Tim Anderson

A stolen domain highlights new web risks

As firms increasingly turn to the cloud for their computing needs, securing the desktop is no longer enough

Written by Tim Anderson

The rise of hosted services is giving new opportunities to malware. Consider the case of blogger David Airey. Late last year he had an unpleasant surprise. His domain name had been transferred to a criminal without his knowledge. An email to the new owner resulted in a demand for money. In the meantime, his site had disappeared from the internet, and although he could start a new site, he had lost his Google search rank.

The cost of the lost business was in excess of the extortionist’s demand, so there was an argument for paying up quietly. Logic like this perpetuates the problem, so it is great that Airey chose instead to blog about the problem, drawing some high-profile attention and eventually securing the return of his domain through the intervention of the chief executive of GoDaddy, the ISP that was hosting the stolen domain.

Technically, the problem was caused by a cross-site request forgery against Google’s email service. Airey must have visited a compromised site while logged into his Google Mail account. A script on the compromised site posted a request to Google which set up a mail filter. The mail filter forwarded any emails concerning domain transfer to the scammer, then deleted them from the inbox. When Airey announced on his blog that he was taking a holiday, the fraudster made his move.

Google has apparently fixed this security hole, though this would not remove existing malevolent filters. It is disappointing that users have not been notified of the risk. Still, the real lessons from Airey’s experience are not confined to this particular case. Users are now mostly aware of desktop risks like running email attachments, but how many realise the security benefits of logging out of web-based services, rather than enjoying the convenience of persistent log-in, or the risks of having secure pages open on one tab of their browser while clicking random search links in another? Attacks like cross-site scripting and cross-site requests are subtle and hard to spot. Another part of the problem is that web vendors such as Google or Facebook are keen to encourage users to be logged in permanently.

Airey’s story is thought-provoking. In part it is about the value of domain names, the vulnerability of web-based businesses, and the risks of sharing information such as holiday plans in blogs. More generally, it shows that moving data from local servers to the cloud changes, but does not remove, security risks.

While firms can easily lock down desktops, controlling what users do on the internet is more difficult. As web applications become more critical, securing the desktop is no longer enough.

  • Have your say
  • Send to a friend
  • Print this
  • Share

Tags:

reader comments

related articles

Benefits and pitfalls of being social

IT and HR must work together to ensure Web 2.0 tools are used responsibly and productively 10 Dec 2007

 

Nominet sees opportunities and risks

The UK registry urges firms to protect domain names and looks forward to new gTLDs 29 Nov 2007

Phishing affects consumer confidence

According to a new survey consumers lose faith in brands that have been phished 27 Nov 2007

Social networks urged to tighten security

New Sophos report warns against complacency 22 Jul 2009

Woman loses $4,000 in Facebook scam

Hacked page leads to major loss 06 Sep 2009

Security experts uncover first ever SMS virus

F-Secure warns of possible mobile spam epidemic 09 Apr 2009

related whitepapers

today's top stories

Police hunt for moles with security software

Lancashire Constabulary to monitor data input of 7,000 staff in bid to prevent intelligence leaks 09 Feb 2010

PaperlinX outsources IT and comms to Bull and BT

Paper company spends €22m on five-year deal for desktop management, helpdesk and datacentre services 05 Feb 2010

Social tools take KM to a new level

Technology expert David Tebbutt explains how – and why – organisations should integrate social networking tools into their knowledge management strategy 02 Feb 2010

EDS court defeat puts vendors on their guard

BSkyB’s victory in a long-running court case against EDS has serious implications for the IT industry 02 Feb 2010

Law firm monitors web traffic violations

Bucks declining global security appliance sales with unified threat management (UTM) platform deployment 01 Feb 2010

Advertisement

Security: The New Face of Intrusion Prevention
An outline of traditional IPS functionality, modern developments and how IPS can be deployed easily.

UK businesses’ attitudes to Cloud Computing revealed

Features results from a survey of over 200 Computing readers.

Advertisement

Keep up to date with the latest products, services and technologies from the world's leading IT companies; ITHound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

Internet Explorer 6

Internet Explorer 6

Following recent concerns about the security of Internet Explorer 6 are you planning to phase it out?

View poll results

Latest audio and video articles

Tony McAlisterVideo

Video Q&A: Tony McAlister, CTO, Betfair - Part one

On changing the skills development strategy at the online gambling firm - part one of a two-part video interview 05 Nov 2009

Video

Nokia shows upcoming handset technologies

Mobile phone features of tomorrow take the stage 21 Oct 2009

Latest in-depth articles

Analysis

Police hunt for moles with security software

Lancashire Constabulary to monitor data input of 7,000 staff in bid to prevent intelligence leaks 09 Feb 2010

Businessman with eye patch, dagger and tie round head, sitting at laptopFeatures

Are you sure you're not a pirate?

It is alarmingly easy for an IT leader to unwittingly exceed the scope of a software licence, and the chances of being caught out have never been greater, as technology lawyers Mark Weston and Paul Gershlick explain 09 Feb 2010

Primary Navigation