Brazilian government providing warm waters for shoals of phish

Security holes in Brazilian government websites are still rife, with no fewer than eight different gov.br sites being compromised within the past week to host phishing attacks and hacking scripts. The situation does not seem to have improved much since two years ago, when we noticed a similar spate of phishing sites and malware hosted on gov.br domains, with evidence of some sites suffering repeated security compromises.

In one of this week's attacks, a gov.br domain was compromised to such an extent that the fraudsters were able to set up their own custom hostname, which was also configured to use HTTPS. The website, at account-verification-redirect-center.[redacted].gov.br, was then used to host a PayPal phishing site, which is still present at the time of writing.

Despite its rather dubious hostname, Let's Encrypt automatically issued an SSL certificate to account-verification-redirect-center.[redacted].gov.br earlier this week. Such foreseeable misuse evidently still does not prevent certificates being issued to phishing sites; but worse still, the fraudulent certificate has not yet been revoked.

The PayPal phishing site makes use of a ready-made phishing kit provided by SHADOW Z118. It includes several comprehensive "antibots" PHP scripts to avoid detection by search engines and enforcement agencies.

The PayPal phishing site makes use of a ready-made phishing kit provided by SHADOW Z118. It includes several comprehensive "antibots" PHP scripts to avoid detection by search engines and enforcement agencies.

To make matters worse, Netcraft found PHP shells on a few of the recently compromised gov.br sites. These backdoors provide fraudsters with almost complete access to the compromised web servers and make it easy for malware and phishing content to be uploaded at any time.

If the PHP shells are not removed, additional phishing sites are likely to appear on the affected sites, or they could even become infested with other PHP shells that will make the clean-up job much harder: If just one shell is overlooked, it can be used to replace all phishing content, malware and backdoors that the web server administrators had already deleted.

PayPal is still the most commonly targeted organisation in the latest attacks hosted by the Brazilian government, but other targets include Microsoft, Naver, Dropbox and the online dating site Match.com.

This OneDrive phishing site can steal Google, Outlook, AOL, Yahoo, Office 365, and other email credentials. The next form will steal the victim's phone number and backup email address.

This OneDrive phishing site can steal Google, Outlook, AOL, Yahoo, Office 365, and other email credentials. A second form steals the victim's phone number and backup email address.

Some of the phishing sites impersonate Microsoft's OneDrive service, using it as a convenient excuse to target Google, Outlook, AOL, Yahoo and other types of accounts from just a single attack. This particular attack could be rather harmful to businesses, as it gives victims the opportunity to log in with an Organizational Google Apps Account, which could result in the fraudster gaining access to sensitive company secrets.

Ironically, after the victim has been phished, he will be redirected to a PDF file on Google Drive entitled "The Business Owner's Guide to Wealth Management".

Ironically, after the victim has been phished, he will be redirected to a PDF file on Google Drive entitled "The Business Owner's Guide to Wealth Management".

All of the aforementioned phishing attacks were added to Netcraft's Phishing Site Feed, which is used by major web browsers and many leading anti-virus, content-filtering and web hosting companies.

Most Reliable Hosting Company Sites in December 2017

Rank Performance Graph OS Outage
hh:mm:ss
Failed
Req%
DNS Connect First
byte
Total
1 One.com Linux 0:00:00 0.000 0.165 0.037 0.110 0.110
2 Swishmail FreeBSD 0:00:00 0.000 0.121 0.055 0.110 0.156
3 Bigstep Linux 0:00:00 0.000 0.135 0.071 0.147 0.147
4 Multacom Linux 0:00:00 0.000 0.156 0.090 0.180 0.316
5 www.viawest.com Linux 0:00:00 0.005 0.249 0.008 0.189 0.189
6 New York Internet FreeBSD 0:00:00 0.005 0.278 0.022 0.047 0.047
7 ServerStack Linux 0:00:00 0.005 0.105 0.063 0.125 0.125
8 Pair Networks FreeBSD 0:00:00 0.005 0.225 0.066 0.134 0.134
9 Hyve Managed Hosting Linux 0:00:00 0.005 0.076 0.067 0.140 0.140
10 www.dinahosting.com Linux 0:00:00 0.005 0.186 0.090 0.181 0.181

See full table

One.com had the most reliable hosting company website in December 2017, successfully responding to all requests made by Netcraft. This is their third time claiming the top spot in 2017, with a total of nine appearances in the top ten in 2017. Founded in 2002, One.com has since established a global presence with offices in eleven countries around the world and services offered in fourteen languages.

