- Bank Web sites full of security holes
- SCO Group: Its future is all used up
- Maligned feature being added to IPv6
- I returned my iPhone 3G after six days!
- VPNs: Six burning questions
News | Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:App Performance | On Demand Security | Networking Solution | SOA | Value of WDS
In last week's newsletter, we began looking at a report from Google (see All Your iFrames Point to Us in the Google blog) in which researchers reveal the depth of the worldwide malware problem. For 10 months in 2007, Google captured data and studied how malware gets from servers it calls “distribution sites” to your PC using an obfuscated yet sophisticated network of compromised landing pages and hand-offs to relay sites. Web surfers go to a seemingly benign Web site, and without their knowledge or permission, they are transported to other Web sites that deliver malicious payloads.
Even innocent Web surfing can be hazardous these days, and it is steadily becoming more dangerous. In April 2007, less than .4% of the incoming search queries to Google’s search engine returned at least one link to a malicious site. By January 2008, this figure has risen to 1.3% of the search queries returning at least one link to a malicious Web site.
It’s not hard to understand why the trend is increasing when you see how easy it is for hackers to seed the search results with compromised content on otherwise benign Web sites. For instance, one way that hackers take control of benign Web pages is through third party contributed content (e.g., blog posts, forum discussions). It is relatively easy for a hacker to embed a link to a malware distribution site in content that they, themselves have posted.
Web-based ads are another source of compromise. On average, 12% of the overall search results that returned landing pages that were associated with malicious content were due to unsafe ads.
The report explains how it happens: “Today, the majority of Web advertisements are distributed in the form of third party content to the advertising Web site. This practice is somewhat worrisome, as a Web page is only as secure as its weakest component. In particular, even if the Web page itself does not contain any exploits, insecure ad content poses a risk to advertising Web sites. With the increasing use of ad syndication (which allows an advertiser to sell advertising space to other advertising companies that in turn can yet again syndicate their content to other parties), the chances that insecure content gets inserted somewhere along the chain quickly escalates. Far too often, this can lead to Web pages running advertisements to untrusted content. This, in itself, represents an attractive avenue for distributing malware, as it provides the adversary with a way to inject content to Web sites with a large visitor base without having to compromise any Web server.”
what are the benefits of project management - Anonymous
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.
Download the white paper.
Unauthorized applications: Taking back control
Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?
Download the white paper.
Comments (1)
Symantec ISTR concurs: beware the WebBy Linda Musthaler on April 10, 2008, 12:22 pmIn early April, Symantec published its semi-annual horror story, Internet Security Threat Report, Trends for July–December 07, Volume XII. (Read the shorter executive...
Reply | Read entire comment
View all comments