificates in the browser a warning, because the publisher is not trusted. To solve this Avast adds itself as a certificate authority to the browser so that certificate or trust.

Once the browser a SSL connection setup the virus will own this certificate to use that now causes no warning. This way you will find there is actually a man-in-the-Middle (MITM) attack place. According to Avast this is necessary to scan the traffic.There is also a difference with traditional MITM attacks, said the virus fighter. "The" man in the middle "that we use is on the same computer as the browser and uses the same Internet connection."

Avast also announced that it generates a different private key for each certificate. A user would with its own installation therefore can not intercept traffic from other Avast users. Yet recently proposed a security researcher that the process of virus scanners, including those from Avast, safety HTTPS undermine.

Monday, 2 March 2015

Mozilla Removes Superfish Certificate From Firefox

Mozilla Firefox

For Firefox users against Man-in-the-middle attacks to protect Mozilla has decided to remove the Superfish certificate from the browser, but only when users first have the controversial program their computers have been removed. Superfish installed on computers a root certificate that could intercept SSL traffic and then inject ads.

However, the adware found to contain a vulnerability whereby users could be attacked. Several parties, including Lenovo, came with removal tools to remove both Superfish Superfish if the installed certificate. Some of these tools do not remove remove the Superfish certificate from Firefox, allowing these users are still at risk of being attacked.

To ensure that these users are still safe Mozilla started rolling out a hotfix . This hotfix checks whether Superfish is removed and then remove the Superfish certificate from Firefox. If Superfish namely still on the computer and Mozilla would remove the certificate from Firefox, users would no longer be able to visit HTTPS sites. The browser developer advises users therefore to the removal instructions to follow Lenovo, which both the software and the certificate can be removed manually

Wednesday, 25 February 2015

PrivDog: Only 57,000 Users At Risk


Adware PrivDog developer has released a security update after there was a vulnerability in the software detects allowing users targeted by Man-in-the-middle attack could be. In total, this "only" 57,000 users have run risk, says the developer. However, this is not the PrivDog software that comes with the programs of security provider and Certificate Authority Comodo. PrivDog makes adware that SSL connections are intercepted and software advertisements of "reliable partners" can inject.

Researchers discovered that PrivDog install a root certificate and thus intercepted each SSL certificate of websites using a self-signed certificate, even when it comes to SSL certificates that are not valid. As a result, the browser will accept HTTPS each certificate that is, whether by a Certificate Authority (CA) is signed or not. For example, users of public Wi-Fi networks could thus be the victim of a Man-in-the-middle attack. The vulnerability is present in versions 3.0.96.0 and 3.0.97.0 PrivDog.

These versions intercept SSL traffic and were downloaded from the website of PrivDog. Contrary to what was thought yesterday is Comodo Internet Security with an earlier version of PrivDog bundled working with a browser extension and thus is not directly vulnerable to this threat. That says researcher Hanno Boeck in addition to his research. PrivDog also confirms that the PrivDogplug-in that comes with the Comodo Browsers problem has not.

Globally, more than 57,000 people have downloaded the vulnerable PrivDog versions. According adware developer made ​​sure that the problem with some sites that use a self-signed certificate no certificate warning was given. However, the encryption was offered to the end user would remain intact, says PrivDog. Tonight there is rolled out an automatic update that fixes the problem by users.

Tuesday, 24 February 2015

Privdog Software Worse Than Superfish Adware


After computer manufacturer Lenovo appears to combine security provider Comodo adware with its own software SSL traffic intercepted, only the impact is much greater than with Lenovo's Superfish was. That says researcher Hanno Bock . Comodo is known software like Comodo Internet Security and Comodo Dragon Browser. With some of the programs PrivDog-adware is included.

Like Superfish intercepted PrivDog HTTPS traffic to inject ads from "reliable partners". Late last year, the ability to filter HTTPS traffic was already on the forum Comodo discussed . The software is after Superfish scandal now in the spotlight. A user decided because Superfish a test page to do, which warns users if their HTTPS connection is manipulated. Although the user is not used Superfish he got a warning. Then this user reported on Hacker News that the possible was the PrivDog-adware.

PrivDog not have the same vulnerability as Superfish, using a weak certificate and a weak password to protect the private key of the certificate, but one which is many times as possible according to Bock. Although Superfish same certificate and key used for all installations, PrivDog makes for each installation a separate key and certificate. The biggest problem is that each certificate PrivDog intercepted and replaced by a self-signed certificate.

It is also about certificates that were not valid in the first place. As a result, the browser will accept HTTPS each certificate that is, whether by a Certificate Authority (CA) is signed or not. "We are still trying to find out the details, but it looks bad," Bock says. The researcher also finds it strange that Comodo, which is itself a CA bundle adware with their own software. "If the CA would be their job to protect HTTPS, not break," the researcher concludes.

