<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CounterMeasures -  A Security Blog » SEO</title>
	<atom:link href="http://countermeasures.trendmicro.eu/category/seo/feed/" rel="self" type="application/rss+xml" />
	<link>http://countermeasures.trendmicro.eu</link>
	<description>Rik Ferguson blogs about current security issues.</description>
	<lastBuildDate>Wed, 28 Jul 2010 17:12:49 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Twitter.Grader.com hacked?</title>
		<link>http://countermeasures.trendmicro.eu/grader-com-hacked/</link>
		<comments>http://countermeasures.trendmicro.eu/grader-com-hacked/#comments</comments>
		<pubDate>Thu, 11 Feb 2010 20:07:29 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[SEO]]></category>
		<category><![CDATA[Site Compromise]]></category>
		<category><![CDATA[Web 2.0]]></category>
		<category><![CDATA[data leakage]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=1757</guid>
		<description><![CDATA[&#160;Â  UPDATE: You will see in the comments on this post an update from HubSpot with a link to their blog explaining the incident, I know a lot of folks don&#8217;t read the comments, so here it is in full. &#8220;We are very sorry for the mistake. It is completely our fault. As your article [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_1758" class="wp-caption alignleft" style="width: 650px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/grader.gif"><img class="size-full wp-image-1758" title="Twitter Grader home page" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/grader.gif" alt="Twitter Grader home page" width="510" height="165" /></a><p class="wp-caption-text">Twitter Grader home page</p></div>
<p>&nbsp;Â <br />
<strong>UPDATE</strong>: You will see in the comments on this post an update from HubSpot with a link to their blog explaining the incident, I know a lot of folks don&#8217;t read the comments, so here it is in full.</p>
<blockquote><p>&#8220;We are very sorry for the mistake. It is completely our fault. As your article mentions, we have contained the situation and stopped the malicious tweets.</p>
<p>We do want to make clear that by design, the HubSpot software applications are on different servers and systems from our free Grader.com tools. This attack did NOT affect the HubSpot software used by our 2,100 customers. Again, there is no impact on our paid product or paying customers.</p>
<p>We have posted an article on our company blog with more information:</p>
<p>http://www.hubspot.com/blog/bid/5594/One-Lesson-From-The-Twitter-Grader-Screw-up-OAuth-Rocks</p>
<p>- Mike Volpe<br />
HubSpot (makers of Twitter Grader)&#8221;</p></blockquote>
<p>&#8230;and that, ladies and gents, is an object lesson in how to deal with an event like this. Much respect to HubSpot.</p>
<p>&nbsp;<br />
__________________________________________________________________________________________</p>
<p>In what looks like another compromise related to Twitter services, a large number of Twitter users who have granted access to their accounts to the web service Twitter.Grader.com have all begun tweeting a bizarre and unauthorised message.<br />
&nbsp;</p>
<div class="mceTemp">
<dl id="attachment_1759" class="wp-caption alignleft" style="width: 557px;">
<dt class="wp-caption-dt"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/posts.gif"><img class="size-full wp-image-1759" title="Example of affected accounts" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/posts.gif" alt="Example of affected accounts" width="510" height="354" /></a></dt>
<dd class="wp-caption-dd">Example of affected accounts (search by Twitscoop)</dd>
</dl>
<p>&nbsp;<br />
Fortunately the link that has been endlessly tweeted by grader users does not appear to host any malicious content. It points to a blog with an embedded YouTube video of Biz Stone back in 2006 promoting Twitter.</p></div>
<p>&nbsp;</p>
<div class="mceTemp">The domain name of the destination site however might give us a clue to the motivation behind the attack. Seonix presumably refers to Search Engine Optimisation and perhaps that is the real purpose of this attack. Forcing large numbers of Twitter users to tweet a link to the site may well be an effective method of pushing it up the search engine rankings. The domain seonix.org was created on the 11th February 2010 and the details of the owner have been anonymised.</div>
<p>&nbsp;</p>
<div class="mceTemp">Embarassingly the victims of this attack also include Dharmesh Shah, the founder of Grader</div>
<div class="mceTemp">
&nbsp;</p>
<div class="mceTemp">
<dl id="attachment_1760" class="wp-caption alignleft" style="width: 581px;">
<dt class="wp-caption-dt"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/dharmesh.gif"><img class="size-full wp-image-1760" title="Dharmesh Shah on Twitter" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/dharmesh.gif" alt="Dharmesh Shah on Twitter" width="510" height="359" /></a></dt>
<dd class="wp-caption-dd">Dharmesh Shah on Twitter</dd>
</dl>
<p>&nbsp;<br />
