Infosecurity Europe 2007
Infosecurity Europe 2007
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Malware authors cut out attachments

Infected web pages now the attack du jour

Iain Thomson at Infosecurity Europe 2007, vnunet.com 26 Apr 2007
ADVERTISEMENT

Malware authors are shifting attack vectors from emails containing infected attachments to web pages embedded with malicious code, according to experts at Infosecurity Europe 2007.

Security firm Sophos is reporting that the traditional method of sending malware via attachment is now falling out of favour and that the authors can now bury the code in web pages and just send out links to that page.

"We are seeing an average of 5,000 infected web pages every day," said Graham Cluley, senior technology consultant at Sophos.

"Some days it goes as high as 20,000. Visit these sites, even if your browser is fully patched, and you run a risk of infection."

By exploiting vulnerabilities in the website server with a PHP attack or other technique, the malware author can imbed code in the site with little chance of detection.

Around 70 per cent of infected web pages are contained in legitimate sites from established companies.

"It is not just porn or gambling sites that are risky," said Carole Theriault, senior security consultant at Sophos.

"They are appearing everywhere, even in gardening sites. Content is no longer an indicator to risk."

PODCAST: Interview with Graham Cluley and Carole Theriault

See also:

HackingMalicious code writers target the web in earnest  25 Apr 2007
HackingCriminal switch from copycats into malware authors  16 Mar 2007
Spyware, adware and Trojan authors tap Ryder Cup zeitgeist  25 Sep 2006
One in 600 profiles host infection  10 Aug 2006

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Bristol, United Kingdom | Boeing
Sr. Software Architect, Bristol,  Competitive and Relocation Money Available Job Description: This position is for a Systems Analyst/SW Engineer for the Boeing Defence UK office in Bristol. The candidate will lead software development activities in ... more >
United Kingdom | Sumisho Computer Systems (Europe) Ltd
SAP Team Leader Sumisho Computer Systems (Europe) Ltd provide customers with a world of enhanced IT solutions. The role will consist of management of projects and application implementation. The candidate must be able to communicate ... more >
Buckinghamshire, United Kingdom | Grass Roots
Business Analyst x4, Aylesbury, Buckinghamshire, Excellent Salary + Benefits Grass Roots are one of the Sunday Times Top 100 companies to work for (2007 and 2008). Established in 1980, we're part of the Grass Roots ... more >
Maidstone, United Kingdom | Kent Police
  Forensic Computer Analyst - Police Headquarters, Maidstone, £27,891 - £38,476 Permanent Contract Digital devices and information communication technology are present in almost every investigation the police service undertakes. Kent Police Digital Forensics Unit is ... more >
More job opportunities