ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Shorter URLs help phishers hook more victims

Marcus Browne ZDNet Australia

Published: 03 Dec 2007 08:56 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Phishers are using shorter URLs for malicious sites in a bid to lend an air of legitimacy to threatening links.

Internet Security Services (ISS), IBM's online security division, claims to have noticed a significant drop in the number of characters used by fraudsters in their phishing URLs.

A post on ISS's Frequency X blog stated that "analysts have been observing host names within fraudulent phishing URLs consistently arrive with lengths of between 30 and 37 characters"; observers "have noted a significant change" as phishing host names have shrunk down to an average of only 17 characters in recent weeks.

Ralf Iffert, researcher for ISS's X-Force threat analysis team and author of the Frequency X blog, believes this is another step in the increasingly sophisticated social-engineering measures adopted by cybercriminals.

Phishers "appear to have adopted shorter URLs to avoid the suspicion of their potential victims", he said.

Steve Reddock, senior IT specialist for ISS believes this is a developing trend: "This is a pattern we've noticed over several months, it's not just a blip".

Reddock told ZDNet Australia that phishers often experiment with new techniques but only for very short periods of time. However, in this case, the tactic of using shortened URLs as a means of deception has been around long enough to be considered best practice for cybercriminals.

"It has to be making money for them, these groups run very efficient businesses," he said.

Paul Ducklin, head of technology at security firm Sophos, said that users and security firms alike should be wary of making assumptions based on the character length of a URL, be it long or short.

"We need to be careful about security metrics which might lead users to assume a reliable correlation between the size of an internet object and its danger… In any case, your email client may disguise the real URL with a link that looks completely different ‐ not just a different length — from what it really is," he said.

ISS's Reddock claims that as users have become more aware of dangerous links, revenues have declined for phishers, thus prompting the need for new approaches.

"The fact that they felt the need to make this move suggests that they were seeing diminishing returns," said Reddock.

Sophos's Paul Ducklin remains sceptical as to whether this new tactic will make a difference, or whether it is something phishers will continue using.

"Size, as they say, generally doesn't matter," added Ducklin.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
4 out of 4 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Sentry Posts Blog

Nasa and the virus

Yesterday the BBC ran a story about a computer virus making it into orbit, which I read with incredulity. OK, it's a nice silly season story on the surface, but what really got me was... More

1 comment

Customer data found on eBay server hig...

The recent news about customer details being retrieved from a server sold on eBay is yet another story about the sorry state of information security in the electronic age (see: http://news.zdnet.co.uk/...m).... More

Post a comment

Does it matter if you are an aardvark...

In spam terms, apparently it does. According to Cambridge University security expert Richard Clayton, if your email address is aardvark at animal.net, you are more likely to receive... More

1 comment