Swishmail also responded to all of Netcraft's requests, but came in second due to a slightly slower average connect time. Swishmail made six appearances in the top ten in 2017, including a first place ranking in August. Swishmail offers business email solutions in a variety of plans, all of which come with a 30 day unconditional guarantee.

Hyve Managed Hosting had the most appearances in the top ten in 2017. They placed every month except January, and are currently on an impressive eleven-month streak. Hyve's site has had a 100% uptime record since Netcraft started monitoring it in 2016.

Linux is the most popular choice of operating system this month with seven of the top-ten hosting companies using it. FreeBSD is second most popular with three appearances.

Netcraft measures and makes available the response times of around thirty leading hosting providers' sites. The performance measurements are made at fifteen minute intervals from separate points around the internet, and averages are calculated over the immediately preceding 24 hour period.

From a customer's point of view, the percentage of failed requests is more pertinent than outages on hosting companies' own sites, as this gives a pointer to reliability of routing, and this is why we choose to rank our table by fewest failed requests, rather than shortest periods of outage. In the event the number of failed requests are equal then sites are ranked by average connection times.

Information on the measurement process and current measurements is available.

December 2017 Web Server Survey

In the December 2017 survey we received responses from 1,734,290,608 sites across 212,870,632 unique domain names and 7,014,428 web-facing computers. This reflects a gain of 5.34 million domains and 121,000 computers.

Web Server Developers - Market Share of Domains

The number of hostnames in use on the web has been a headline metric since the inception of the Web Server Survey, but it has been subjected to quite large fluctuations in recent years. Netcraft has therefore introduced the number of unique domains as an additional metric that provides a more stable view of the web.

The domains metric is not influenced by wildcarded domains or other large numbers of sites that can be hosted under a single domain name with minimal effort; but unlike the active sites metric, the domains metric still takes account of sites that are still under construction, or running hosting company or domain registrar holding pages.

Web server market share for domains

The noticeable spike in Apache-powered domains in May 2013 was caused by the largest hosting company of the time, GoDaddy, switching a large number of its domains from Microsoft IIS to Apache Traffic Server (ATS) . GoDaddy switched back to using IIS 7.5 a few months later.

Today, Apache still has the largest market share by number of domains, with 81.4 million giving it a market share of 38.2%. It also saw the largest gain this month, increasing its total by 1.53 million. This growth was closely followed by nginx, with a gain of 1.09 million domains increasing its total to 47.5 million. While Microsoft leads by overall number of hostnames, it lags in 3rd position when considering the number of unique domains those sites run on, with a total of 22.8 million.

Web-facing Computers

The number of web-facing computers provides an alternative view that corresponds more closely to the install base of each server vendor.

With 1.63 million web-facing computers, nginx is already 97,800 computers ahead of Microsoft since it took second place in October, but Apache remains much further ahead with a total of 2.98 million. Apache experienced the largest gain of 58,000 computers this month, closely followed by nginx with 49,000, and with Microsoft trailing with an increase of just 22,000.

Web server market share for computers

Web Server Updates

Microsoft's Internet Information Services platform has benefitted from a few improvements since the publication of last month's survey. The newest version of the IIS Administration API (2.2.0) introduced new endpoints that make it easy to monitor the health of a web server, as well as the individual websites and application pools running on it. There is also a new configuration endpoint for the files API, which allows the API's root folders to be configured – this means administrators no longer have to edit a file to configure which sections of the file system can be accessed via the API.

Version 1.0 of the IIS CORS Module, which works on IIS 7.5 or later, was also released in November. This enables support for the Cross-Origin Resource Sharing protocol, which lets webpages make use of resources that are hosted on other websites, such as web fonts and AJAX endpoints. If a website hosts these resources without setting a suitable CORS policy, the default same-origin policy enforced by all browsers would prevent other websites from accessing them.

