Solid Performance for Firefox Download Site

The download site for Firefox is performing well following the release of a widely-anticipated update of the open source web browser. Firefox version 1.5, which was released Tuesday night, features "dozens of enhancements," according to the Mozilla Corporation, including improvements in popup blocking, RSS integration and updating.

Firefox download site performanceA distributed network of mirror sites in more than 30 countries appears to be handling current download demand with few difficulties. The download.mozilla.org site, which redirects traffic to the mirrors, has had good response time today and fared well during a Slashdotting Tuesday night. That's a contrast with last year, when the mozilla.org web site was slowed by heavy demand after Firefox 1.0 was released. The browser has since been downloaded more than 112 million times. While that number reflects multiple downloads by some enthusiasts, the growth of Firefox places a premium on efficient handling of new releases.

A dynamically updating chart of the site performance for download.mozilla.org is available here.

Microsoft Launches Free Email Services for Domain Owners

Microsoft has launched the beta version of its Windows Live Custom Domains service, which offers e-mail and instant messaging service for existing domains. The free service offers up to 20 e-mail accounts per domain, with each mailbox featuring scanning for junk mail and viruses, as well as 250 megabytes of storage space - adding up to a storage limit of 5 gigabytes of e-mail for each domain.

With Windows Live Custom Domains, Microsoft can offer e-mail services to business users who want a free solution but are reluctant to use its existing Hotmail service. Tying the new offering to an existing domain makes it easier to address any abuse of the service for spamming, which historically has been a major issue for free e-mail services.

Continue reading

Hacked Server Exposes Brokerage Customers’ Data

Online brokerage Scottrade says a server compromise at a service provider may have exposed the financial details of its customers, including banking account information and Social Security numbers. The security breach follows warnings from U.S. securities regulators that hackers and phishing fraudsters have stepped up their targeting of online investors, prompting enhanced education efforts by brokerage firms and the U.S. government.

Scottrade, which has 1.4 million customers, said it was notified Oct. 25 that a hacker had compromised a server at eCheck Secure, an electronic payment service provided by The Troy Group Inc. "As a result, some of your personal information, including your name, driver's license or state ID number, date of birth, phone number, bank name, bank code, bank number, bank routing number, bank account number and Scottrade account number may have been compromised," read the message to investors.

Continue reading

Yahoo, iPowerWeb Slash Domain Prices to Below $3

Web hosting provider iPowerWeb has slashed its domain name pricing to $2.95 a year, following the lead of Yahoo, which is offering limited-time domain pricing of $2.99 a year. iPowerWeb's promotional offer undercuts the lowest prices seen among current market leaders, and is a sign that Yahoo's continuing promotions are pressuring competitors to respond, planting the seeds for further domain price cutting.

Netfirms ($4.95 a year) and 1&1 Internet ($5.99 a year) are currently offering the lowest non-promotional pricing on domain names, which are viewed as an important "gateway" purchase by small business customers who are likely to be shopping for web hosting and e-commerce services as well. Yahoo has been particularly aggressive in using domain pricing to attract new users, with "permanent" pricing of $9.98 supplemented by limited-time offers of $4.98 and now $2.99 a year.

Continue reading

Google Closes Security Holes in Google Base

Google has fixed a security hole in Google Base that would have exposed sensitive information stored by users of Google's services. The cross site scripting vulnerabilities discovered by British Computer Scientist Jim Ley would allow an attacker to steal cookies and other information from users, while providing fraudsters with the facility to publish their own forms and receive input using an apparently reassuring Google Base URL.

Google Base will spearhead the search giant's entry into classified advertising and payment processing, where it will compete with established offerings from eBay and CraigsList. If it succeeds, Google Base will likely accelerate a trend which has seen a growing percentage of advertising dollars shift to the web and away from television, magazines and especially newspapers, which rely heavily on classified ads for revenue. Strong application security is important to gain user confidence in the service, as Google Base is eventually expected to integrate a micropayment system (presumably Google Payments).

Google's move towards a single Google Account for multiple services exacerbates the problem, as the same account used by the Google Base site can also be used to access financially sensitive services such as AdWords and AdSense, and Google's GMail webmail service.

Ley, who also recently found a similar security vulnerability in Yahoo Maps, says that there is a pervasive problem with companies releasing new applications on to the Web with easy-to-find vulnerabilities still present. Too little thought is given to the consequences of such action, which in the case of an identity or data theft scenario on a very widely used service could be severe for a correspondingly large number of people.

The nature of the problems discovered by Ley provides fraudsters with the tools to create phishing sites with a good level of plausibility because the base URL would be that of a well-known brand - in this case Google or Yahoo. This is the same in principle to that scenario whereby fraudsters try to find open redirects or cross site scripting vulnerabilities on bank sites to improve the authenticity of their frauds. The importance of testing to remove application vulnerabilities is proportional to the level of trust the public places in the service and the impact of this trust being broken.

Netcraft provides a range of services for companies to eliminate these kinds of errors from their systems, including comprehensive application testing, training for developers and designers of web based applications, and an service aimed specifically at detecting and reporting Open Redirects.

Report a phishing site, gain a chance to win an Ipod

In October we received and reviewed more than 8,700 unique URLs reported to us as phishing sites; by far the busiest month to date.

To further incentivise people reporting phishing sites, each accepted report is now treated as a ticket in a monthly draw for a top of the range iPod.

The October draw was won by Alan. Alan has been one of the largest and most accurate reporters of phishing sites, with several hundred reports accepted to date.

“Every day I feel that I'm doing my small bit to make the Internet a safer place.” said Alan."It's good that there are still people on the Internet who try hard to make it better. Some of them are well known companies like Netcraft, some of us are just anonymous individuals trying to do our bit. As well as the satisfaction of a job well done, it's a lot of fun to have a shiny new toy to play with."

Including the toolbar community itself and customers of ISPs using our Phishing site feed, well over a million people are now protected from phishing by the Netcraft Toolbar.

The Netcraft Toolbar is available for both Internet Explorer and Firefox, and serves as a giant neighborhood watch scheme for the Internet, in which members who encounter a phishing fraud can act to defend the larger community of users against the attack. Once the first recipients of a phishing mail have reported the target URL, it is blocked for toolbar users who subsequently access the URL and widely disseminated attacks simply mean that the phishing attack will be reported and blocked sooner.

Reporting a Suspicious URL

When you visit a page that you believe to be a phishing site, or contains fraudulent or deceptive content, we ask that you report it so that other toolbar users will benefit from your vigilance. The more sites that are reported, the more useful the toolbar will become for everyone.

You can report a URL by clicking on "Report a Phishing Site" in the toolbar menu, accessed by clicking on the Netcraft logo:

reportphish.png

After you report a URL, Netcraft will review the report and block the page if we confirm it as part of a phishing attack.