Meanwhile warns also the CERT Coordination Center (CERT / CC) at Carnegie Mellon University for PrivDog. An attacker could according to the CERT / CC HTTPS sites spoof and intercept HTTPS traffic without users see a certificate warning.Users will also be advised to remove PrivDog. This would also be the root certificate in question to be removed.

US-CERT writes: "Adtrustmedia PrivDog is promoted by the Comodo Group, which is an organization that offers SSL certificates and authentication solutions." A variant of PrivDog that is not affected by this issue is shipped with products produced by Comodo (see below). This makes this case especially interesting because Comodo itself is a certificate authority (they had issues before). As ACLU technologist Christopher Soghoian points out on Twitter the founder of PrivDog is the CEO of Comodo. (See this blog post.)

Update/Clarification: The dangerous TLS interception behaviour is part of the latest version of PrivDog 3.0.96.0, which can be downloaded from the PrivDog webpage. Comodo Internet Security bundles an earlier version of PrivDog that works with a browser extension, so it is not directly vulnerable to this threat. According to online sources PrivDog 3.0.96.0 was released in December 2014 and changed the TLS interception technology.

Update 2: Privdog published an Advisory.

Monday, 23 February 2015

Mozilla Is Considering Blacklist For Superfish Certificate


Mozilla is considering to put the Superfish certificate was installed on laptops from Lenovo on a blacklist.According to a discussion on Mozilla's Bugzilla where developers discuss issues and bugs in Mozilla software. By putting the certificate on a blacklist would user certificate warnings that are displayed when using the Superfish certificate can not ignore.

Through the root certificate that installs Superfish on the root store of computers, where all root certificates are stored, SSL connections can be intercepted. Superfish late because all SSL connections run through its own certificate. Researchers managed to crack the password using the private key of the Superfish certificate. This makes it possible in some cases to Man-in-the-middle attacks against systems that perform Superfish and certificate are active.

"Every certificate that is added to root stores by commonly used software and whose private key is known, is a risk," said Gervase Markham on Bugzilla. He notes that the behavior of software installation certificates or not install on computers can change. A program can one week show no suspicious behavior and that a week later do it again. "Without extensive research, we do not know exactly how they work, and in what cases can modify software root lists and also what root lists."

Although Mozilla employees were initially quite hesitant to put the certificate on the blacklist, the decision by Microsoft to the Superfish application and the certificate by using Windows Defender and Security Essentials to remove changed this. "This paves the way for us free to revoke the certificate," said Mozilla's Richard Barnes . Since Microsoft already has the certificate on many computers removed the impact of any blacklisting will therefore be easy. "It just adds to the disinfection," Barnes continues. However, if and when the certificate on the blacklist will not yet decided.

Weak "Superfish Certificate" Found In More Software


It is not just the owners of a Lenovo laptop that ran through the Super Fish-adware risk that their SSL traffic was intercepted, also all kinds of other programs using the same kind of certificate. That security researchers discovered Marc Rogers and Filippo Valsorda , both working for CloudFlare. The certificate used Superfish was from Komodia, an Israeli company.

The company shows the framework that for Superfish also used to have used other software. This relates to Keep My Family Secure, Easy hide IP Classic, Lavasoft Ad-aware Web Companion, Staffcop version 5.6 and 5.8, Kurupira Webfilter and Qustodio's parental control software. Also hide-my-ip is called by Rogers, only this software does not use SSL man-in-the-Middle and the certificate used is slightly different with the other programs. Yet it still uses an unrestricted root certificate with a simple password in plain text. Furthermore, the certificates Komodia for these programs used weak and the password is always Komodia.

"I think it's safe to assume that every SSL interception product sold by Komodia or Komodia SDK is based on the same method will be used," said Rogers. This means that the dangerous certificates are not only restricted to the laptops from Lenovo. Everyone who has come into contact with a product or Komodia parental control software installed check that it is not at risk.

"This problem is much bigger than we thought," warns Rogers. By using weak certificates, an attacker can eavesdrop on traffic or manipulate, without requiring users to see this. Even if the SSL connection is checked, the user sees only the strength of the connection between the Komodia software and its browser, and not the connection which goes over the internet. Users can use this page to check if it is installed on their computer, one of the Komodia certificates.
Superfish

Meanwhile Superfish puts the blame down to Komodia. The company leaves opposite the Associated Press that the vulnerability was inadvertently caused by a third party in the software. Superfish CEO Adi Pinhas also denounces the "false and misleading messages" in the media.

Researcher Late MITM Attack With Superfish Certificate See


An American security researcher demonstrated how he set up via a malicious WiFi network and the Superfish certificate Lenovo users may attack. Previously showed researcher Robert Graham already see how the password cracked that the private key of the Superfish certificate used.

