Information Age: News, analysis & insight for IT & business leaders

 
8 January 2009

Cyber-crime goes SaaS

29 February 2008  

On-demand application for identity thieves emerges

Security vendor Finjan has identified a website that allows users to access the secure .FTP sites of 8,700 organisations – including Fortune 500 companies and high profile websites – and inject malicious code with a few clicks of the mouse.

Along with the usernames and passwords for numerous FTP sites, visitors to the site were granted remote online access to an application called NeoSploit. This can inject a number of Trojans and other malicious code into a website’s underlying code, using so-called iframes.

The site has been compared to legitimate software-as-a-service applications such as Salesforce.com in its design and modus operandi. The discovery illustrates the ease with which systems can now be compromised in order to steal identity information.

Authorities in Hong Kong, where the URL was registered, have now blocked the site, although it could easily re-emerge at another destination. According to Finjan, much of the text on the site was in Russian.

Further reading

Anti-virus vendors: Fighting a losing battle Anti-virus vendors are struggling to keep up with the new methods of propagating malware

Securing the future Central identity management systems are now a chief priority, but biometric technologies continue to disappoint

Find more stories in the Security & Continuity Briefing Room


Comments 

There are currently no comments on this article

People who read this also read...

 
Advertisement

White Papers

Read article

10 Reasons Why Your Email is More Secure in a Hosted Environment versus an In-House

IT Services

Take an in-depth look at the security risks associated with complex business email configurations and how hosted email solutions stack up.

Read article

3 Steps to Creating Personalized Customer Support Experiences

Information Management

Learn how tailoring support interactions to fit the specific circumstances of an account can not only increase customer satisfaction, but also increase revenue.

Read article

4 Key Steps to Automate IT Security Compliance

IT Services

A unified approach for IT, audit and operation teams.

More