ghacks Technology News

Firefox Search Engine Security Add-On, Protects Against Referred-Based Attacks

A common attack form on the Internet is to optimize web pages or domain for specific keywords to make them appear on the first search result pages of popular search engines such as Google or Bing. The attack is enabled once the page or domain receives first visitors from the search engines, which are more often than not unsuspecting of the dangers of the site. Different types of attacks are used on those sites, from harmless spam and popups over drive by downloads and redirects to fake antivirus offers.

Many of the pages have in common, that they display different results for search engine visitors, and visitors who do not come from search engines. This is relatively easy to do by checking the web browser’s referrer value.

The new Firefox add-on Search Engine Security protects users from some referrer based attacks by changing the referrer of the web browser when coming from search engine pages. The extension supports Google, Bing and Yahoo currently.

It basically displays a different referrer than the one it should display. The effect depends largely on the attack site. Users may circumvent attacks if the site checks the browser’s referrer to display a harmless page to non-search engine users.

While that’s obviously no 100% protection against these kind of attacks, it is another layer of protection.

search engine security

The extension works on the default search engine domains and localized search engines. Zscaler SES on or off is displayed below the search form to indicate if the add-on is enabled on that particular search engine.

search security

Search Engine Security can protect Firefox users from redirect attacks that load fake antivirus pages, videos or other malicious contents. Firefox users can download the extension from the official Mozilla Firefox add-on repository.

You can disable the add-on on for a specific search engine in the options. Here you can also add sites to a whitelist, which may be happy if a legit website checks referrers and displays different contents based on those. Lastly, it is possible to add or change the referrer itself in the preferences.

Enjoyed the article?: Then sign-up for our free newsletter or RSS feed to kick off your day with the latest technology news and tips, or share the article with your friends and contacts on Facebook or Twitter.

Related Articles:

Firefox Quick Search Bar, Easier Search Engine Access
Add Google Sandbox Search Engine To Web Browsers
Replace Firefox’s Right-Click Search Engine
SaferChrome Protects Chrome Users Against Man In The Middle Attacks, Improves Security
Change the Firefox Location Bar Search Engine



About the Author:Martin Brinkmann is a journalist from Germany who founded Ghacks Technology News Back in 2005. He is passionate about all things tech and knows the Internet and computers like the back of his hand. You can follow Martin on Facebook or Twitter.

Author: , Friday April 29, 2011 -
Tags:, , ,


Responses so far:

  1. jasray says:

    Would something like Buffer Zone work as well and perhaps more so?

  2. Paul(us) says:

    Great find Martin, Thanks a mill. for this. I am constantly looking for upgrading main browser security, and naturally also the rest of main computer. And i think this is a worth-will extension to main outer security measures, despite the small delay at startup
    On a outer note i wish that the developer is upgrading the Firefox add-on url-security0.10, to a newer version compatible with Firefox 4.0.1. Do you maybe know or this is happening in the near future, or do you maybe know an alternative for this add-on?

  3. SFdude says:

    Hi Martin,

    thanks for another good FF ext!
    Interesting…

    I do have a simple, (maybe silly) question:

    - why would a malicious website you land in,
    wish to try to attack you,
    ONLY if you are “refered” by Google, Bing or Yahoo?.

    Suppose I _click on a link_ in “Reddit.com”
    or “innocent_sheep.com”.
    I’ll then land on the malicious website.
    Will this bad site not try to attack,
    even if I ** didn’t ** come from Google?

    After all, the objective of a bad site is to attack you,
    no matter where are you are coming from….right?

    thanks,

    • bastik says:

      One reason might be “hacked” websites.

      When you set-up a domain to attack someone I agree that you most likely attack everyone who hits the page where ever he comes form. (although some try to filter IP ranges from antimalware vendors)

      When you manage to break into a website (which is popular) it’s most likely that people that belong to that domain will not visit their site through web search and therefor not discover the attack. Like I visit ghacks directly and would not notice anything if there would be a problem.

  4. bastik says:

    The same trick is done by websites which offer free software, but require personal information and send you a bill after you downloaded some free stuff because they claim you agreed to an pay subscription.

    When you visit such a site from Google (or Bing) there’s no sign of any service that would cost you money, but when you visit the site directly the information about the costs is displayed.

    The trick behind is that you search some free software through Google, enter your private data and if you get the bill you most likely visit the site directly. Then you may be afraid that you overlooked it and pay the bill.

    Great article. There are other addons to control referers, of course this one is very easy to set-up.

  5. Crodol says:

    bastik, thanks for the explanation. Only now I understand the purpose of this extension.

  6. TechLogon says:

    Interesting concept and a useful add-on. Good explanations of why it is needed!

    I like WOT (Web Of Trust) to protect against dodgy websites in search results but it would be of no use against a newly hacked website that is normally well rated – this add-on should help.

    Another nail in the coffin of IE which doesn’t allow blocking the referrer (although you could use a firewall/AV suite to achieve it)?

Leave a Reply   Follow Ghacks   Subscribe To Comment Rss

Subscribe without commenting

© 2005-2012 Ghacks.net. All Rights Reserved. Privacy Policy - About Us