Home / Blogs

SiteFinder Is Leaking Data

Richard M. Smith

I just discovered that VeriSign's SiteFinder Web site is leaking data submitted in Web forms to its marketing analysis partner, Omniture. Forms can easily contain personal information such as an email address. For the problem to occur, a Web form must use the GET method.

This data spill problem occurs if a Web page anywhere on the Internet submits a Web form to an action URL with a misspelled or expired domain name.  Because of VeriSign's recent controversial changes to the DNS system, this form data is submitted to the SiteFinder Web site.

SiteFinder in turn passes the form data along to Omniture in the URL of a Web bug.  The Web bug is constructed on the fly by about 50 lines of JavaScript code embedded in the SiteFinder home page.

This data spill problem raises legal questions because of possible violations of the VeriSign privacy policy and of the Electronic Communications Privacy Act (ECPA).

As a point of comparison, it appears that Microsoft went out of their way to not receive form data with their Smart Search feature. In my experiments, Smart Search is not enabled for Web form action URLs with misspelled or expired domain names.  Instead, Internet Explorer gives a generic 404 error page.

Here's an example form that illustrates the problem:



Enter Any Email Address:



And here's what the URL of Omniture Web bug looks like with an email address from the form in it:


< a href="http://verisignwildcard.112.2o7.net/b/ss/verisignwildcard/1
/">http://verisignwildcard.112.2o7.net/b/ss/verisignwildcard/1/
G.2-Verisign -S/s07262928512095?[AQB]&ndh=1&t=23/8/2
003%2016%3A6%3A20%202%20240&pageN ame=Landing
%20Page&ch=landing&server=US%20East&c1=www.atypod
omainthatism isdirectedbyverisign.com/cgi-bin/subscribe.pl
%3Flist%3Dhorsebreeding%26a mp%3Bemail%3D&c2=ww
w.atypodomainthatismisdirectedbyverisign.com/cgi-bin/ sub
scribe.pl%3Flist%3Dhorsebreeding%26amp%3Bemail%3D
%20%2800/00%29&c3=ww w.atypodomainthatismisdirecte
dbyverisign.com/cgi-bin/subscribe.pl%3Flist %3Dhorsebree
ding%26amp%3Bemail%3D%20%28DYM%29&c12=No&c13
=00&c14=No&c15=0 0&c16=Yes&c17=15&c22=NOT%26%2
332%3BSET&g=http%3A//sitefinder.verisign.co m/lpc%3Fu
rl%3Dwww.atypodomainthatismisdirectedbyverisign.com/
cgi-bin/sub scribe.pl%253flist%253Dhorsebreeding%2526
email%253D%26host%3Dwww.atypodo mainthatismisdirec
tedbyverisign.com&s=1024x768&c=32&j=1.3&v=Y&k=Y&b
w=101 6&bh=530&ct=lan&hp=N&[AQE].

Some relevant links are:

- Data spills in banner ads

- SiteFinder privacy policy

- Omniture privacy policy

- Omniture company overview

- Electronic Communications Privacy Act

- Court draws a line for online privacy

By Richard M. Smith, Computer & Internet Security Expert

Related topics: DNS, Domain Names, Privacy

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

Re: SiteFinder Is Leaking Data Jim  –  Sep 23, 2003 4:38 PM PST

What IP adresses can be entered into a software firewall such as ZoneAlarm to prevent access to Verisign and it's minions? How do you id the spy cookie to delete? 

Re: SiteFinder Is Leaking Data Status Quo  –  Sep 24, 2003 12:45 AM PST

Jim,

From the command prompt/shell, type in the following:

# ping alksjdaksdj.com
— or --
c:> ping alksjdaksdj.com

The IP that this non-existant domain will resolve to (and all other non-existant .com and .net domains) is 64.94.110.11

So it may be possible to block HTTP request to 64.94.110.11 with your personal firewall (or with your router). You may also request that your ISP or employer block requests to this address.

A word of caution: Verisign could easily change the IP address for Site Finder at any time. The best solution is to have your ISP/employer ignore the Site Finder wildcard at the DNS level.

For businesses/ISPs running their own DNS, you should thank your stars that the ISC has already released a patch for BIND that'll allow you to block root level DNS wildcards. Check out http://www.isc.org/products/BIND/delegation-only.html
for information on configuring your BIND servers to ignore wildcards and thus ignore the Site Finder service.

Happy blocking.

- status quo

Re: SiteFinder Is Leaking Data Jon P.  –  Sep 26, 2003 8:16 PM PST

Hey, also to let you guys know of an easy way to block Verisign's monopoly of the internet is to edit your HOSTS file.

This file is found in the following locations:
Linux /etc
Windows 95/98/Me c:windows
Windows NT/2000/XP c:windowssystem32driversetc
c:winntsystem32driversetc

Copy and paste the following line to the bottom of this file.

127.0.0.1 sitefinder.verisign.com

If you don't have a HOSTS file juse open a text editor and save it as HOSTS with no extension in the appropriate directory.

Happy blocking these jerks. Boycott Verisign, Boycott Network Solutions (parent company)! Support Do-Not-Call registry. The general public hates telemarketers!

Re: SiteFinder Is Leaking Data BackupBob  –  Sep 30, 2003 5:32 PM PST

You MUST be kidding!

VeriSign is supposed to provide security and privacy.  If what you say is correct then VeriSign is doing just the opposite.

On the one hand VeriSign is making big bucks with their security services.  On the other hand they are making big bucks by capturing private information and passing it along to a marketing company.

I would like to refuse to use VeriSign's new Site Finder service because I do not agree with their terms and conditions (T&C). 

Unfortunately, I have no choice in the matter; I am dumped on their site against my will and being told that since I am there I must abide by their T&C. 

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

Top Level Domain Holdings Raises $14M for New gTLDs

.ORG COO Discusses Priorities With DailyVista, Pursuit of .NGO Domain

StarHub to Acquire '.starhub' New Top-Level Domain

ARI Registry Services Signs 21 Contracts in the First Week of New TLD Applications

MarkMonitor to Exhibit at Internet Tech Policy Exhibition and Reception to be Held on Capitol Hill

Sedari Signs With Dot Moscow Bidders

.ORG, The Public Interest Registry Welcomes Nancy Gofus As Chief Operating Officer

Minds+Machines Works with .bayern

The New Domain For Japan, JP.NET, Launches With Exclusive Invitation to Trademark Owners

Being a .PRO When Choosing a Registry Services Partner

UK Cabinet Office Looks to BlueCat Networks' Expertise and Best Practices for Securing PSN

Afilias Acquires Registry Services Corporation, .PRO

Thoughts on Applying for a Generic Top-Level Domain

Sedari Launches "Guess the Numbers Game" for New TLD Program

dot Brand Makes Its Debut: Afilias Advises Companies to Act Now for Successful TLD Applications

BlueCat Networks Helps Organizations Transition to IPv6 with HP

BlueCat Networks to Host Webinar on DNS, DHCP and IPAM Featuring Independent Research Firm

Facets of gTLD Registry Technical Operations - Registry Services

Technology and Finance Industries to Dominate New gTLD Applications

.CO Internet Selects Sedo to Broker Previously Unreleased .CO Domain Names

Hot Topics

Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines
Afilias

DNSSEC

Sponsored by
Afilias
dotMobi

Mobile

Sponsored by
dotMobi
Verisign

Security

Sponsored by
Verisign
Neustar UltraDNS

DNS

Sponsored by
Neustar UltraDNS