Something for which he needed about three hours. Then he wanted to demonstrate that an attack with the obtained certificate would not only theoretically, as the CTO of Lenovo claimed, but also practical. For this, Graham chose as a hardware Raspberry Pi2 combined with Alpha-WiFi adapter. Through " RPI Wireless Hotspot "he changed the Raspberry Pi2 into a wifi hotspot, while sslsplit to perform the Man-in-the-middle attack used. In total, cost of setting up the hotspot also three hours.

Graham leaves on his blog how a simulated user via its Wi-Fi hotspot is internet banking can be intercepted, even though the user gets when visiting his bank site to see a valid SSL icon. According to Graham he used for performing the attack only commonly available tools. "The only special feature is sslplit, but it is a tool that companies use often for security purposes, and does not have a special hacking purpose. '" The researcher therefore concludes that this attack is really practical and not just theoretical.

Saturday, 21 February 2015

Lenovo Warns Customers For Super Fish-Adware


Lenovo has a security bulletin released which warns customers for the Super Fish-adware that was installed previously on laptops. According to the manufacturer discovered several vulnerabilities in Superfish, including the installation of a self-signed root certificate.

Consumers can remove Superfish, but Superfish certificate but will remain on the system. Since Superfish according Lenovo SSL traffic intercepted this is a "security concern". Therefore, the manufacturer removal instructions put online, and a list of vulnerable laptops. These laptops in E, Flex, G, M, S, U, Y Yoga and Z-series that are delivered between September 2014 and February 2015. Together account for more than 40 models.

Customers who leave running the certificate in certain scenarios, for example when an open Wi-Fi network, the risk of being attacked by a man-in-the-Middle. Users will also be advised to remove the certificate. Furthermore Superfish would be asked to turn off all server activity of the software. Via Twitter Lenovo announces that it is busy working to rectify the problem and regain the trust of customers.

The CERT Coordination Center (CERT / CC) at Carnegie Mellon University now has a warning issued for the certificate and advises users to delete it. There are EFF by the American civil rights movement removal instructions put online, including for Firefox users.

Superfish-Adware Is Lenovo Customers Cost


The Super Fish-adware that Lenovo laptops installed and making SSL connections risk reminiscent of the Sony rootkit scandal a few years ago and the computer manufacturer will ultimately cost customers.That says Adam Winn software company OPSWAT.

"Although the intentions may not be malicious, the implementation is certainly is. Superfish is more than just adware, it's a man-in-the-middle attack that occurs as adware. In an era of continuous security-related news it is shocking that Lenovo software installs the SSL chain breaks on in such a fundamental way. " Winn sees similarities with the Sony rootkit scandal in 2005, only this time the consequences are much greater.

"It touches both privacy as the fundamental trust that consumers have SSL-protected Web sites." He also predicts that this action Lenovo customers will cost. "Lenovo has a loyal following among IT professionals, as evidenced by the present Thinkpads anywhere within companies. There is no doubt that this incident will have a severe drain on the balance of Lenovo. No system tolerates a Man-in the-middle attack on proprietary or BYOD devices. "

The American civil rights movement EFF calls it an amateurish design choice of Superfish to inject ads through a self-signed certificate. "Lenovo's decision to provide this software was incredibly irresponsible and a great abuse of the trust that they received from customers." Lenovo late by Bloomberg know it was a mistake to install the software standard on laptops and that the only purpose was to improve the customer experience.

Thursday, 19 February 2015

Adware Lenovo Laptops Brings SSL Connection In Danger


Chinese computer maker Lenovo installs default very aggressive adware on the laptops that sells to the customer, allowing all users to set up SSL connections that are at risk. It was some time known that Lenovo installs the Superfish-adware on laptops, only now its impact appears to be much greater than was assumed initially.


According to researcher Marc Rogers adware performs a "Man-in-the-middle attack" to gain access to sensitive data running over SSL connections and inject ads. In addition, Lenovo also installs a weak certificate on the system, so users no SSL connection that they can set up more confidence.


The problem was already on 21 January by a user on the Lenovo forum reported. According to the user hijacks Superfish, also known as Visual Discovery and Similar Products, all SSL / TLS connections using a self-signed root certificate authority that is trusted by the browser. The user in question has returned to his laptop and asked for his money back.

Through Superfish ads are displayed on the computer. Rogers calls it an infamous piece of adware that hijacks legitimate connections, user activity monitors, collects personal information and upload to servers, pop-up displays with adware and another attacking users of SSL connections and uses a self-signed certificate. Superfish used also a weak SHA1 certificate.SHA-1, however, has been replaced by SHA-256, SHA-1 as attacks on can now be carried out using standard computers. It also appears that there is a 1024-bit RSA key is used which is to crack.

