UK typo business compromises web security
By Barry Collins,
A UK-based firm which tries to make money off of web address typos could be compromising security of the biggest companies online, a security research has said.
The problem stems from ISPs who employ the British firm Barefruit to intercept traffic from non-existent domains, where the user has typed a web address that doesn't exist.
Instead of returning a normal error message page, Barefruit provides a list of suggestions for the site the reader may have intended to visit, as well as a series of ads.
The potential security flaw arises when the user mistypes a subdomain of a well-known website - such as webmale.google.com instead of webmail.google.com. In this instance, according to a report on Wired.com, the Barefruit content appears in the browser window while the title bar continues to suggest it's an official Google site.
IOActive security researcher Dan Kaminsky claimed Barefruit's servers were vulnerable to a JavaScript attack that made it possible to serve up any links the attacker wanted, whilst still having the appearance of an official site. Such attacks could be used to fool people into divulging personal data to fake PayPal sites or Facebook accounts, for example.
Barefruit fixed the Javascript flaw last week, but Kaminsky said the underlying problem remains. "The entire security of the internet is now dependent on some random ad server run by some British company," Kaminsky told Wired.
Barefruit was unavailable for comment at the time of publication, but the company told Wired: "Barefruit endeavors to ensure online security while providing an improved internet user interface by replacing unhelpful and confusing error messages with alternatives relevant to what the user was seeking."
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Networking Analysis & Insight
Bring you own device: the $600 question
Inside the enterprise: A recent Cisco report claims bring your own device is gaining support from IT departments. But how much are staff willing to invest in personal technology?
- Interop 2012: Q&A, Saar Gillai, CTO, HP Networking
- Is BT the key to broadband Britain?
- Tencent: the biggest web company you’ve never heard of
- The truth about spam
- Have ISPs finally lost the DEA fight?
- Are you ready to launch IPv6 securely?
- Broadband, pricing and small businesses
- Welcome to the stay-at-home Olympics
- Q&A: Cisco on servers, storage and strategy
Latest Networking Reviews
HP t410 All-in-One Thin Client review: First look
- Swyx SwyxExpress X20 review
- Ipswitch WhatsUp Gold Premium 15
- ForeScout Technologies CounterACT 6.3.4
- ThinPrint Printer Dashboard review: First Look
- TITUS Aware for Microsoft Outlook review
- Windows Phone 7 Mango review: First Look
- Dartware InterMapper review
- Kemp Technologies LoadMaster 3600 review
- Sangfor WANACC M5500 review
advertisement
Most popular
- Apple iPad 3 vs iPad 2 head-to-head review
- ICO: Fines for cookie law breakers
- Hutchison denies it will pull plug on Three UK
- Sony Vaio T13 Ultrabook review: First look
- BlackBerry 7 OS certified to carry 'Restricted' UK government information
- Facebook floatation marred by Nasdaq glitch
- Open source software driving cloud-based innovation
- CIO: Career is over?
- EMC World 2012: Tucci declares Documentum is here to stay
- Dell PowerEdge R820 review
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