<strong>UPDATE</strong>: Hubspot, the parent company have <a href="http://twitter.com/HubSpot/status/8974998969">tweeted</a> that they are aware of the hack and working on a solution. In the meantime, if you are a Grader user, you may want to consider temporarily revoking Access to Grader in your Twitter profile <a href="http://twitter.com/account/connections">via Settings -> Connections</a>.</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/grader-com-hacked/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Facebook &#8220;Un Named App&#8221; scare leads to malware</title>
		<link>http://countermeasures.trendmicro.eu/facebook-un-named-app-scare-leads-to-malware/</link>
		<comments>http://countermeasures.trendmicro.eu/facebook-un-named-app-scare-leads-to-malware/#comments</comments>
		<pubDate>Wed, 27 Jan 2010 14:12:18 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[SEO]]></category>
		<category><![CDATA[Web 2.0]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=1725</guid>
		<description><![CDATA[A few minutes ago I noticed that a friend of mine had posted the following status to her Facebook profile: &#160; Facebook status &#160; Of course this got my bat senses tingling and I smelled a panic-inducing spiral of insanity brewing, so I thought I&#8217;d have a bit of a look around. &#160; Nothing to [...]]]></description>
			<content:encoded><![CDATA[<div class="mceTemp">
<p>A few minutes ago I noticed that a friend of mine had posted the following status to her Facebook profile:<br />
&nbsp;</p>
<dl id="attachment_1726" class="wp-caption alignleft" style="width: 510px;">
<dt class="wp-caption-dt"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/01/FB-status.png"><img class="size-full wp-image-1726" title="Facebook status" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/01/FB-status.png" alt="Facebook status" width="510" height="198" /></a></dt>
<dd class="wp-caption-dd">Facebook status</dd>
</dl>
</div>
<div>
&nbsp;<br />
Of course this got my bat senses tingling and I smelled a panic-inducing spiral of insanity brewing, so I thought I&#8217;d have a bit of a look around.</div>
<p>&nbsp;</p>
<div>Nothing to worry about here as far as your Facebook is concerned, this does not appear to be a genuine malicious app. In fact a <a title="What is the &quot;Unnamed App&quot; on Facebook?" href="http://answers.yahoo.com/question/index?qid=20100126190431AAJkPoW" target="_blank">thread</a>Â on Yahoo answers appears to demonstrate in a reproducible fashion that &#8220;Un named App&#8221; is nothing more than your &#8220;Boxes&#8221; tab on your Facebook profile page.</div>
<p>&nbsp;</p>
<div>Beware though, there is still real risk attached to this Chinese whisper. Criminals have picked up on the concern among Facebook users (or possibly they were responsible for starting the rumour?) and they have already started to poison Google search results.</div>
<p>&nbsp;</p>
<div>
<div id="attachment_1727" class="wp-caption alignleft" style="width: 611px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/01/Google-search-result.png"><img class="size-full wp-image-1727" title="Google search result" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/01/Google-search-result.png" alt="Google search result" width="510" height="258" /></a><p class="wp-caption-text">Google search result</p></div>
</div>
<div>
&nbsp;<br />
I queried Google for &#8220;facebook unnamed app&#8221; and the third result on the first page pointed to a malicious website set up for the purposes of distributing fake anti-virus software, this time called &#8220;Security Tool&#8221;. If you are unwary enough to click the link you will be presented with a dialogue box informing you that you have a huge number of infected files on your machine and prompting you to use Security Tool to clean them up. The software of course is no real security solution and is designed to fool the victim into parting with hard-earned cash.<br />
&nbsp;<br />
<div id="attachment_1728" class="wp-caption alignleft" style="width: 532px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/01/Security-Tool1.png"><img class="size-full wp-image-1728" title="Security Tool Rogue AV" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/01/Security-Tool1.png" alt="Security Tool Rogue AV" width="510" height="396" /></a><p class="wp-caption-text">Security Tool Rogue AV</p></div><br />
&nbsp;<br />
Â Always search with caution, especially when searching for terms of high current popularity. Using search trends and conversation trends to target malicious software is now a firmly established criminal modus operandi.<br />
&nbsp;<br />
If you are worried aboutÂ computer security and not sure where to click, you can always <a href="mailto:rik_ferguson@trendmicro.com?subject=Mail from Countermeasures">contact me directly</a>. If you feel you may have been affected by this or any other scam, then I would advise you to go and scan your PC with a real security solution, our own free <a title="Trend Micro HouseCall" href="http://housecall.trendmicro.com/uk/" target="_blank">HouseCall</a> service.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/facebook-un-named-app-scare-leads-to-malware/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Malware on Demand</title>
