Blogging sites that fail to check software stored by users are proving useful to hackers, according to web monitoring firm Websense.
The company claims to have identified hundreds of cases of hackers using blogs to store Trojan software and other malicious code, because blogging firms seldom check to see what code they are hosting.
"Blogs allow you anonymously and freely to gather and create accounts," said Dan Hubbard, senior director of security and technology research at Websense.
"Most have quite a bit of hosting space available too. Some blog site hosters allow you to post attachments, but most do not check the code that is posted so it could be anything."
Hubbard explained that hackers exploit blogs in a number of ways. In March a hacker placed key-logging software onto a blog site. The URL was then spammed out purporting to be a message from a popular messaging service.
The message offered a new version of an instant messaging program, but when users clicked on the link the key-logging software was installed.
A more advanced technique is to use a blog page to store malicious code updates. Many so-called zombie PCs update the Trojan software regularly, and a blogging site offers an anonymous and free website that can be used to store the update software.
Both methods use browser attacks, which experts warn are becoming increasingly popular. These attacks bypass firewall and intrusion detection software by entering systems through improperly patched browsers.
About EDS EDS provides a broad portfolio of business and technology solutions to help its clients worldwide improve their business performance. EDS' core portfolio comprises information-technology and business process outsourcing services, as well as information-technology ... more >
Sutton, Surrey, United Kingdom | Royal Marsden Hospital NHS Trust
The Royal Marsden NHS Foundation Trust is a centre of excellence for research, development, education and care in the treatment of cancer. Analyst Programmers, Band 6, £23,458-£31,779 plus 15% HCAS, Sutton, Surrey We are ... more >
South West, Darlington, United Kingdom | University College Falmouth
Web Sharepoint Development Manager, £23,692-£26,665 (£29,138) per annum (Grade 5) The creation of a new University for the Arts in the South West has taken a major step forward with the merger of University ... more >
London, United Kingdom | University of London (Institute of Education)
INSTITUTE OF EDUCATION University of London Systems Administrator (London Knowledge Lab) Computing and Media Support Salary in the range £28,290 - £33,780 per annum, plus £2,323 London Allowance Job share considered We are seeking to ... more >More job opportunities