The latest version of the open source LiteSpeed HTTP server, OpenLiteSpeed 1.4.28 (stable), was released on 8 November. This release adds multithreading APIs for LSIAPI – the API that allows it to support third-party modules. Although there are only 12,400 web-facing computers running LiteSpeed, these computers host 2.42 million domains. It is not clear how many of these computers are already running LiteSpeed 1.4.28, as this server does not expose version information in its headers.

lighttpd 1.4.48 was subsequently released on 11 November. This adds a new mod_authn_sasl module, which provides Simple Authentication and Security Layer (SASL) authentication similar to Apache's libapache2-mod-authn-sasl module. With 20,800 web-facing computers running lighttpd, it has a greater install base than LiteSpeed, but its market share of domains is noticeably smaller with a count of 565,000.

nginx 1.13.7 was released on 21 November, although this addresses several bugs rather than introducing any new features. There are, however, several new features in the latest version of its commercially supported product, NGINX Plus Release 14, which was announced on 12 December. This release features several improvements, including an updated live monitoring dashboard and JSON support in its nginScript scripting language; and there is also a technology preview of its extended clustering support, which lets NGINX Plus instances in a cluster share state information.

Total number of websites

Web server market share

DeveloperNovember 2017PercentDecember 2017PercentChange
Microsoft669,517,17736.80%535,762,81330.89%-5.91
Apache443,521,99524.38%446,418,87825.74%1.36
nginx367,687,48920.21%395,881,69022.83%2.62
Google20,333,6041.12%21,308,0691.23%0.11
Continue reading

Most Reliable Hosting Company Sites in November 2017

Rank Performance Graph OS Outage
hh:mm:ss
Failed
Req%
DNS Connect First
byte
Total
1 Webair Linux 0:00:00 0.000 0.145 0.048 0.095 0.097
2 Swishmail FreeBSD 0:00:00 0.000 0.138 0.055 0.110 0.156
3 vXtream Ltd Linux 0:00:00 0.005 0.148 0.066 0.132 0.132
4 Hyve Managed Hosting Linux 0:00:00 0.005 0.093 0.068 0.141 0.141
5 Pair Networks FreeBSD 0:00:00 0.005 0.236 0.073 0.144 0.144
6 Bigstep Linux 0:00:00 0.005 0.142 0.075 0.151 0.151
7 Netcetera Linux 0:00:00 0.005 0.096 0.089 0.180 0.180
8 CWCS Linux 0:00:00 0.005 0.217 0.150 0.231 0.231
9 New York Internet FreeBSD 0:00:00 0.010 0.289 0.024 0.048 0.049
10 One.com Linux 0:00:00 0.010 0.187 0.037 0.110 0.110

See full table

Both Webair and Swishmail responded to all of our requests in November 2017, but the faster average connect time for Webair means it takes the top spot. Webair is a US-based provider of fully managed hosting solutions and has appeared in the top ten a total of seven times in 2017, also taking the top spot in May. Swishmail, a provider of email and web hosting solutions using FreeBSD, has appeared in the top ten five times in 2017.

The six websites ranking third to eighth each failed to respond to only a single request in November. vXtream and Hyve (in third and fourth places) have both made their tenth appearances in the top ten in 2017 - vXtream was absent only in March, while Hyve narrowly missed out by ranking 11th in January. London based vXtream recently acquired Qube Managed Services contracts and infrastructure including presence in datacentres in London, New York and Zurich. Hyve places fourth with an average connect time of 68ms, 2ms slower than vXtream, it offers fully managed cloud hosting from datacentres in the UK, US and China.

Pair Networks owns its own datacentre in Pittsburgh and also offers space in the datacentre of a partner in Denver, it is one of the three websites in the top ten to be run on FreeBSD.

Linux is once again the most prevalent operating system in use for the top ten websites, with seven of the ten websites using it. FreeBSD is the operating system of choice for the remaining three.

Netcraft measures and makes available the response times of around thirty leading hosting providers' sites. The performance measurements are made at fifteen minute intervals from separate points around the internet, and averages are calculated over the immediately preceding 24 hour period.

From a customer's point of view, the percentage of failed requests is more pertinent than outages on hosting companies' own sites, as this gives a pointer to reliability of routing, and this is why we choose to rank our table by fewest failed requests, rather than shortest periods of outage. In the event the number of failed requests are equal then sites are ranked by average connection times.

Information on the measurement process and current measurements is available.

