Cross-site scripting vulnerability may affect Earthlink, other ISPs

By Michael Hatamoto | Published April 23, 2008, 3:21 PM

Security research firm IOActive notes that several ISPs, including Earthlink, are using advertising servers to collect revenue on misspelled URLs, but alleges that in so doing, they may have mistakenly exposed users to cross-site scripting.

Dan Kaminsky, the group's director of penetration testing, reported that a bug on Earthlink servers may have allowed hackers to launch phishing attacks through the third-party Barefruit service used by several ISPs. Barefruit is a service whose stated purpose is to help ISPs catch DNS errors and redirect users appropriately. However, ISPs took advantage of that redirection by building error-catching pages that included paid advertisements. Earthlink was notoriously caught using Barefruit for this purpose in 2006.

Kaminsky, describing the provider-in-the middle (PiTMA) attacks during the Toorcon security conference in Seattle, Washington (PowerPoint slides available here), was able to exploit the bug and insert his own JavaScript code that allowed him to steal authentication cookies, create fake subdomains, and log into other users' accounts using stolen passwords. Also during his presentation, Kaminsky was able to easily add the YouTube Rick Astley music video to Facebook, PayPal, Fox News and Toorcon.

Earthlink and Barefruit announced a patch to the bug found by Kaminsky, though they chose not to discuss other security issues related to Earthlink's method of covert advertising. Earthlink said it will continue to use Barefruit in the future, but warned it will closely watch the system moving forward. It is possible there are similar vulnerabilities that put Internet users at risk when heading to mistyped URLs, even though ISPs are now aware of the problem.

Comments

View comments by with a score of at least

I've been with Earthlink for many years (I recall buying a PC magazine with two Earthlink floppy discs bundled for Windows 3.1...how long ago? 1994?), and this troubling Barefruit redirecting issue, also putting ads on the webmail of paying Earthlink members, has got me looking elsewhere. They used to be a great ISP and the best dialup available by far back in the day, but they've gotten worse and worse over the years. Cheesy and slow, and crappy software. Just talk to old Mindspring fans. Now that was a great ISP, but Earthlink killed it. Earthlink used to have great service and be a cool, friendly company. Not anymore.

Score: 0

|

Mark Russinovich on MinWin, the new core of Windows

The next version of Windows three years hence will likely build onto a significant architectural change implemented in Windows 7 and Server 2008 R2.

Security firm: Windows patches not responsible for 'Black Screen of Death'

On second thought, maybe that access control list thingie with the lockdown something-or-rather didn't trigger an alleged, perhaps non-existent, pandemic.

My Windows 7 confession (and why you should confess, too)

I've held back the real reason for sticking with Windows 7, even as, gulp, iLife calls me to go back to the Mac.

Apple settles with Psystar except for 'circumvention devices'

The fracas with the Florida clone computer maker might have ended today had Apple not have muddled the issue over a cheap piece of Psystar software.

Google begrudgingly adjusts news crawling for paid publishers

If publishers want to make readers pay for news content, and thereby drive down its popularity and Google ranking, the company says, they can just go right on ahead.

Fee or free? Murdoch, Huffington square off over the cost of Internet news

Participants in an FTC workshop yesterday witnessed the two extremes of the Web news publishing debate, still centered on the issue of long-term profitability.

Microsoft denies latest 'Black Screen of Death' claims

After an anti-malware producer announced a fix to what it says is a swarm of recent KSoD problems, evidence of the swarm itself has yet to turn up.

Latest Firefox 3.6 beta fixes 133 bugs, promises faster page load times

A once-sluggish beta testing process has kicked into overdrive, with astonishing success at finding serious bugs. Will Mozilla be able to fix all the others in time?

Confirmed: Office 2010 to ship in June

Two weeks after Microsoft had been expected to draw a clearer roadmap for its principal applications suite, it's finally ready to commit to the end of H1.

New EU antitrust commissioner will oversee Microsoft, Oracle+Sun, Intel issues

As one of Europe's most prominent politicians shifts positions in January, her replacement remains a question mark over technology's biggest issues.

Without its own 'iTablet' yet, is Apple missing the boat?

Steve Jobs is on record as dissing "single-purpose" devices like e-readers. But given their recent popularity, was that a mistake?