Home > Windows Security Tips > Vulnerability/Authentication tips for Windows > Stop URL spoofing attacks in their tracks
Windows Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

VULNERABILITY/AUTHENTICATION TIPS FOR WINDOWS

Stop URL spoofing attacks in their tracks


Serdar Yegulalp
03.10.2005
Rating: -4.67- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


In this two-part series, Serdar Yegulalp explains how URL spoofing targets Windows users and how to protect systems from attacks. Part one detailed how URL spoofing works and how to educate users on its warning signs. Part two below covers anti-spoofing browser features, domain spoofing, weaknesses in international domain names and e-mail vulnerabilities.

In my previous tip, I offered some tricks to help you and your users identify URL spoofing scams -- but user education can only go so far. Today I'll discuss steps you can take to help lock down Windows systems.

Use browser-based features when available
As spoofing becomes more common, newer Web browsers are being programmed to identify such scams. For example, Mozilla's Firefox 1.0.1 can detect when certain tactics are being employed (i.e. site redirection that falsely claims to be SSL-protected). It then warns the user accordingly. Consider this another reason to dump Internet Explorer. Also be mindful of third-party plug-ins like CoreStreet's SpoofStick, which can also help protect you from spoofing scams.

Set up a spoof@ e-mail address where potential spoof messages can be sent and analyzed
An overwhelming number of spoof e-mails forced both eBay and PayPal to set up spoof@ addresses where people can forward the scams as attachments. Each company's security team analyzes the URLs and routing information in each e-mail to quickly identify and shut down offenders. If you create such an e-mail account, you should assign someone to monitor it continually to keep up with your volume of spoofed traffic.

Enforce reverse DNS authorization if possible
Reverse DNS authorization insures that a given piece of e-mail is indeed coming from the professed sender's domain. Unfortunately, not all ISPs consistently support reverse DNS authorization, which means that a perfectly legitimate e-mail may bounce.

Accept and send only plaintext e-mails
This fairly radical maneuver is a great way to expose spoof URLs. All hyperlinks are displayed in plaintext-only format. A bogus link will be obvious. How to enforce such a policy on inboound e-mail depends on your mail setup. For Exchange, you can use a third-party product called Aloaha.

If you have to send automated e-mails from your domain, you may also be wise to send plaintext-only e-mails and educate recipients about your decision. Make it clear that if anyone receives non-plaintext e-mail from your domain, URLs in that e-mail may be spoofed. If there's no pressing need to send HTML e-mails from your domain, it's better not to do so.

Beware of URL spoofs that take advantage of International Domain Name (IDN) system weaknesses
This is a new and dangerous variety of URL spoofing that relies on IDN system weaknesses to render bogus URLs that appear to be legitimate, even when using SSL. It creates URLs using international characters that look like conventional Roman or Latin characters. To demonstrate this problem, Secunia's Eric Johanson conducted a proof-of-concept exploit where the URL http://www.paypal.com was invisibly redirected to http://www.xn--pypal-4ve.com. This is called a homograph attack, in which an attacker or phisher spoofs the domain and URLs of businesses. There is no easy way to detect or work around such attacks at this time.

Homograph attacks will only work in browsers configured to support internationalized domain names. Internet Explorer does not support such domains by default, but Mozilla and Firefox do. To disable this feature in Mozilla-based browsers, go to about:config and set network.enableIDN to "false." However, until the IDN system can be hardened against spoofing, your best defense is to spread word about spoofs as quickly as possible to avoid being taken by them.

Serdar Yegulalp is the editor of the Windows 2000 Power Users Newsletter.


More Information from SearchWindowsSecurity.com

  • Tip: Get educated on URL spoofing scams
  • Article: Microsoft fixes spoofing flaws in ISA, proxy server
  • Article: Attacking the IE alternative

  • Also visit our sister site SearchExchange.com for additional coverage of e-mail security issues.

    Rate this Tip
    To rate tips, you must be a member of SearchWindowsSecurity.com.
    Register now to start rating these tips. Log in if you are already a member.




    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Vulnerability/Authentication tips for Windows
    Buffer overflows can be prevented by GS cookies
    DHCP Client Service error affects network security
    Free security tools that can improve IIS security
    Correct improperly assigned user rights in Windows XP
    Free security testing tools for Windows handheld devices
    Windows Integrity Control (WIC) in Vista
    Metasploit 3.1 updates improve Windows penetration testing
    Cross-site scripting 101: XSS attacks plague Web browsers
    Windows network rights, password policy and network security testing
    Top Windows security testing tips of 2007

    Hardening
    Anti-spyware, anti-virus proetction for Windows e-mail needed
    Enterprise email and IM security journal
    10 tips in 10 minutes: Phishing exposed
    Learning Guide: How to fight spam on Exchange Server
    Office 2003 SP2's antiphishing filter for Outlook
    Blocking peer-to-peer applications
    Step 1: Blocking peer-to-peer applications
    Symantec to purchase IMlogic
    Security Bytes: New threats target IM chatters, Web browsers
    Step-by-step guide: Simple e-mail encryption

    Hardening
    ActiveX security improves with Internet Explorer 8's security features
    Web security features of Internet Explorer 8
    How can I use Process Explorer as a Web security tool?
    New Windows security tool protects users from keyloggers: XecureCK
    Cross-site scripting 101: XSS attacks plague Web browsers
    What's hot in Windows security? New Microsoft Office Security Guide
    Data protection on the Web: Windows SSL security and other myths
    What's hot in Windows security: Updating Windows Update; new IE scare
    Web security tactics that harden Windows networks
    What do you know about Microsoft Internet security?

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

    HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT DownloadsBlogs
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts