May 31, 2006

Update: 'Yapbrowser' raises security concerns

Web browser was taken down when security analysts found it directed users to child pornography

A Web browser originating in Russia is available for download again after it was taken down last month when security analysts found it directed users to child pornography.

The Yapbrowser instantly raised concern when it was noticed in April, said Chris Boyd, security research manager for FaceTime Communications. Typing any search or URL (uniform resource locator) into the browser led users to Web sites containing child pornography.

Under pressure from security researchers, the software's creators took the browser offline about a month ago. But the Yapbrowser has now appeared on a new download site, according to a security blog run by FaceTime.

Security researchers say it falls into the category of rogue browsers, which take users to ads or other content that they don't ask to see. It was originally hosted on a server in Russia that also hosted "hijack" sites, such as search engines that flood computers with adware, Boyd said. Users were lured to the site through unsolicited e-mail.

The new version of the Yapbrowser doesn't work properly, throwing up a 404 error page when a URL is entered, according to Boyd.

"We'll be keeping an eye on it just to see what happens," Boyd said. "For the moment they've relaunched, but it doesn't actually function, which seems a bit pointless."

Security researchers advised users to not download the browser, despite tortured English claims on the site that say "Your computer will be free from viruses breeding online."

The Yapbrowser at one time was also bundled with Zango, software from 180solutions Inc., based in Bellevue, Washington, that delivers ads based on searches. 180solutions has come under frequent fire for promoting programs that installed unwanted adware and spyware with little or no user consent.

Adware, the term for software that delivers advertisements, and spyware programs, which can record what Web sites a person visits and send the information to a marketer, can slow down computers and be difficult to remove.

Steve Stratz, public relations director for 180solutions, said the software bundle with the Yapbrowser was never publicly available. However, at least one copy of the bundle was obtained and eventually looked at by security experts, Stratz said.

The bundle was still being tested when 180solutions severed its arrangement after the Yapbrowser's link to child pornography became known, Stratz said. 180solutions, he said, will not have any further business with Yapbrowser.

Yapbrowser officials acknowledge that 180solutions had nothing to do with the link to the pornography, and the problem was with their own hosting service, Stratz said. 180solutions contacted the U.S. Federal Bureau of Investigation.

"That is obviously the worst of the worst of the Web," he said.

180solutions was the target of a complaint filed earlier this year with the U.S. Federal Trade Commission by the Center for Democracy and Technology (CDT), a Washington, D.C., nonprofit group. The CDT alleged the company used deceptive practices to get users to download software.

Boyd and other security analysts corresponded with Yapbrowser's Russian creators, who eventually withdrew the product, saying they were "shocked" by the content it fetched.

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.