The researcher suggests that Lenovo is therefore ignorant and reckless busy. "It's probably the worst I've seen put on a supplier customers." In a reaction that enables Lenovo Superfish temporarily of laptops has been removed. In addition, the manufacturer notes that the plug-in can not hurt.

Or the plug-in is removed only on new laptops and Lenovo can do this on existing computers is unclear. It is also unclear whether in this case the self-signed root certificate authority is removed. The Next Web reports that Firefox users are not at risk, because the open source browser uses its own certificate store. Furthermore, virus scanners would Superfish detect adware and recommend to remove.

Lenovo said in a statement that Superfish from January 2015 not installed on new systems. Furthermore Superfish would already sold Lenovo machines are turned off. According to the manufacturer the adware on only a "select few" consumer models installed.

Superfish Domains & IP Addresses
Security Researcher Conrad Longmore has published a list of IP addresses and domain names used by Superfish. He notes that the information is sent to US IP addresses. Superfish itself is Israeli. "What seems to be a popular place to develop adware," he notes.


Owners of a Lenovo laptop can through this page, check the Superfish Certificate Authority trusted by their browser and they are therefore at risk.


Several researchers have meanwhile managed to crack the password that the private key of the Superfish certificate used.The password proved "komodia" to be, according to an analysis by researcher Robert Graham . In theory it would be possible thus to perform man-in-the-middle attacks and encrypted traffic to intercept Lenovo users. For this, an attacker would have to place between the user and the Internet. Further says researcher Erik Loman that contrary to what was first reported Firefox users be vulnerable.


Lenovo showed earlier know Superfish is no longer installed in new laptops and existing installations were off.Whether this also the self-signed certificate is removed is unclear. Lenovo has asked for clarification but received no reply.

Lenovo late know that it completely stops Superfish and not on machines will install the software. Additionally, the software off in January of this year on the server side of Lenovo. Thereby Superfish would no longer be active. Or users themselves must remove the self-signed certificate is unclear. This question is still open at Lenovo.

The computer manufacturer also states that it has extensively researched the technology, but has found no evidence to justify the resulting safety concerns. "But we know that users are concerned about this problem and therefore immediate action taken by products with this software to deliver any more.

Tuesday, 17 February 2015

Microsoft Gives Details On HSTS Security In IE


Last month it was announced that Microsoft finally HTTP Strict Transport Security (HSTS) is added to Internet Explorer, which users must protect against man-in-the-middle attacks. Now the software giant has more details given about the security measure.

HSTS allows websites visited to visit over HTTPS only over HTTPS, even though HTTP is introduced into the address bar.The browser in this case captures the user's command and turns off automatically in HTTPS. Thus, no information is transmitted over unsecured HTTP there. HSTS websites offers two options to secure their connections with visitors.

The first option is to register the website on a table loaded by Internet Explorer and other browsers with HTTP traffic directly to HTTPS is put through. This makes IE using the Chromium HSTS list. Chromium is the open source browser on which Google Chrome is based. The second option is to offer a HSTS header. In this case, the browser after having visited the site for the first time over HTTPS, all future HTTP connections run over HTTPS.

Microsoft warns that HSTS can have two important effects on users. If there namely a certificate warning is displayed, the user can not ignore and must disconnect. Additionally supported by HSTS sites no mixed content. All content should be delivered over HTTPS. This can be a problem for websites where for example ads and images are loaded over HTTP. The HSTS-feature is already testing the Windows 10 Technical Preview and will later be added to the Project Spartan browser of the new OS.

Wednesday, 9 April 2014

Fake poll as a lure for Facebook Phishing Scam

The Facebook application asks users to register their votes

Cyber criminals have again found a new way to Facebook to trick users into entering their login details. They run a fake online poll for the purpose of luring. Potential victims to a phishing site.

A pop-up window requesting for user account information

Symantec reports that the scammers run an online poll with the question: "Who better boys or girls" Once the visitor has cast his vote will be prompted to log in to the Facebook account and asked whether the visitor is male or female. After logging the victim sees the message that his voice has been sent. Scammers host the site on a subdomain ([http://] Smart Apps. [deleted]. com) to indicate that it is an application and the to appear. matter professionally in this context is the number of voters also raised periodically.

A comparison of the previous vote count and the current vote count

While it does seem that way at first glance Facebook has nothing to do with the campaign. When visitors log in reality they give their login information to the cyber criminals.

The scammers probably realize only too well that many Facebook users, this kind of thing every day without too much thought do. It is not inconceivable that they have already succeeded in many account data store.

Prevent
To a victim of a Facebook scam to be, it is important that you never put your password on domain other than facebook.com enter. The real login page of Facebook is secured with an SSL certificate which can be used by the padlock in the address bar of the browser and the HTTPS recognized connection.