home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers



  C O L U M N S

Hijinks on the High Seas

November 29, 1999
By ROBERT MOSKOWITZ

Remember when Wile E. Coyote would paint a picture of a road on a canyon wall in hopes of fooling and capturing the Road Runner? If you do, you also probably remember that Wile E.'s plan always failed. But these days, there are some Wile E. Coyotes on the Internet who are trying to do the same to your customers--with much more success.

Welcome to pagejacking, the latest in Internet hijinks. Pagejacking is what happens when Internet surfers think they've selected www.this.com from a search engine, but they end up at www.that.com. The mechanics have nothing to do with any security flaws in HTTP, Web servers or clients. Rather, pagejacking is a sham perpetrated on the search engines, and your Web site is a potential dupe. While you can't take any direct action against pagejacking, once you discover it, you can act before any serious customer-relations damage is done.

The FTC (Federal Trade Commission) has been treating pagejacking as fraud, and a few pagejackers have been stopped. But the FTC can't stem the tide. Much pagejacking is done from overseas servers, and there is some doubt as to whether pagejacking really meets the definition of fraud or falls into the FTC's jurisdiction.

The pagejacking process is trivial. Pagejackers copy an important page from your Web server, build a Web page with all the key metatags and text, then rig the page content and title so that search engines sort their page ahead of yours. It's as simple as that. The attack is uncomplicated and requires no assault against your servers or your DNS entries; pagejackers use your own metatags to defeat you. Although this is not a security problem, security tools can be tuned to root out pagejackers.

With the knowledge that pagejackers use search engines as the hapless barkers bringing in the marks, you can find them in the search engines more easily than your customers can. After all, those metatags are yours--you know what to look for. What you need is a reversed IDT (intrusion-detection tool), and perhaps an EDT (extrusion-detection tool) that will perform automatic searches for your own metatags. This EDT would run your tags and key text against the main search engines nightly, reporting all URLs that sort higher than yours. Some AI (artificial intelligence) might help, but in the end you'll need someone--most likely your Webmaster--to review the report each morning and personally investigate some of the URLs. Because the economic model for most pagejackers is to send the pagejackee to a porno site (pagejackers get a few microcents in return), the investigation must be conducted outside your firewall with protection and alarms. This way, the investigator knows where he or she is going, but does not have to view any objectionable material.

If a pagejacker is found, you can set remedial actions in motion. The FTC may still assist you. The search-engine owner may be willing to help as well, to avoid possibly being considered an accessory to the fraud. A potential and interesting side benefit from this effort is that you'll inevitably see how you rate in the search engines against your competitors. This alone could pay for your effort. If a casual search on retailers shows you instead of them, your site benefits in the long run.

Pagejacking is a real threat to the Internet's usability. If it becomes pervasive, customers will simply stop searching for things. It's unlikely that standard security technologies will provide any relief. It's also difficult to envision any digital signing that is not defraudable, and what browser users ever check out security information? Only your active vigilance can thwart pagejackers. If you're concerned about pagejacking, contact the folks at your intrusion-detection vendor and ask if they can whip up an extrusion detector for you.

Robert Moskowitz is a senior technical director at ICSA. Send your comments on this column to him at rgm@htt-consult.com.



 





Looking for a new job?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
The tumbling of IT jobs stopped in the second quarter, as the IT sector added about 44,000 jobs.

It's just a glimmer, but Oracle is starting to see a bit of light at the end of the recession tunnel.










2009 IT Salary Survey: Meager Raises, Solid Prospects
Though raises are notably smaller than a year ago, and job security’s shrinking, IT careers are looking safer than many others in this economic downturn. Get all the findings in InformationWeek's 2009 IT Salary Survey. Available FREE for a limited time.
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



Techweb
Informationweek Business Technology Network
InformationweekInformationweek 500Informationweek 500 ConferenceInformationweek AnalyticsInformationweek Events
Informationweek MagazineGlobal CIOIWK Government ITbMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingPlug Into The CloudDr. DobbsContentinople
space
TechWeb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0Mobile Business ExpoNoJitter
Black HatGTECEnergy CampCloud ConnectGov 2.0 ExpoGov 2.0 Summit
space
Light Reading Communications Network
Light ReadingLight Reading AsiaUnstrungCable Digital NewsInternet EvolutionPyramid Research
Heavy ReadingLight Reading LiveLight Reading InsiderEthrnet ExpoTelco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems and TechnologyInsurance and TechnologyWall Street and TechnologyAccelerating WallstreetBST SummitBuyside Trading SummitIT Summit
space
Microsoft Technology Network
MSDNTechNetTotal IT ProTotal Dev ProNET Total Dev Pro CommunitySQL Total Dev Pro Community
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service