Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Wednesday, 11 September 2013

Google Operating System, Phishing Site?

If you use Opera to visit the site, you'll probably see this warning: "This site has been reported as fraudulent. Exchanging sensitive or confidential information with this site could put you at risk for identity theft and/or financial fraud. Opera Software strongly discourages visiting this page."


Opera uses Netcraft's phishing blacklist. You'll get a similar warning if you install Netcraft's toolbar:


Netcraft's site report page doesn't provide too many useful information. I could only find that the Google OS blog has a 5/10 risk rating, but the rating varies depending on the URL. The recent post about the Google logo has a 7/10 risk rating.


Many factors contribute to the risk rating of each site. The dominant factor for most sites is the age of the domain name in which the site appears. Domain names that have never been seen in the Netcraft Web Server Survey are given a high risk rating, since many phishing sites and relatively few legitimate sites fall into this category. Other factors which can influence the risk rating include:

* Any other known phishing sites in the same domain.
* Whether a hostname or a numeric IP address is used in the URL.
* Whether or not a port number appears in the URL.
* The hosting ISP's history with respect to phishing sites.
* The hosting country's history with respect to phishing sites.
* The top level domain's history with respect to phishing sites.
* The site's popularity with Netcraft Extension users.

So just because other Blogger blogs are used for phishing, Netcraft decided that this is a phishing site? It's hard to say. Google's official blog has a 0/10 risk rating, while a random blog like googlelatlong.blogspot.com (it's not Google's Maps blog) has a 7/10 risk rating, but there's no warning.

A site that lets you check multiple anti-phishing blacklists is the Google-owned VirusTotal. "VirusTotal is a free service that analyzes suspicious files and URLs and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware." VirusTotal reported that there are 3 services that flag the Google OS blog: Opera, Netcraft and Kaspersky. They probably have the same source.


Here's Kaspersky's "access denied" message:


Ironically, a recent blog post from Kaspersky's site informs that: "Kaspersky's product blocked 99 percent of the 187 phishing websites while producing zero false alarms among the 400 legitimate URLs, earning first place among its competitors with an Advanced + award from AV-Comparatives."

I used Netcraft's browser extension to report that the URL was flagged by mistake and received this message after a few minutes: "Thank you for your enquiry. Following a review of the URL in question, I have unblocked the URL from the toolbar. Please allow a short period of time for the changes to propagate."


{ Thanks, Josh Rich. He reported this issue. }

Wednesday, 10 July 2013

The Android Bug 8219321

There's a lot of talk about an Android security bug that affects almost all the Android devices. Jeff Forristal from Bluebox Security reported that "the vulnerability involves discrepancies in how Android applications are cryptographically verified & installed, allowing for APK code modification without breaking the cryptographic signature. Details of Android security bug 8219321 were responsibly disclosed through Bluebox Security's close relationship with Google in February 2013."

So the bug could allow someone to create a modified version of an system app and trick other people to install it. The modified version could include malicious code.

Actually, the bug is simple: APK files are ZIP archives and Android allows APK files to include files with the same name. "It's a problem in the way Android handles APKs that have duplicate file names inside," says Pau Oliva Fora, security engineer at security firm ViaForensics. "The entry which is verified for signature is the second one inside the APK, and the entry which ends up being installed is the first one inside the APK - the injected one that can contain the malicious payload and is not checked for signature at all."

The problem is that Android supported duplicate file names in APKs and the patch removed this support. The patch is extremely simple: return an error if the APK file has duplicate file names.


Apparently, Geremy Condra from Google wrote a patch in February. "Google made changes to Google Play in order to detect apps modified in this way and a patch has already been shared with device manufacturers," informs ComputerWorld. CyanogenMod included the bug fix in the latest release, faster than OEMs and even Google, which didn't update Nexus devices to address this issue.

The bug #8219321 is now a test that will show us how fast Google, OEMs and carriers can deploy security patches. For now, CyanogenMod is the place to go to get the latest features and security patches.

Thursday, 13 June 2013

Google Shows Your Recent Sign-ins

There's a new section in the Google Account settings page: recent activity. Google shows a list of recent sign-ins and other security-related actions, with information about the browser, device, IP address and approximate location.


The feature seems similar to Gmail's account activity feature, but it's not. Gmail's feature shows information about about recent activity, whether it's from a browser or an email client, and it's only limited to Gmail. Google's new recent activity feature shows "security-related actions you've taken, like signing in to your Google Account, changing your password, or adding a recovery email address or phone number. This information is for your entire Google Account, so sign-ins from any Google product (such as Blogger, Gmail, or YouTube) will be listed in this section."

There's a subtle difference: "A sign-in is only listed when you've actually typed your username and password to sign in. For example, if you've been signed in to your account for several weeks on your phone, checking your email from time to time, we'll only list the time and location of your initial sign-in." That's not the case for Gmail's account activity feature, which is not limited to the initial sign-ins.

In other related news, Google has a new security dashboard that shows information about your password, recovery options, notifications for unusual activity, 2-step verification and connected applications/sites.


{ Thanks, Florian K. and Herin. }

Wednesday, 3 April 2013

Google Blocks Gmail's Mail Fetcher

Google has always added great security features that protect user accounts: from SSL access to most services, Google Safe Browsing, Gmail's spam and phishing filters to 2-step authentication, phone number verification and Gmail's account activity monitoring.

Sometimes Google's security features are extra paranoid and block Google's own services. I tried to use the mail fetcher feature from a secondary Gmail account and Google mentioned that the authentication failed (it's been enabled before). I entered the right password and Google still couldn't authenticate. Then Google started to show warnings in my main Gmail account, at the top of Google search pages and even sent an email and an SMS message: "Someone recently tried to use an application to sign in to your Google Account. We prevented the sign-in attempt in case this was a hijacker trying to access your account."

Google sent me to this page which says: "We detected activity on your Google Account from a location you don't usually sign in from." The IP address is 209.85.192.147 (mail-pd0-f147.google.com) and it's from United States. Obviously, it's Google's own IP address.




How to fix this issue? Go to this page, click "Yes" and "Yes - Continue". From the Google confirmation message: "As a security precaution, Google may prevent an application from accessing your account if it's the first time we've seen this application sign in to your account, or if it's attempting to sign in from a new location."


Then Google sends you to this page and you need to click "Continue" and "sign in using the application you want to authorize access to your account within the next ten minutes."


Unfortunately for Google, it wasn't even the first time when Gmail's mail fetcher was enabled. Google should find a way to make Gmail's mail fetcher work without having to jump through hoops.

Wednesday, 12 December 2012

Security Notifications for Google Accounts

A Google help center page mentions a new feature that will be added to the Google Account settings page: security notifications.


"Google notifies you via email and/or text message when your password is changed, and when we detect a suspicious attempt to sign in to your account. If you receive a notification about a password change you didn't make, or an attempt to sign in to your account that wasn't you, these email and text message notifications will provide details on next steps to help you secure your account," informs Google.

This feature should be available under the "security" tab of the Account Settings page, but I don't see it. Maybe it's enabled in your accounts.

In other related news, the Account Settings page has a new interface and shows information about your account activity, a large photo from your profile, Google Drive storage data.


{ Thanks, Herin. }