What to Do When Sites You Trust Suffer Redirect Attacks

What to Do When Sites You Trust Suffer Redirect Attacks Featured Image

September 2017 was a very gray month indeed for people who are concerned about their security and the privacy of their data. For starters, Equifax – a major credit reporting agency in the U.S. – was hacked, leaking the personally identifiable information of 143 million people. Then there was the data leak from Amazon S3 servers. And now, the Equifax website for customers looking to mitigate problems with their credits report has (again) been hacked, redirecting people to malware. What should people do when they suffer redirect attacks?

What’s a Redirect Attack?

redirecthack-equifaxlogo

Before we dive into how redirect attacks work, we need to talk about a little bit of history:

After the breach of Equifax, an organization that is trusted by various financial institutions to provide the credit reports of millions of people around the world, the company made efforts to try and remedy the situation

Despite all of this, its website still had vulnerabilities that hackers took full advantage of in the wake of the recent compromise. This led to Equifax’s website unintentionally redirecting people to a fake Flash update download that would install adware on their computers. The malware itself is not extraordinarily damaging since it merely displays advertisements on Internet Explorer. But in any other situation, things could get a lot worse.

A redirect attack happens when a hacker compromises a website to the point that its visitors are directed to a fake page when they click a link. To give you a proper scenario, imagine that hackers manage to hijack Facebook’s homepage so that every time you click on an advertisement, it takes you to an affiliate site that pays them every time they get a visit. That’s a more harmless example than the typical scenario, but it summarizes redirect attacks succinctly. You click a link you trust to take you somewhere, and it swings you somewhere else.

How Hackers Execute Redirect Attacks

The simplest way to redirect someone to another website is to take advantage of vulnerabilities of a website’s database. Sometimes a well-executed SQL injection allows the hacker to slip some malicious code into a website’s output.

This isn’t always possible, which leads more clever hackers to find vulnerabilities in the software that runs the website or its content management system (CMS). Sometimes a vulnerability like Apache Struts CVE-2017-5638 that allows people to execute arbitrary code will occur.

What You Can Do To Prevent Becoming A Victim

redirecthack-security

It’s easy to feel helpless when trusted organizations suffer attacks that are easily preventable and do not take sufficient measures to remedy the situation. But there are a couple of things you can make a note of when you’re browsing the web to prevent yourself from falling victim to redirect attacks.

For starters, you should never open “software updates” or any other kind of executable file from websites that don’t usually hand them out. While you can expect to get a ZIP file with an EXE in it or just a plain EXE from a website like Softpedia – which many people use to download programs and utilities – you should never expect an EXE to come from an email attachment, a social media site, or from a credit reporting agency.

If you’re unsure of an EXE that you have received and expected, upload it to a trusted online virus checking utility like VirusTotal or Metadefender.

No matter how scary redirect attacks are, it’s helpful to keep in mind that they will often push you to a different domain name than the organization’s official one. Make a habit of keeping an eye on your address bar as you browse the Web. At some point it will become second nature, and you’ll notice any suspicious changes quickly.

Do you have any other tips that can help people arm themselves against redirect attacks similar to the one Equifax suffered? Let us know your ideas in a comment!

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Miguel Leiva-Gomez Avatar

Read next

Suzanne Simard sealed paper birch and Douglas fir seedlings inside plastic bags, fed them carbon-14 and carbon-13 dioxide, and nine days later found carbon had crossed between species through fungal threads in the British Columbia soil beneath her boots
A species of jellyfish called Turritopsis dohrnii can revert its adult cells back to a juvenile polyp stage when injured or starving, effectively restarting its life cycle, and biologists have so far failed to identify any natural limit to how many times it can do this.
A Japanese man named Jiroemon Kimura, who lived to 116, was born in 1897 when Queen Victoria still ruled and died in 2013, meaning a single human life personally overlapped with the invention of the airplane, the atomic bomb, the internet, and Instagram
The Hollywood sign originally read HOLLYWOODLAND when it was built in 1923 as a real estate advertisement for a housing development, and it was only meant to stand for 18 months, but nobody ever got around to taking it down and the city eventually adopted it as a landmark
Almost all of the world’s internet traffic does not travel by satellite but through fibre-optic cables lying on the ocean floor, a hidden web of wires crossing the deepest parts of the sea to connect the continents.
People who flip their phone face down on every table aren’t being secretive. They figured out that staying interruptible meant handing their time to whoever rang first
Twitch vs. Facebook Gaming vs. YouTube Gaming: What’s the Best Live Game Streaming Platform?
Chrome Extensions Ownership Transfer is a Direct Threat to You: How to Stay Safe