Web-based malware on legit sites soars

By Tom Espiner, ZDNet UK
Friday, June 06, 2008 08:23 AM

The amount of Web-based malware on legitimate sites has increased by over 400 percent since last year, according to security vendor ScanSafe.

In a security report entitled A comparative look at the state of Web security, May 2007-May 2008, released on Thursday, ScanSafe found 68 percent of all Internet-based malware was now being hosted on legitimate sites.

"The compromise techniques being used now allow hackers to quickly 'colonize' thousands of legitimate sites, from big brand-name sites, to smaller but equally legitimate sites," said Mary Landesman, senior security researcher at ScanSafe.

Techniques to compromise Web sites, including Iframe and SQL injection attacks, are becoming more ubiquitous, ScanSafe warned.

The fastest-growing category of threats hosted on the sites was backdoor and password-stealing malware, which increased 855 percent from May 2007 to May 2008. There was also a 220 percent increase in the amount of Trojans, viruses, password stealers and other malicious code being hosted on the Web, according to ScanSafe.

"Over the last year malware authors have moved away from direct attacks--attacks in which they directly interact with victims, via social engineering for example--to indirect attacks accomplished through compromised Web sites," said Landesman.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Storage-based compression and de-duplication overview

Enterprise Servers & Storage

Managing storage is always a challenge, so anything to simplify it is worth a look. Rick Vanover shares notes on storage-based compression and de-duplication.


Read more »



Do we need more delivery centers?

Blog thumbnail

As I wrote a while back in about "racing to subsidies", there certainly is an increased focus by governments to attract delivery centers to their region. To do that, many..... by Michael Rehkopf

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web