abednarz
Executive Editor

An unseemly marriage

News
Nov 7, 20056 mins

Porn sites and spyware go hand in hand on the Web.

Spyware used to worm its way into PCs when users tried to download a free utility, such as a screen saver, and wound up with an unexpected bonus after agreeing to the distributor’s license agreement.

Today most spyware infiltrations follow a different course: Users browsing the Web unknowingly launch “drive-by” downloads as they peruse sites affiliated with spyware makers. What those spyware-dumping sites often have in common is pornographic content.

“We’ve gotten to a point where, statistically, virtually all of the spyware that you get is being planted onto a system by browsing the Web,” says David Perry, global education director for security vendor Trend Micro. “The most available Web sites to undertake this kind of thing are those Web sites that are willing to do anything to make a buck off of you. And those have a tendency to be pornography and gambling sites.”

When users browse such sites, they wind up silently installing adware, keystroke loggers, Trojans and other nefarious programs. A person browsing pornographic Web sites from an unprotected machine could pick up 50 or 60 pieces of spyware in just 30 minutes, Perry says.

Habitual porn surfers can find their PCs quickly disabled from all the programs running in the background. The problem is so widespread among consumers that one computer repair consultant says the first thing he looks for when a customer complains of poor PC performance is pornography.

“Almost universally, it’s what the problem is,” says the consultant, who asked not to be identified. “A computer I just did had 36 instances of viruses and 700 pieces of malware installed. And gee, they wondered why their computer wouldn’t work. Absolutely it’s porn-related.”

It’s a problem that’s not limited to private PCs. In corporate settings, a growing percentage of help desk calls are associated with spyware, says Richard Stiennon, vice president of threat research for anti-spyware vendor Webroot Software and a former Gartner analyst.

When Webroot uses its auditing tools to discover a corporation’s threat exposure, “we’ll find 55% of machines have adware or spyware, about 4% will have keystroke loggers, and 7% to 12% will have Trojans on them,” Stiennon says. “These are companies that have anti-virus at the gateway, on the desktop and at the mail server, and they still get infected.”

One reason companies are behind in the battle against spyware is that they failed to recognize it was a problem until about 12 months ago and now they’re playing catch-up, Stiennon says. There’s a lot to keep up with: Webroot discovers and writes signatures for 300 new spyware variations every week, he says.

Meanwhile, corporate users continue to invite spyware and other threats by surfing inappropriate sites. Reconnex, a start-up that offers corporations risk-management software and services, reports in its latest threat index that 89% of companies that took Reconnex’s 48-hour risk assessment found inappropriate content on user PCs.

Delta Consulting this spring surveyed 50 of the 500 largest U.S. firms and found half formally dealt with the discovery of illicit images in the workplace during the past 12 months. Of those firms that pursued an investigation, 44% removed an employee from the company and 41% took other disciplinary action.

Illicit intentions

URL filtering is one way to reduce corporate exposure to pornography-related spyware – plus it can help reduce unproductive Web browsing by employees.

By blocking gambling, pornography and “other sites that have no business in a business,” companies can reduce the quantity of spyware attempting to enter their environments by about half, says Bob Hansmann, senior product marketing manager at Trend Micro.

But URL filtering alone isn’t enough. For one, the number of undesirable sites keeps skyrocketing. Thousands of pornographic sites are created every week, analysts say.

In addition, while the Internet is the most likely way users will access pornographic images, it’s by no means the only avenue. Illicit material can make its way to desktops and notebooks via CDs, memory sticks, mobile phones, digital cameras and MP3 players, says Andy Churly, vice president of marketing at PixAlert.

PixAlert’s technology monitors image files that reside on a company’s network and scans users’ desktop screens to see if what’s being viewed is of an illicit nature. The software analyzes skin tone, curvature and background settings, for example, and it can block or blur suspicious images before users see them.

PixAlert has found users will go to great lengths to circumvent corporate policies that prohibit viewing and distributing inappropriate content. One familiar tactic is to embed pornographic images inside innocuous-looking documents. “We regularly come across images that are embedded inside PowerPoint and Word documents, and even an Excel spreadsheet,” Churly says.

“They’ve been quite industrious, and ingenious in some cases, on the ways of actually getting images in through company gateway blocking. Once images are introduced behind the gateway, then they can be proliferated with impunity,” he adds.

Kevin Cheek, vice president of marketing at Reconnex, has seen similar efforts to circumvent URL-blocking technologies. One user in a large healthcare company went so far as to install a Citrix server to bypass his company’s Web proxy, Cheek says. Reconnex was assessing the company’s compliance with healthcare privacy regulations when its technology exposed the rogue server, which the employee was using to download inappropriate content, among other things.

Not only do such practices invite security threats, they also expose companies to potential sexual harassment lawsuits, negative publicity and even criminal violations if a company is found to have been negligent in preventing employees from downloading or distributing illegal material. “Corporate officers can be held vicariously liable if negligence is proven,” Churly says.

Overt use of monitoring technology is one way for companies to deter improper surfing and downloading habits. If users can see that an image has been flagged as inappropriate, many will cease the behavior, Churly says. “That prevents most people from transgressing. Only those who have become habituated to surfing for porn will continue to try to beat the system.”

Some employees caught red-handed simply continue the abuse. Reporting features built into Webroot’s software can quickly identify the most spyware-prone users, and many are repeat offenders, Stiennon says. “Those guys jump right to the top. They get reinfected every day,” he says.

It’s about compulsion, some say. “Certainly there’s a growing body of evidence saying that [Internet pornography] is addictive in nature,” Churly says. “Some employees can spend several hours a day just surfing for illicit material.”

abednarz

Ann Bednarz is the executive editor of Network World. Ann is a longtime IT journalist and has spent 26 years writing and editing for Network World, where she has worked as a news reporter, managed product testing and reviews, and developed features and how-to articles for an audience of network professionals and data center managers. Over the last two years, she has conceived and edited award-winning content for Network World that includes 2025 Jesse H. Neal Award finalists, 2025 Azbee Award regional winners and national finalists, and 2024 Eddie & Ozzie Award finalists.

Ann holds a bachelor’s degree in architecture and spent the early part of her journalism career writing about architectural design and construction. In her free time, she keeps those skills alive through DIY projects.

More from this author