Security Basics mailing list archives

Re: alexa - google toolbar behaviour


From: Aaron <nite () sonic net>
Date: Mon, 18 Jul 2005 15:35:55 -0700

Alexia is major spyware... I thought this was well known but I guess
not, if you don't believe me.. I I have pcap files to prove it.
When you install the google toolbar, it also tells you that it will
report your information to google, or you can choose disable this
feature. I know because I've installed it on friends machines before to
help stop popups before IE had a pop-up blocker.
Alexia will also create popups and do things it shouldn't. 
An easy way to tell if your system or network is infected with spyware
is to look for strange DNS lookups and strange user agents.
Firefox also has a user agent switcher extention that allows you to
change your user agent, or make a custom one :-)
   -Aaron

On Wed, 2005-07-13 at 11:10 +0300, Mehmet Buyukozer wrote:
Hi All

Lately, I saw several webserver statistics showing exact number of browsers
and operating system's that the visitors using so decided to analyze what my
browsers (IE, Opera, Mozilla) are sending to webservers. I was using google
toolbar and alexa toolbar addons on IE and when I checked what IE sending as
User-Agent, I saw the result in below. It might seem normal that Alexa adds
its print to IE's agent properties but I already disabled from "Add-on
Management" . And also another thing is www.k2pdf.com has anybody idea what
this comes from? Is there a way of hacking these headers from registry or
somewhere else?

Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; www.k2pdf.com; SV1; .NET
CLR 1.1.4322; Alexa Toolbar)


Another thing, as I already accepted the legal issues for google toolbar as
spyware, I was not expecting such a behaviour.

It sends all your surf information to google.

An example for this:
http://toolbarqueries.google.com/search?client=navclient-auto&googleip=O;130
2&ch=62317384429&iqrn=3neB&orig=0H8Hr&ie=UTF-8&oe=UTF-8&features=Rank:FVN&q=
info:http%3A%2F%2Fwww%2Esonofnights%2Ecom%2F

Regards

Mehmet

www.sonofnights.com





Current thread: