Secure IT Foundation

Archive for October 2011

If it walks like a duck, quacks like a duck, looks like a duck, it must be a duck…

If software on computer communicated to third parties like malware, altered settings like malware, behaved like malware, it must be malware. You would think so but there is a threat to computer security that does not get classified as malware.

It gets around being classified as malware by making the user accept the software as part of an installation of other software. For example if you look at the Top 10 downloads from Download.com at the moment you will see at number three there is a program called YouTube Downloader, with nearly 800,000 downloads in the previous month.

When you install the software you get a typical install process for Windows, but with an additional option page for a Toolbar:

YouTube Downloader Toolbar Screenshot

YouTube Downloader Toolbar Screenshot

While there is an option to decline (which we strongly recommend you use!), most users do not. There is no informed consent for the user that they are about to install a potentially unwanted program, which will make changes to your computer. But if you click ‘Accept’ the toolbar takes over you browsers and your PC. In nature, this would be called a parasite, as it feeds on the others in a symbiotic relationship.

As the user has clicked ‘Accept’ to the legalese terms they have agreed to allow it control of their computer. Following the trail, brings you to a company called Spigot whose slogan is ‘Turn on the revenue’. In case you don’t realise it, they mean revenue for application developers by using your internet data, mined by the toolbar! You are the cash cow, as they make money on selling marketing information based on your surfing habits.

These terms include:

“The Spigot Toolbar Privacy Policy applies to the Spigot Toolbar only and is independent of any other application(s) you may be installing or using concurrently. Spigot Toolbar is built and maintained by Spigot, Inc. (“We”). We care about your privacy and will never collect personally identifiable information or monitor usage on an individual level.”

The information we collect is for basic reporting purposes only, and includes the following:
a) Date and time of installation
b) Date and time of un-installation
c) Originating IP address and the user’s country at time of installation/un-installation
d) Toolbar status in Internet Explorer or Firefox (i.e. if a toolbar is hidden or displayed in the browser)
e) Partner ID at time of installation
f) Toolbar version at time of installation

Information we collect during Toolbar Usage

We do not monitor the web pages you visit. When you perform a search, your search may be sent through our servers in order to ‘optimize the search result’. This will record the following anonymous usage information:
a) Date and time of search
b) Originating IP address
c) Partner / Channel ID of your Toolbar
d) Toolbar version
e) Search term

In addition, your web browser will communicate to us the same information it gives to every web server on the Internet. This could include information such as your computer hardware and software attributes, cookies for our site, and the URL of web page you are requesting.

How we use the Information we collect

Information we collect from you is used on an aggregate basis and for reporting purposes only. For example, we measure the total number of Toolbar installations per month in order to pay our partners, the total number of Toolbar searches conducted per month to measure growth patterns, the number of Toolbars used in Microsoft Internet Explorer or Mozilla Firefox per month to study browser trends, and so on. All information is collected in aggregate and never measured on an individual basis.

Information collected by Third Parties

Search results pages you visit when performing a search using the toolbar are provided by our search engine partners (i.e. Yahoo, Baidu, Yandex, eBay, Amazon). These search engines can track the following:
a) Search term that was entered into the search box
b) Originating IP address and the user’s country or OS language setting
c) Sponsored listings or other advertisements that were clicked on
d) That the search request came from the Spigot Toolbar and its associated revenue tag

The toolbar does not collect personally identifiable information or monitor your surfing behavior.

Use of Cookies

When you conduct a search using the toolbar, our content providers who supply search results (i.e. Yahoo, Baidu, Yandex, eBay, Amazon) may set or access cookies on your computer. The cookies are used for the purpose of measuring referrals from our toolbar on an aggregate basis and are not tied to your personal information. Many browsers offer users the option of declining cookies. If you do not wish to accept cookies, please modify the settings in your browser.

Toolbar Updates

The toolbar communicates with our servers from time to time to check for available software updates such as bug fixes, patches, enhanced functions and new versions. By installing the toolbar, you agree to automatically request and receive updates. If you wish to turn off automatic updates, you can do so from the “Options” menu in the toolbar.

Toolbar Uninstall

You can easily uninstall the toolbar in the traditional Add/Remove programs section in Windows, or from the toolbar by selecting

Options > Help > Uninstall.

Toolbar Deactivation

You can easily hide or deactivate the Toolbar in Internet Explorer or FireFox by selecting View > Toolbars, and then unselecting the checkbox for the toolbar.

Changes to this Privacy Policy

We may update this privacy policy from time to time. We will notify you about significant changes in the way we treat personal information by placing a prominent notice on our site. “

The bold type highlights the problem. It claims it only monitors your search terms without identifying you but your IP address is like a fingerprint. It always leaves a trail on every computer you communicate with and all those in between. The legal issue is that on its own an IP address is not classed as personal data, for example compare the UK stance with the US approach. In reality, every email you send, website you visit or post on a public forum can log your IP address. Combined with your email address or forum username and you can have personally identifiable data.

In addition some toolbars ‘optimise’ the search results to preferred companies whose activities may not be strictly legal or could be classified by some people as scam merchants.

Until these legal issues are resolved, Anti Virus and Computer Security companies cannot classify Toolbars as malware without risk of litigation from the companies involved, says a lot about the money involved here.