		<link>http://countermeasures.trendmicro.eu/malware-on-demand/</link>
		<comments>http://countermeasures.trendmicro.eu/malware-on-demand/#comments</comments>
		<pubDate>Thu, 23 Apr 2009 12:44:16 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[SEO]]></category>
		<category><![CDATA[Underground Economy]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[malicious code]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=432</guid>
		<description><![CDATA[I came across a very well designed and presented SEO pay-per-click &#8220;affiliate program&#8221; a couple of days ago. Â  This scheme offers the affiliate a customised &#8220;file&#8221; (detected by Trend Micro as TROJ_DROPPER.JLA) which you can then distribute to your victims using whichever means are the most convenient for you. Â  Maybe you want to [...]]]></description>
			<content:encoded><![CDATA[<p>I came across a very well designed and presented SEO pay-per-click &#8220;affiliate program&#8221; a couple of days ago.</p>
<p><img class="alignleft size-full wp-image-434" title="seoclicksfront1" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/04/seoclicksfront1.png" alt="seoclicksfront1" width="492" height="300" /></p>
<p>Â </p>
<p>This scheme offers the affiliate a customised &#8220;file&#8221; (detected by Trend Micro as <a href="http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FDROPPER%2EJLA&amp;VSect=P" target="_blank">TROJ_DROPPER.JLA</a>) which you can then distribute to your victims using whichever means are the most convenient for you.</p>
<p><img class="alignleft size-full wp-image-435" title="seoclicksget" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/04/seoclicksget.png" alt="seoclicksget" width="477" height="252" /></p>
<p>Â </p>
<p>Maybe you want to push it out through your own botnet, spamvertise it, or perhaps rent some time on someone else&#8217;s botnet to get your file out there. Once installed, the malicious file will silently redirect browser traffic driving users to sites of dubious pedigree. You&#8217;ll need to be selective though, the scheme only pays out for victims in Australia, Canada, Germany, Great Britain and the US.</p>
<p><img class="alignleft size-full wp-image-436" title="seoclicksstats" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/04/seoclicksstats.png" alt="seoclicksstats" width="496" height="342" /></p>
<p>Â </p>
<p>With its fully hosted management and tracking interface, automated malware generation, and the free sign-up process thisÂ scheme once again demonstrates how low-skill, low-effort and low-cost entry into this shady underworld has become.</p>
]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/malware-on-demand/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Poisoned Downad/Conficker Removal Searches&#8230;</title>
		<link>http://countermeasures.trendmicro.eu/poisoned-downadconficker-removal-searches/</link>
		<comments>http://countermeasures.trendmicro.eu/poisoned-downadconficker-removal-searches/#comments</comments>
		<pubDate>Mon, 30 Mar 2009 21:12:04 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[SEO]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[worm_downad]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=373</guid>
		<description><![CDATA[Reminder: For aÂ FREE tool to remove Conficker (and every other malware in the current pattern file) use Trend Micro&#8217;s SysClean available here. As soon asÂ the good news breaks that it is possible to use tools such as the network scanning tool nmap to search for machines infected by Downad/Conficker, then the malicious SEO work starts. [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Reminder</strong>: For aÂ <strong><span style="color: #800000;">FREE </span></strong>tool to remove Conficker (and every other malware in the current pattern file) use Trend Micro&#8217;s SysClean available <a href="http://www.trendmicro.com/download/dcs.asp" target="_blank">here</a>.</p>
<p>As soon asÂ the <a href="http://www.theregister.co.uk/2009/03/30/conficker_signature_discovery/" target="_blank">good news breaks</a> that it is possible to use tools such as the network scanning tool <a href="http://nmap.org/" target="_blank">nmap </a>to search for machines infected by Downad/Conficker, then the malicious SEO work starts.</p>
<p><img class="alignleft size-full wp-image-375" title="nmapconresult1" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/03/nmapconresult1.png" alt="nmapconresult1" width="560" height="323" /></p>
<p>If you need malware removal tools type the URL of your vendor of choice directly into the browser bar and use links on their website. Do not rely on Google search results at this time, as they may have been &#8220;optimised&#8221;.</p>
<p>Careful what you click on, these Google results are loaded!</p>
]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/poisoned-downadconficker-removal-searches/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
	</channel>
</rss>
