Shorter URLs help phishers hook more victims

By Marcus Browne, ZDNet Australia
Tuesday, December 04, 2007 09:08 AM

Phishers are using shorter URLs for malicious sites in a bid to lend an air of legitimacy to threatening links.

Internet Security Services (ISS), IBM's online security division, claims to have noticed a significant drop in the number of characters used by fraudsters in their phishing URLs.

A post on ISS's Frequency X blog stated that "analysts have been observing host names within fraudulent phishing URLs consistently arrive with lengths of between 30 and 37 characters"; observers "have noted a significant change" as phishing host names have shrunk down to an average of only 17 characters in recent weeks.

Ralf Iffert, researcher for ISS's X-Force threat analysis team and author of the Frequency X blog, believes this is another step in the increasingly sophisticated social engineering measures adopted by cyber-criminals.

Phishers "appear to have adopted shorter URLs to avoid the suspicion of their potential victims," he said.

Steve Reddock, senior IT specialist for ISS believes this is a trend rather than a "blip": "This is a pattern we've noticed over several months, it's not just a blip".

Reddock told ZDNet Australia that phishers often experiment with new techniques but only for very short periods of time, but in this case the tactic of using shortened URLs as a means of deception has been around long enough to be considered best practice for cyber-criminals.

"It has to be making money for them, these groups run very efficient businesses," he said.

Paul Ducklin, head of technology at security firm Sophos said that users and security firms alike should be wary of making assumptions based on the character length of a URL, be it long or short.

"We need to be careful about security metrics which might lead users to assume a reliable correlation between the size of an Internet object and its danger... In any case, your e-mail client may disguise the real URL with a link that looks completely different--not just a different length--from what it really is," he said.

ISS's Reddock claims that as users have become more aware of dangerous links, revenues have declined for phishers, thus prompting the need for new approaches.

"The fact that they felt the need to make this move suggests that they were seeing diminishing returns," said Reddock.

Sophos's Paul Ducklin remains skeptical as to whether this new tactic will make a difference--or if it is something phishers will continue using.

"Size, as they say, generally doesn't matter," added Ducklin.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Migrating DHCP from Windows 2000 Server/Windows Server 2003 to Windows Server 2008

Windows Server

With a little bit of work, it's not hard to migrate DHCP services from Windows 2000 Server or Windows Server 2003 to Windows Server 2008. Here's how.


Read more »



Do we need more delivery centers?

Blog thumbnail

As I wrote a while back in about "racing to subsidies", there certainly is an increased focus by governments to attract delivery centers to their region. To do that, many..... by Michael Rehkopf

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web