We have relaunched: What's new at ZDNet Asia?

Web-based malware on legit sites soars

Summary

Security vendor ScanSafe reports more than 400 percent increase in the number of compromised legitimate Web sites in the past year.

Events

The 2nd InfoSecurity Summit HK 2010
17 Mar 2010

Hong Kong Convention and Exhibition Centre, Hong Kong

IT Architect Regional Conference Singapore 2010
20 - 21 Apr 2010

Singapore Management University, Singapore

The Internet Show 2010
21-22 Apr 2010

Suntec Singapore

The amount of Web-based malware on legitimate sites has increased by over 400 percent since last year, according to security vendor ScanSafe.

In a security report entitled A comparative look at the state of Web security, May 2007-May 2008, released on Thursday, ScanSafe found 68 percent of all Internet-based malware was now being hosted on legitimate sites.

"The compromise techniques being used now allow hackers to quickly 'colonize' thousands of legitimate sites, from big brand-name sites, to smaller but equally legitimate sites," said Mary Landesman, senior security researcher at ScanSafe.

Techniques to compromise Web sites, including Iframe and SQL injection attacks, are becoming more ubiquitous, ScanSafe warned.

The fastest-growing category of threats hosted on the sites was backdoor and password-stealing malware, which increased 855 percent from May 2007 to May 2008. There was also a 220 percent increase in the amount of Trojans, viruses, password stealers and other malicious code being hosted on the Web, according to ScanSafe.

"Over the last year malware authors have moved away from direct attacks--attacks in which they directly interact with victims, via social engineering for example--to indirect attacks accomplished through compromised Web sites," said Landesman.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment
Transform your business interactions with real-time voice, video and telepresence solutions.
Tech Vendor: Cisco

ZDNet Asia Live

#Cisco #Cloud Aussie university joins Cisco cloud - Hardware - News: Curtin University of Technology working w... http://bit.ly/bnsSsA #TCN

31 minutes ago by thetechgang on topsy

#Cloud #News Google making it easier to leave Exchange - Zd Net Asia.com: Google's bid to get businesses on it... http://bit.ly/9rabRB #TCN

1 hour 12 minutes ago by thetechgang on topsy

it is not to good for china.
Proactol

1 hour 22 minutes ago by nathonastle on Chinese ad partners beg Google for information

Salesforce opens up Chatter developer preview - Zd Net Asia.com: Salesforce.com is giving 5,000 developers access ... http://bit.ly/9nOR0G

1 hour 31 minutes ago by collabotweet on topsy

RT @zdnetasia: HP touts new products and management and productivity tools to address business computing pain points. http://bit.ly/dudgA6

For those with a computer science background, or interested in the high performance computing scene: http://bit.ly/9vFC3i

HP touts new products and management and productivity tools to address business computing pain points. http://bit.ly/dudgA6

RT @VivianZDNetAsia: HP touts new products & management & productivity tools to address business computing pain points. http://bit.ly/dudgA6

2 hours 34 minutes ago by liruchan on topsy

** S'pore govt launches traffic Web app. http://www.zdnetasia.com/s-pore-...

the new look site is very nice @zdnetasia @zdnetaustralia

Big up to my peeps at www.ZDNet.com.au (and www.ZDNetasia.com and www.ZDNet.com.uk). Loving the redesign!

McAfee steps up cloud assurance - Zd Net Asia.com
http://www.zdnetasia.com/mcafee-...

Interesting take on social analystics. http://www.zdnetasia.com/blogs/w...

Singapore govt (LTA) wants to provide live parking data to third parties. http://bit.ly/90Fc0m

RT @jay_ro: Loving the new site and unified design! www.zdnet.com.au (also www.zdnetasia.com and www.zdnet.co.uk) /via @pastawoua

ZDNet Australia, Asia and UK re-launch on a unified platform - looking good. www.zdnet.com.au www.zdnetasia.com www.zdnet.co.uk

Loving the new site and unified design! www.zdnet.com.au (also www.zdnetasia.com and www.zdnet.co.uk) /via @pastawoua

RT @pastawoua: The new ZDNet is live, www.zdnet.com.au (also www.zdnetasia.com and www.zdnet.co.uk) yay for unified design

RT @zdnetasia: We've cut over to a new design. Check out www.zdnetasia.com!

RT @pastawoua: new ZDNet is live zdnet.com.au (also zdnetasia.com & zdnet.co.uk) yay for unified design / Congratulations, it's a milestone

Very good explanation of JMX

23 hours 28 minutes ago by Babith B on Managing applications with JMX

The reaction to a report issued Tuesday by Flurry Analytics managed to completely overlook some interesting news--the Android-based Motorola Droid outsold the original iPhone over the same period of time following their respective launches--to focus instead on the sales numbers for the Nexus One.

1 day 31 minutes ago by lonemavericks on diggs

Another ZTE story....

1 day 33 minutes ago by Moderate Your Greed on Philippines opens bid for final 3G license

We at www.fifosys.com have also seen a growth in IT outsourcing and anticipate it as a growing field.

1 day 6 minutes ago by sarah Jane on Companies' outsourcing spend to increase

I agree with you. The iSiVaL is super portable and TVs can't expand their image size. I recorded a video that might bring some ideas to...

1 day 37 minutes ago by Jesse B Andersen on Buying a projector? Try an LED TV instead

hermm... he deserved it.. he shud not talk abt sensitive things like tat, well, he shud think twice before saying all those things, event...

1 day 15 minutes ago by ... on Facebook user charged in Malaysia

Password manager tools are potential security threat. Criminals who hack into the computer can use the password manager to log onto any s...

1 day 15 minutes ago by ohanae on What defaults should random password generators use?

I've found the cross platform utility unetbootin to be rather handy for this kind of thing as well.

1 day 49 minutes ago by Jim on Use Live USB Creator to install Fedora 12 from a USB stick

Thanks for the article. I think the debug command has an "\" after "C:" it should say w32tm /debug /enable /file:C:\l...

1 day 50 minutes ago by Roger Biefer on Manage time accuracy with W32Tm

available in singapore now
http://www.portablemall.com.sg/goods-71-Microsoft+Zune+HD+32GB+-+Platinum.html

1 day 27 minutes ago by steve on Microsoft coy on apps for Zune HD

How about just using http://www.random.org/strings/? It is very configurable, satisfies all of the flexibility requirements you have ment...

1 day 32 minutes ago by Varun V Nair on What defaults should random password generators use?

Wi-Fi as the "Rodney Dangerfield of wireless", is a catchy metaphor, but it's already been used. In fact, it was the title of a...

2 days 31 minutes ago by Martin Suter on Selina Lo: Wired up for Wi-Fi in Asia

Dear Sir/Madam, I am Narasimha Rao.L. From bangalore India , i searching job in abroad , in electronics field, i have 6+ years exp....

3 days 33 minutes ago by Anonymous on Hot tech jobs in Singapore

Good article, computational aspect of acquired knowledge from the social platform is really questionable, given that there are a lot of p...

3 days 39 minutes ago by JN on What will social analytics say about your company?

The worlds most popular browser Firefox which has remained a stable trustworthy and secure product for many years now was today broken by...

4 days 50 minutes ago by Mitchell Krog on Mozilla aggressively asks older Firefox users to update