Category: Security

  • The war on terror on the web

    Since it’s related to the web, I’ll post it here. According to The Times Online (UK), tens of websites linked to Al-Qaeda have abruptly vanished from the web. Apparently, it’s suspected that British Intelligence has had something to do with the closing of the sites which, among other things provided information on building and using biological weapons and “how to strike a european city”.

  • Data Security

    One of the things that apparently is commonly overlooked in the area of computer security is what happens to the data on your hard drive when you get a new computer.
    (more…)

  • Preventing web crawlers from indexing everything

    Ok, so we’ve seen how to password protect directories to keep the web crawlers out, but I don’t want to go through that. I want to keep the page open, but I don’t want it spidered and indexed by the bots. (more…)

  • There aren’t THAT many phish in the sea, more on phighting phishing

    The last post, I got sidetracked into another idea as I was doing a google search. Not uncommon. OK, what I was curious about is how many phishing sites are estimated to be “in the wild” at any given moment threatening to defraud viewers? Well, my search did turn up an interesting report. (more…)

  • More phishing phighting

    I mentioned that I had gone after another two phishing sites the other day. One was down within 24 hours. I was impressed with the responsiveness, but it’s possible I wasn’t the first to complain. Still it was good to see it gone. I’m still working on the second. It’s hosted at an xo.com ip address. Along the lines of the phishing battle, (more…)

  • Protecting access to web directories with htaccess

    Okay, in an earlier article I was looking at uses of Google that might reveal things you don’t want revealed about your website. Maybe a test directory that you don’t want to be spidered. I want to say that it’s not possible to keep it hidden just by NOT linking to it. That’s what some will suggest, the argument goes along these lines “spiders just follow links, so don’t link to a directory or document you don’t want the web spiders to see.” Spidering bots seem to be a bit more resourceful though, I’ve seen files and folders that I can’t imagine were linked to being picked up in a web search, so how do we prevent that? (more…)

  • Anti phishing information (phighting phishing ?)

    Well, after the early week experience with getting a Bank of the West site taken down, I’ve taken on two more which have come in today. One of these was an ebay spoof, the other paypal. In both cases I’ve emailed the appropriate abuse address on the owners network (this time one is in China, I think the second was as well.) I did find out something neat about paypal and ebays ways of reporting. (more…)

  • Phish down – finally

    Finally, I just checked and ~80 hours since my first emails the Bank of the West phishing site is finally down. (~32 hours since contacting the ISP and 8-10 hours since contacting Bank of the West.) I suspect the ISP probably is the one responsible as I’ve found 24-48 hour response time for ISP’s with virus complaints. (Note to self, first round of complaints should probably go to ALL contacts that might be directly responsible, domain owners, ISP and even spoofed company.) I hate that it took so long, but I’m glad that it’s down. I feel like I actually have accomplished something with all the time I’ve spent on it this week. (more…)

  • Phishing – Bank of the West Notice part three… (deeper sigh)

    You’ll notice I haven’t mentioned the URL of the phishing site thus far. That is, in part, because I feel as though it would be irresponsible. That someone might come across this and take advantage of the fact that the site is still up and running to harvest account information. I would like to think that wouldn’t happen, but hey, that’s why the site is there to begin with. Well, 72 hours and still no action. (more…)