So there is a stalemate situation where you know its bad software but your security defences let it through as if it was ok. For now, all we can advise is when you install new software, read the install pages and look out for Toolbars and changes to your search engine and browser settings. If you see one, untick all options and decline it! Weasel words to look for include ‘Community‘, ‘Conduit‘, ‘Spigot‘ and ‘Mybrowserbar‘ amongst many… Clues to look for are those companies who don’t tell you where they are and have no publicly checkable address showing.

Say No to Toolbars and rid the Internet of another parasite by cutting off their revenue stream, namely your information.

SecurityBrad

One of the most common questions asked, is how did I get a virus on my Windows computer? Simple answer – human error.

To get a virus to infect your computer you had to do / not to do one or more of the following scenarios:

  1. Use Windows with no firewall and never update Windows (Windows XP Service Pack 2 or older, ME, 98, 95 users – that means you). The virus is sent by bad people to every computer on the Internet. Your lack of a firewall allows the bad code to enter your computer and without any other security the code will run. The computer is then in the control of the bad guys.
  2. Use Windows with a firewall, update Windows occasionally, but have no Anti Virus software. The firewall stops the bad guys code but you receive an email or instant message with an attached file, from person known or unknown (doesn’t matter!). You open email and double click on the attachment. Bad guys code runs, no Anti Virus which may stop the code, bad guys have control of your computer.
  3. Use Windows with a firewall, update Windows occasionally, use up to date Anti Virus software, but also use Internet Explorer to browse the Internet. You visit a web site. The trusted web site receives adverts from a third party but bad guys manage to get their bad code sent as an advert to all web site visitors of the trusted web site, including yours. Firewall does not help as you want your computer to communicate with the Internet. The bad guys code is new so not stopped by your Anti Virus software. Your Windows is not fully up to date and the bad guys use a known problem with Windows to get their code to run. The bad guys have control of your computer.
  4. Use Windows with firewall, up to date Anti Virus, Windows is fully updated, and you use Firefox. The bad guys publish a new message on FaceTubeHive which links to their bad website, under excuse of a funny / rudeĀ / surprising / adult / flash video (delete as appropriate). You click on link to see the mentioned funny / rudeĀ / surprising / adult / flash video (delete as appropriate). As you have never updated your Adobe Flash Player, the bad guys’ code uses a known problem with the software and the bad guys have control of your computer.
  5. Use Windows with firewall, up to date Anti Virus, updated Windows, updated Office, updated all installed applications, use Firefox instead of Internet Explorer with Adblock Plus and NoScript plugins. However you wanted to speed up your old computer / remove viruses from your computer / remove spyware from your computer (delete as appropriate) and clicked on a link to software that claimed to do just that. Guess what, the software is a fake and the bad guys wrote it. It is new code so not detected by Anti Virus software, and now the bad guys have control of your computer.
  6. You use Windows with firewall, up to date Anti Virus, updated Windows, updated Office, updated all installed applications, use Firefox instead of Internet Explorer with Adblock Plus and NoScript plugins, hardened to equivalent of Secure IT Foundation Standard Level 4 (highest!). Your kids use the computer and want to play a new game, they click randomly on links in Google / use eMule / use Bittorrent / use Limewire (delete as appropriate) and download bad guys’ code. They double click on the file and it goes to run. The kids are prompted to enter the administrators password which they do not know. They moan and whine, so you give in and enter your password for them. The bad guys’ code runs and they now have control of your computer.

It should be:

You use Windows with firewall, up to date Anti Virus, updated Windows, updated Office, updated all installed applications, use Firefox instead of Internet Explorer with Adblock Plus and NoScript plugins, hardened to equivalent of Secure IT Foundation Standard Level 4 (highest!). Your kids use the computer and want to play a new game, they click randomly on links in Google and download bad guys’ code. They double click on the file and it goes to run. The kids are prompted to enter the administrators password which they do not know.

  • They moan and whine so you contact your IT Security professional and ask is this file safe to run. They check and say yes or no. You listen and kids may or may not have a new game to play. If not, you explained it was a computer virus and not a real game. You even told them the example of a Xmas present with a loaded mouse trap inside to explain that all that looks shiny may not be what it looks like. If you must demonstrate use your own fingers!
  • You have some IT knowledge, upload the suspicious file to http://www.virustotal.com, and it comes back clean. You test it in a virtual computer using VMware or similar and find no problems or suspicious firewall traffic. Nothing happens, kids get new game the next day.

Anything less than full security all the time, is all it takes to give your computer to the bad guys.

Even with the highest level of security there are no guarantees and occasionally the bad guys get lucky and write code that goes through all defences. Only up to date backups will save you then, assuming you do make backups.

Prepare for the worst and you should be ok. Hope for the best and it won’t be ok. Security can be so simple.

SB



  • None
  • Coldwind: Couldn't agree more. I downloaded a piece of software just now, disabled the 'toolbar' 'offer' (which fortunately for me has become a reflex); but co
  • ModemJunki: I only discovered this today - I had updated the firmware to the latest out of habit, and I could STILL access my TrendNet cams on the local network w
  • PrentOS – a Simple Secure Computer « Secure IT Foundation: [...] September 2010 we said it was time for a brand new start to computing, well it is starting to take shape… [...]

Categories