Evil Searching: Compromise and Recompromise of Internet Hosts for Phishing
نویسندگان
چکیده
Attackers compromise web servers in order to host fraudulent content, such as malware and phishing websites. While the techniques used to compromise websites are widely discussed and categorized, analysis of the methods used by attackers to identify targets has remained anecdotal. In this paper, we study the use of search engines to locate potentially vulnerable hosts. We present empirical evidence from the logs of websites used for phishing to demonstrate attackers’ widespread use of search terms which seek out susceptible web servers. We establish that at least 18% of website compromises are triggered by these searches. Many websites are repeatedly compromised whenever the root cause of the vulnerability is not addressed. We find that 19% of phishing websites are recompromised within six months, and the rate of recompromise is much higher if they have been identified through web search. By contrast, other public sources of information about phishing websites are not currently raising recompromise rates; we find that phishing websites placed onto a public blacklist are recompromised no more frequently than websites only known within closed communities.
منابع مشابه
The Impact of Public Information on Phishing Attack and Defense
Attackers compromise web servers in order to host fraudulent content, such as malware and phishing websites. While the techniques used to compromise websites are widely discussed and categorized, analysis of the methods used by attackers to identify targets has remained anecdotal. In this paper, we study the use of search engines to locate potentially vulnerable hosts. We present empirical evid...
متن کاملDetecting Fake Websites Using Swarm Intelligence Mechanism in Human Learning
The internet and its various services have made users to easily communicate with each other. Internet benefits including online business and e-commerce. E-commerce has boosted online sales and online auction types. Despite their many uses and benefits, the internet and their services have various challenges, such as information theft, which challenges the use of these services. Information thef...
متن کاملWho is peeping at your passwords at Starbucks? - To catch an evil twin access point
In this paper, we consider the problem of “evil twin” attacks in wireless local area networks (WLANs). An evil twin is essentially a phishing (rogue) Wi-Fi access point (AP) that looks like a legitimate one (with the same SSID name). It is set up by an adversary, who can eavesdrop on wireless communications of users’ Internet access. Existing evil twin detection solutions are mostly for wireles...
متن کاملThe “Evil Bit” Revisited: Blocking DDoS Attacks with AS-Based Accountability
DDoS attacks expose two seemingly contradictory expectations of the Internet: end hosts should be able to access services in an open and flexible manner, yet a service should be able to prevent a group of end hosts from rendering it unavailable to others. While the majority of prior work has focused on distinguishing malicious traffic from valid traffic, we argue that networks also need to prov...
متن کاملBlind Men and the DNS (abstract)
Domain names have been used to provide a simple identification label for hosts, services, applications, and networks on the Internet [12]. They have also been long misused for types of abuse: phishing, malware distribution, spamming, and botnet command-and-control (C&C), among others. Underlying these abuses, we find profitable business models that provide the incentives for these abusers to co...
متن کامل