Original URL: http://www.channelregister.co.uk/2008/01/23/ebay_thwarts_redirection_ruse/
High-profile websites have cleaned up their act after a small team of security researchers documented how they were unwittingly helping phishing fraudsters.
Phishing scams often use "open redirector" exploits on major sites to make their attack URL look more legitimate. The trick also makes it more likely that fraudulent emails that form the basis of phishing attacks will slip past spam filters.
Typically, security shortcomings on targeted sites allow scammers to furnish links that appear kosher but actually redirect to a fraudulent site.
Previous Register stories have covered examples of the ruse practiced on websites including Barclays Bank (story here (http://www.theregister.co.uk/2006/08/15/barclays_phish_scam/)), eBay (here (http://www.theregister.co.uk/2006/11/13/ebay_redirection_ruse)), and others.
A campaign by SiteTruth to name and shame high profile firms that fail to block open redirector exploits is beginning to bear fruit.
SiteTruth cross-referenced the 10,000 sites listed in PhishTank (a clearing house for reports about phishing sites) with the 1.7 million sites in the Open Directory Project database to discover a list of problem domains. Domains listed typically have a security vulnerability which is being exploited by phishing fraudsters.
URL redirection isn't the only category for listing in this blacklist (hosting or otherwise unwittingly helping phishing scams also counts), but the sites allowing URL redirection included many high-profile organisations that ought to know better, including Google Maps, AOL, and eBay.
Recent updates by Google Maps and eBay since we wrote (http://www.theregister.co.uk/2007/12/12/phishing_redirection) about SiteTruth's work have nipped the problem in the bud. Other organisations, such as AOL, are yet to address the problem. Nonetheless, SiteTruth is happy at making inroads into the number of high-profile sites open to abuse.
"You'll be pleased to know that the combination of your article, our reports, efforts at the Anti-Phishing Working Group, and a certain amount of nagging on our part has made a considerable dent in the 'open redirector' problem," SiteTruth's John Nagle told El Reg. Google fixed its problem last week, and currently has no active phishing attacks listed in PhishTank. eBay also cleaned up its act and it too is now out of the tank.
AOL, however, is yet to clear up its problem, first reported (http://www.phishtank.com/phish_detail.php?phish_id=375596) earlier this month, that allows open redirector exploits (harmless example that redirects from AOL to El Reg here (http://www.aol.com/redir.adp?_url=http://www.theregister.co.uk)).
That's just one example that illustrates the problem is a long way from being resolved. Nonetheless, SiteTruth's list of problem domains is shrinking.
"Our list of major sites with exploited vulnerabilities, not all of which are open redirectors, has been shrinking as the word gets out. There were 171 problem domains in early December, and we're down to 54 today. Publicity is working," Nagle added.
Phishing sites come and go rapidly, but some problematic domains have become a fixture of SiteTruth's phishing blacklist (http://www.sitetruth.com/reports/phishes.html).
"Only 16 of those domains have been on our list since its inception in late November. Most of those are DSL service providers inadvertently providing connections for computers hosting phishing attacks. The others come and go as phishers find vulnerabilities and site operators plug the holes," Nagle concluded. ®
Security researchers show how to hook phishers (19 March 2008)
http://www.channelregister.co.uk/2008/03/19/anti-phishing/
eBay scripting trick used to boost seller ratings (18 March 2008)
http://www.channelregister.co.uk/2008/03/18/ebay_scripting_malfeasance/
Hackers find clever new way to hose Google users (6 March 2008)
http://www.channelregister.co.uk/2008/03/06/googe_iframe_piggybacking/
Phishers clean up at online casinos (28 February 2008)
http://www.channelregister.co.uk/2008/02/28/casino_phishing/
Spammers dive into Google's lucky dip (30 January 2008)
http://www.channelregister.co.uk/2008/01/30/google_feature_aids_spammers/
eBay: 'We will lower listing fees' (29 January 2008)
http://www.channelregister.co.uk/2008/01/29/ebay_lowers_listing_fee/
Phishing coders hook clueless crooks (24 January 2008)
http://www.channelregister.co.uk/2008/01/24/phishing_kit_backdoor/
Perl.com sends visitors to porn link farm (19 January 2008)
http://www.channelregister.co.uk/2008/01/19/perl_site_redirects_to_porn_site/
Cybercrooks lurk in shadows of big-name websites (12 December 2007)
http://www.channelregister.co.uk/2007/12/12/phishing_redirection/
eBay redirection ruse reloaded (13 November 2006)
http://www.channelregister.co.uk/2006/11/13/ebay_redirection_ruse/
US harbours one-in-four phishing sites (7 November 2006)
http://www.channelregister.co.uk/2006/11/07/phishing_stats_october/
Barclays scripting SNAFU exploited by phishers (15 August 2006)
http://www.channelregister.co.uk/2006/08/15/barclays_phish_scam/
Spear phishers target eBay (5 January 2006)
http://www.channelregister.co.uk/2006/01/05/ebay_spear_phishing/
eBay provides backdoor for phishers (28 February 2005)
http://www.theregister.co.uk/2005/02/28/ebay_phishing_backdoor/
eBay aims to thwart phishing (6 January 2005)
http://www.theregister.co.uk/2005/01/06/ebay_anti-phishing/
UK banks and police proffer anti-phishing advice (22 October 2003)
http://www.theregister.co.uk/2003/10/22/uk_banks_and_police_proffer/
Lloyds TSB phishing scam nipped in the bud (25 September 2003)
http://www.theregister.co.uk/2003/09/25/lloyds_tsb_phishing_scam_nipped/
© Copyright 2008