Contact
QR code for the current URL

Story Box-ID: 90178

Finjan Software GmbH Alte Landstrasse 27 85521 Ottobrunn, Germany http://www.finjan.com
Contact Ms Claudia Meisinger +49 89 67359711
Company logo of Finjan Software GmbH
Finjan Software GmbH

Finjan Reconfirms Google’s Anti-Phishing BlackList Exposed Confidential User Information

(PresseBox) (Ottobrunn, )
Finjan Inc., the global provider of best-of-breed proactive web security solutions for businesses and organizations, today announced that it reconfirms recent reports that Google have unwittingly exposed private user names and passwords on the Google anti-phishing blacklist, which did not use any access protection. Such sensitive information could potentially have been used to compromise user privacy, and could even have been used for identity theft or financial profit (as users generally have a single “web” password for most of their online accounts).

On January 3, 2007, Finjan’s Malicious Code Research Center (MCRC) researchers discovered that a list of URLs was available and unprotected on Google’s servers and immediately informed Google, which acknowledged receipt of Finjan’s alert about the vulnerability. Finjan believes the information on the servers had been gathered using Google’s anti-phishing browser extension. Google has fixed the problem, and it is assumed that Google has notified all affected users. Recent tests conducted by Finjan confirm that there is no data leakage on the current Google anti-phishing blacklist.

“Finjan became aware of the problem after examining a publicly available list of URLs provided from Google’s servers” said Yuval Ben-Itzhak, Finjan’s Chief Technology Officer. “After examining the data provided in these files, Finjan found that sensitive user information was available on the web with no access protection, including emails, usernames, passwords and session tokens that could be used by hackers to compromise users’ privacy.”

Finjan offers the following advice to minimize the risk of exposing confidential information from similar web applications:

Pointers for home users:

- Avoid sharing your browsing habits with third parties by disabling URL sharing or forwarding - as this is usually enabled in your browser’s toolbars.
- Use adequate password policy for your web accounts. Do not use the same password for all web accounts. Having the same password for several accounts will compromise ALL of them if just one is compromised.
- Make sure that your PC is adequately protected from malicious software such as spyware and adware that can send out private information. Even when an application’s privacy policy looks sensible, remember that it’s enough for it to send a full URL (including parameters) to disclose your email and other private information.

Pointers for corporate users:

- Make sure that you have proactive protection in your web security solution – chasing the attack vectors after the event is always “too little, too late”, particularly if you get hit by a zero hour attack that your security solution does not recognize. Anti-virus and URL Filtering are not enough!
- Make sure that your security solution is updated for handling new technologies and trends. Security products must protect you from the vulnerabilities rather than just attacks and exploits.
- Check your vendor’s research capabilities and their ability to provide up-to-date information which is immediately translated it into actionable security measures.
- Deploy a web security solution that protects users from being subjected to information leakage by preventing users from visiting phishing sites in the first place. The solution should also prevent any toolbar or add-on that is installed in the browser from getting to see the URL.
- Examine your egress data policy to make sure that you cover all known and suspicious site access (users trying to access phishing sites).

About MCRC

Malicious Code Research Center (MCRC) is the leading research department at Finjan, dedicated to the research and detection of security vulnerabilities in Internet and email applications as well as other popular applications. MCRC’s goal is to continue to be steps ahead of hackers attempting to exploit open platforms and technologies to develop malicious code such as spyware, Trojans, phishing attacks, worm and viruses. MCRC researchers work with the world’s leading software vendors to help patch their security holes, as well as contribute to the development of next generation defense tools for Finjan’s proactive secure content management solutions. For more information, visit our MCRC subsite.

Finjan Software GmbH

Finjans sichere Web Gateway Lösung bietet höchst effektiven Schutz gegen alle Bedrohungen aus dem Web. Das Unternehmen nutzt dafür seine patentierte verhaltensbasierte Technologie um in Echtzeit all jene Bedrohungen abzuwehren, die über das Web kommen; so wird der Geschäftsbetrieb vor Spyware, Phishing, Trojaner und andere Malware proaktiv geschützt. Die Sicherheitslösungen von Finjan haben zahlreiche Industrieauszeichnungen erhalten und genießen die Anerkennung führender Analysten und Publikationen, eingeschlossen IDC, Bulter Group, SC Magazine, CRN, PCPro, ITWeek und Information Security. Weitere Informationen gibt es unter www.finjan.com.

The publisher indicated in each case (see company info by clicking on image/title or company info in the right-hand column) is solely responsible for the stories above, the event or job offer shown and for the image and audio material displayed. As a rule, the publisher is also the author of the texts and the attached image, audio and information material. The use of information published here is generally free of charge for personal information and editorial processing. Please clarify any copyright issues with the stated publisher before further use. In case of publication, please send a specimen copy to service@pressebox.de.
Important note:

Systematic data storage as well as the use of even parts of this database are only permitted with the written consent of unn | UNITED NEWS NETWORK GmbH.

unn | UNITED NEWS NETWORK GmbH 2002–2024, All rights reserved

The publisher indicated in each case (see company info by clicking on image/title or company info in the right-hand column) is solely responsible for the stories above, the event or job offer shown and for the image and audio material displayed. As a rule, the publisher is also the author of the texts and the attached image, audio and information material. The use of information published here is generally free of charge for personal information and editorial processing. Please clarify any copyright issues with the stated publisher before further use. In case of publication, please send a specimen copy to service@pressebox.de.