Infosecurity Europe 2007
Infosecurity Europe 2007

Malware authors cut out attachments

Infected web pages now the attack du jour

Written by Iain Thomson at Infosecurity Europe 2007

Malware authors are shifting attack vectors from emails containing infected attachments to web pages embedded with malicious code, according to experts at Infosecurity Europe 2007.

Security firm Sophos is reporting that the traditional method of sending malware via attachment is now falling out of favour and that the authors can now bury the code in web pages and just send out links to that page.

"We are seeing an average of 5,000 infected web pages every day," said Graham Cluley, senior technology consultant at Sophos.

"Some days it goes as high as 20,000. Visit these sites, even if your browser is fully patched, and you run a risk of infection."

By exploiting vulnerabilities in the website server with a PHP attack or other technique, the malware author can imbed code in the site with little chance of detection.

Around 70 per cent of infected web pages are contained in legitimate sites from established companies.

"It is not just porn or gambling sites that are risky," said Carole Theriault, senior security consultant at Sophos.

"They are appearing everywhere, even in gardening sites. Content is no longer an indicator to risk."

PODCAST: Interview with Graham Cluley and Carole Theriault

Tags:

Further reading

Special Report: Infosecurity Europe 2007

All the news from Infosec in London   More...

Golf sites fall into malware sand trap

Spyware, adware and Trojan authors tap Ryder Cup zeitgeist   More...

Social networks riddled with malware

One in 600 profiles host infection   More...

Total malware volumes grow 'dramatically'

Malicious code writers target the web in earnest   More...

Related articles

New malware-infected site found every five seconds

Experts warn of 'dramatic rise' in web-based threats   More...

Angelina Jolie 'nudes' fuel malware spike

Oldest trick in the spammers' book   More...

Cyber-criminals launch PDF malware offensive

PDFex storms into the charts   More...

Bogus Microsoft security bulletin hides Trojan

Malware writers use Redmond to spread malware   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

16 May 2008

2.97 MBXP on OLPC, broken dreams and Yahoo fights back More...

15 May 2008

3.28 MBDark fibre, mobile TV and solar power More...

14 May 2008

2.66 MBOnline inequality, mobile thumbprints and corporate raids More...

Poll

HOME WORKING

HOME WORKING

Do you let any or all of your employees work from home?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

OLPC

OLPC to ship with Windows XP

Microsoft teams up with One Laptop per Child project   More...

The Sims

The Sims goes flat-pack with Ikea

Virtual world gets Swedish wood   More...

Advertisement

Microsoft-Yahoo

Yahoo board fights back at Icahn

Investor accused of 'significant misunderstanding' in Microsoft saga   More...

MySpace

Woman charged over MySpace suicide

Lori Drew indicted on federal charges   More...

Advertisement