LinkedIn certificate blunder leaves users LockedOut!

Many LinkedIn users were unable to access the professional networking website today after its administrators failed to renew a TLS certificate before it expired.

Image10

The certificate in question was used by various country-specific LinkedIn websites such as https://uk.linkedin.com and https://de.linkedin.com. It expired at midday today, immediately preventing users from accessing the site via these hostnames.

The expired certificate was issued to us.linkedin.com, but was also valid for – and used by – dozens of other country-specific LinkedIn hostnames. The main site at www.linkedin.com was not affected.

The expired certificate was issued to us.linkedin.com, but was also valid for – and used by – dozens of other country-specific LinkedIn hostnames. The main site at www.linkedin.com was not affected.

The sites were still inaccessible a few hours after the problem manifested itself.

The sites were still inaccessible a few hours after the problem manifested itself.

Ironically, LinkedIn's better-than-average security made the expired certificate even more problematic. Most browsers will allow users to ignore certificate validation warnings — however unwise that may be — but the warnings cannot be ignored on these LinkedIn sites.

LinkedIn is in a minority of sites that make use of a security feature called HTTP Strict Transport Security. This feature protects HTTPS sites against trivial man-in-the-middle attacks, but unfortunately in this case, the additional security made the site completely unreachable for regular users.

Good security requires great care: Strict Transport Security is a good idea, but when a certificate expires, users cannot visit the site because browsers will not allow the warnings to be ignored.

Good security requires great care: Strict Transport Security is a good idea, but when a certificate expires, users cannot visit the site because browsers will not allow the warnings to be ignored when an active HSTS policy is in place.

Many modern browsers, such as Firefox and Chrome, simply do not allow users to add an exception when a site has an HSTS policy in place. LinkedIn's HSTS policy has a validity period of 30 days, which means that anyone who has visited the site within the past month would have been unable to add a certificate exception, and would therefore not be able to visit the site until LinkedIn renewed the certificate.

LinkedIn's expired certificate was renewed shortly before this article was published.

November 2017 Web Server Survey

In the November 2017 survey we received responses from 1,819,412,110 sites and 6,893,323 web-facing computers, reflecting a gain of 4.17M sites and 6,961 computers.

This month’s web server survey saw Microsoft’s market share amongst all sites fall by 12.64 percentage points due to a loss of 228M sites. Despite this, Microsoft still retains its place with the largest market share by this metric of 36.80%, with Apache trailing at 24.38%. The majority of the loss occurred at just one hosting provider where over 190M Microsoft sites were lost.

This change isn’t reflected in the active sites metric which only saw minor changes amongst the main web server vendors. Microsoft lost only 0.03 percentage points of its market share with a drop of 261k active sites. Apache leads in the active sites metric by a considerable margin, increasing its share slightly this month to 44.55%.

Amongst the top million busiest sites Microsoft experienced a small increase in market share, pausing its general decline in this market. nginx experienced the largest growth with an increase of 2,133 of the top million sites.

nginx also saw the largest increase in number of web-facing computers, gaining 25k and pulling 1 percentage point of market share clear of Microsoft, which it overtook last month. Apache also experienced a gain in computers, albeit smaller at just 7k. It remains considerably ahead with a 42.38% market share.

New gTLDs Seen for the First Time

This month the controversial new .search gTLD being run by Google’s Charleston Road Registry subsidiary was found for the first time, with www.nic.search responding to the survey. Google hopes it will be able to run .search as a dotless domain which will automatically redirect users to their search engine of choice. This proposal has been criticised for going against ICANN’s own rules, which prohibits this functionality due to the potential for conflicts with existing names on internal networks. This feature could also cause confusion for users who have come to expect that typing words into their address bar will perform a search query for that term.

It is currently uncertain whether or not Google will be allowed to run the .search TLD as a dotless domain, however with the launch of the first site on this TLD this month Google is one step closer to the provision of this service.

Total number of websites

Web server market share

DeveloperOctober 2017PercentNovember 2017PercentChange
Microsoft897,467,51749.44%669,517,17736.80%-12.64
Apache340,811,23518.78%443,521,99524.38%5.60
nginx333,942,60418.40%367,687,48920.21%1.81
Google21,127,0781.16%20,333,6041.12%-0.05
Continue reading