Web Security Projects and Demos @ NaN

Under PIs Menczer and Jakobsson, NaN and cybersecurity folks collaborate on a number of Web security and privacy-related projects. Here is a sample, especially public demos.

Social Phishing

We conducted a study to show how easy it is to trick people into releasing their secrets to strangers, by exploiting their social vulnerabilities. We mined public friendship information from social network websites. 72% of victims who thought they received a message from a friend, disclosed their passwords. The results are published in Communications of the ACM (October 2007). Talk given at a SOUPS 2005 panel and CACR.

Gossip Engine

This demo shows that fraudsters can make money from ads by generating fake content that looks real enough to search engines and appears original enough to lure people into clicking. This kind of click fraud may not be illegal, but it pollutes the Web.

Phroogle

This demo illustrates how one can exploit comparison shopping engines to bait victims into disclosing their credit card or bank account numbers. Try it, it's safe! (Case study in Phishing and Countermeasures.)

Email Cluster Bombs

Web forms for email subscriptions can be harvested and exploited to launch DDoS attacks. We demo this attack and illustrate how to defend from it. Published in login.

Riddle

Could your browser release your personal information without your knowledge? Find out by solving this riddle! (Case study in Phishing and Countermeasures.)

Poll of the Day

This demo is intended to show that online polls and ratings are unreliable, and that third-party cookies can be tricky.