Plaxo plugs phishing vulnerability

NEWS

Online contacts management company Plaxo plugged a serious security hole in its Web site on Monday that left its members' contact lists vulnerable to be stolen, modified or deleted.

With more than two million users, Plaxo is one of the most popular online address book companies. It stores its members' contacts in a central database and provides access to them over the Internet. The service allows its members to invite contacts to update their own information, helpings users keep their address books up to date.

The security flaw, which was discovered by Web application security company Lodoga, was reported to Plaxo on Monday evening.  Lodoga's security test engineer Jeremy Wood told ZDNet UK it took him less than an hour after discovering the weakness to build an attack script that could exploit the vulnerability.

Wood demonstrated the attack script to ZDNet UK. Using the live Plaxo Web site, Wood's script added an additional layer over the username and password box. With this layer in place, if a user typed in their access details, the information would first be sent to the attacker's Web site and then to Plaxo to log the user in. Users would have had no idea their details had been taken.

"We are using a vulnerable field on the front page of Plaxo to specifically overlay their user ID form with something called a 'Div' -- a Javascript element that is a layer. If you place a layer on top of a Web page, you can colour it the same and make it present the same information," said Wood.

Wood explained that because the additional layer was being placed over the actual Plaxo Web site, its members would not be able to tell the difference, even though the site was connected over SSL. Clicking on the padlock displayed on the browser would show the Web site as genuine despite its modification.

Plaxo's service is an ideal target for phishers. Any fraud would probably be delivered in the same way that criminals target bank customers, by sending a user an email asking them to click on a specially crafted hyperlink that would lead them to a doctored page.  Banks can tell their customers to ignore such emails, but Plaxo's users need to send and receive emails to invite contacts to click on a link and update their details.

"The whole Plaxo environment is built around trust and sharing information, and you have seen how easily emails can be spoofed. This attack is designed to create victims, but more importantly, not allow them to know they have become victims," said Wood.

Rikk Carey, vice president of engineering at Plaxo, told ZDNet UK that the Web site was fixed a few hours after the problem was highlighted and he was "fairly certain" that the vulnerability had not been exploited by anyone except Lodoga's security testing.

"It required the evildoer to trick the victim into clicking on a URL controlled by the evildoer. This URL adds some extra HTML to the target Web site (and thus is actually happening on the target Web site, such as Plaxo.com) which can be used to steal the victim's password. The fix was minor and has been deployed," he said.

According to Lodoga's Wood, there are a large number of Web sites that have not programmed their databases to ensure that database records only accept information they are designed to collect. This will be a real headache for businesses such as Plaxo that require the promiscious exchange of emails between groups of contacts. 

"Plaxo is not alone. We have been running workshops this month and every client we deal with has the same problem. Developers haven't really realised how robust they have to be in terms of security coding. This is probably the number one problem, and companies really are jeopardising their trade name and potentially their customers' data," added Wood.

Russ Cooper, founder and moderator of the NTBugtraq Newsletter and surgeon general at security company TruSecure, told ZDNet UK that Plaxo had been caught making a classic scripting error: "You shouldn’t be able to put scripting code into something that asks you for a business title," he said.

Talkback

I had strange happennings with my Outlook Express account recently. I am running Window XP professional and have Plaxo installed. Plaxo is programme that integrates itself into OE and allows you to automatically update your contacts lists.
One day I went to check my e mail and although all my contacts were intact all of my messages had gone. Also all of my folders that I had set up had gone back to default.
There was also the original welcome to OE message from Microsoft so it was behaving as though it was a fresh install. I contacted Plaxo to see if there were any known issues or bugs and they said not so what the heck has happened here I wonder??

1 April, 2004 09:54 Reply

Post your comment

In order to post a comment you need to be registered and logged in

Log in or create your ZDNet UK account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

ZDNet UK Live

nikeshoes998

Oracle signs Solaris deals with HP and Dell: Find the answers in the Community FAQ free shipping wholesale product... http://bit.ly/bcjQtY

mensapparel2010

Oracle signs Solaris deals with HP and Dell: Find the answers in the Community FAQ free shipping wholesale product... http://bit.ly/9GWZRh

womensapparel20

Oracle signs Solaris deals with HP and Dell: Find the answers in the Community FAQ free shipping wholesale product... http://bit.ly/bPLHL8

lisabarnes001

Oracle signs Solaris deals with HP and Dell: Find the answers in the Community FAQ free shipping wholesale product... http://bit.ly/bVw3F2

KC616

Oracle signs Solaris deals with HP and Dell: Find the answers in the Community FAQ free shipping wholesale product... http://bit.ly/cDUyaj

KC616

free shipping wholesale products: Read more »h handbags,NIKE shoes, jewelry, watches, and jacket and so on. We gua... http://bit.ly/cWcW1e

SpyScroll

Cyberwar defence plan is essential, says former CIA head: Michael Hayden, former head of the CIA and the National ... http://bit.ly/beLpKQ

Droid_News

SAP leads businesses into augmented reality http://bit.ly/9eMWYp | #Droid #Android

wholesalegurru

free shipping wholesale products: We mainly supply top mirror quality brand name products, such as wholesale handb... http://bit.ly/cWcW1e

CNSInstructor

Cyberwar defence plan is essential, says former CIA head: Michael Hayden, former head of the CIA and the N... http://bit.ly/9sn6ax #pdln4nx

AllAboutFashion

Oracle signs Solaris deals with HP and Dell http://bit.ly/9KVeqD

Droid_Phone

SAP leads businesses into augmented reality http://bit.ly/9eMWYp | #Droid #Android

AllAboutFashion

free shipping wholesale products http://bit.ly/c7cpX4

Droid_Phone

TalkTalk to sell mobile services via Vodafone deal http://bit.ly/bLVfxI | #Droid #Android

wholesalegurru

Oracle signs Solaris deals with HP and Dell: Find the answers in the Community FAQ free shipping wholesale product... http://bit.ly/cDUyaj

wholesalegurru

free shipping wholesale products: Read more »h handbags,NIKE shoes, jewelry, watches, and jacket and so on. We gua... http://bit.ly/cWcW1e

felixsprisci

DoJ joins whistleblower in Oracle fraud suit http://bit.ly/bMT3SJ

actatrudy

Update: free shipping wholesale products - ZDNet UK (... http://www.actahandbags.com/trends/free-shipping-wholesale-products-zdnet-uk-blog/

lisabarnes001

free shipping wholesale products: Read more »h handbags,NIKE shoes, jewelry, watches, and jacket and so on. We gua... http://bit.ly/bRvFgG

mensapparel2010

free shipping wholesale products: Read more »h handbags,NIKE shoes, jewelry, watches, and jacket and so on. We gua... http://bit.ly/9CXYG9

Featured white papers

The need for email archiving

Without an effective system for archiving emails, organisations can find themselves unable to recover vital business records, leaving them open..

Download now

Dell Data Storage Summary

This study was conducted in the United States amoung IT decision makers with involvement in data centre purchases at companies..

Download now

Datasheet: Infrastructure as a Service

'Infrastructure as a Service' gives enterprises the flexibility to subscribe to the compute power and storage they require today with 'pay..

Download now