Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

4/27/2010
01:18 PM
John H. Sawyer
John H. Sawyer
Commentary
50%
50%

Trusting 'Trusted' Sites Again

I've been teaching a user security awareness and training course to faculty and staff at our university. One of the great aspects of the class is the discussions that develop out of the participants' questions, like the security of social networks and how to use wireless securely while on the road. Lately, I've been getting one question more and more often: How do I know if a site is safe?

I've been teaching a user security awareness and training course to faculty and staff at our university. One of the great aspects of the class is the discussions that develop out of the participants' questions, like the security of social networks and how to use wireless securely while on the road. Lately, I've been getting one question more and more often: How do I know if a site is safe?That's a simple question that has become tougher to answer. It used to be that we security professionals would advise users to stick to trusted websites for activities like shopping, e-mail, and searching. For news, go to sites like the New York Times or CNN. Shopping -- Amazon and eBay.

Unfortunately, that's not the case anymore. Just as we've adapted our methods of protection, attackers have done the same. First they began targeting sites that users trusted to be safe from malware. They would compromise the site, add their malicious code, and wait for the victims to pile up.

Next came malicious advertising, or malvertising. Attackers were finding it wasn't always so easy to hack the trusted site. Either the security was solid or changes to Web content were noticed immediately. So they adapted by delivering their malicious code via third-party advertisers. Popular sites like The New York Times and Gizmodo are examples of sites hit by malvertising.

After I explained those scenarios to users, they again asked the same question: How do I know whether a site is safe? My first recommendation was to follow standard defense methods I've been teaching, which include not running as an administrator, keeping your operating system and third-party applications patched, and keeping your antivirus updated and run daily scans.

Once they're patching, updating AV, and running as a nonprivileged user, then we talk about determining site safety. There are several companies that try to monitor the "badness" of a site by scanning and monitoring for malicious content. McAfee's SiteAdvisor and Web of Trust are two that come to mind. They have a search function that lets you put in the domain in question to find out whether malicious content has been seen on that site and how recently it was seen.

Both Microsoft and Mozilla include some functionality in their browsers to alert when a user is visiting a site that has been reported to have malicious content or been used for phishing attacks. Additionally, there are browser toolbars that provide additional functionality for determining whether a site is good or bad. ThreatExpert has a good one called BrowserDefender, which has integration with popular search engine results to give you the ranking of a site. McAfee and Web of Trust also have software that can provide similar functionality.

There's still the chance something can slip through one of those tools, but by being aware of the threats and having defensive measures in place, users will stand a better chance of not getting their systems owned...both at work and at home.

John H. Sawyer is a senior security engineer on the IT Security Team at the University of Florida. The views and opinions expressed in this blog are his own and do not represent the views and opinions of the UF IT Security Team or the University of Florida. When John's not fighting flaming, malware-infested machines or performing autopsies on blitzed boxes, he can usually be found hanging with his family, bouncing a baby on one knee and balancing a laptop on the other. Special to Dark Reading.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Commentary
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-3493
PUBLISHED: 2021-04-17
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivile...
CVE-2021-3492
PUBLISHED: 2021-04-17
Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a denial of service (ker...
CVE-2020-2509
PUBLISHED: 2021-04-17
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later Q...
CVE-2020-36195
PUBLISHED: 2021-04-17
An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulnerability in the following versions of Multimedia C...
CVE-2021-29445
PUBLISHED: 2021-04-16
jose-node-esm-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed `JWEDe...