Information Age: News, analysis & insight for IT & business leaders

Most of the web's biggest sites are unsafe

15 September 2009  

Web security vendor finds 61 of the 100 most popular websites to be hosting malware or redirecting to malicious sites

The majority of the web's most visited sites pose security threats, according to research by security vendor Websense. The research found that 61 of the Internet’s top 100 sites were either hosting malicious content or containing a masked redirect to a malicious website in the last year.

The number of malicious web sites on the Internet has grown almost 700% on the same time last year, and 77% of these are legitimate sites that have been compromised by malicious code.

The study found many of these breaches were the result of three large-scale SQL injection campaigns, named Gumblar, Beladen and Nine Ball, which utilised ‘drive-by’ exploits to install Trojan downloaders on more than 40,000 legitimate web sites.

Botnet-based SQL injection attacks have become increasingly popular ever since the Asprox botnet demonstrated that automating a relatively low-level ‘script-kiddy’ attack could be very successful.

Such attacks send database commands to servers through poorly-coded entry fields on web pages. The servers are typically instructed to download and execute a malicious program, which then steals data from or serves ads to visitors to the legitimate website.

Websense also reported that the total volume of email containing viruses increased 600% in the month of June. In addition, the automated submission of blog and forum comments containing links to malicious web pages was increasingly popular; the security firm estimated 95% of all user-generated comments are spam or malicious.
 
 


Comments 

There are currently no comments on this article

People who read this also read...

EC’s fears for MySQL holding up Oracle / Sun deal

Reports say the EC may demand that the open source database is spun-off before granting Oracle’s proposed acquisition anti-trust approval

Microsoft previews web-based Office

Software giant makes long-awaited response to Google Apps available for public testing

Jailed cyber criminal takes over prison computers

Incarcerated credit card bandit changed prison system passwords after being given programming job

Wigan Council condemned for losing details on 43,000 students 

Wigan Council's loss of personal information on 43,000 students highlights the need for encryption and staff training, says Information Commissioner's Office.

Wal-Mart phishing fraudster pleads guilty

A 30-year-old Sacremento man has pleaded guility to defrauding Wal-Mart stores using identities stolen through phishing attacks

 

White Papers

Read article

'Think Lean' When Developing Management System Documentation

Learn how to efficiently and effectively implement a document management system for your organization.

Read article

11 Hiring Trends for 2011

In this document, you'll get the insider info you need to give potential employers what they want and beat your competition in 2011. You'll learn about the most valuable certifications and the game-changing skills that can lead to more job security and stability.

Read article

12 Hiring Manager Secrets to Getting the IT Job You Want

Learn how you can make yourself a more attractive candidate now with PrepLogic's free 12 Hiring Manager Secrets to Getting the Job You Want.

More
Advertisement
div class="banner">