Warning on web 'super worm'

XSS database could cause major problems

Written by Iain Thomson

Security specialists have warned that internet users could be facing a major worm outbreak spread via weaknesses in current browser technology.

A 'creative hacker' organisation known as GNU Citizen has published details of cross-site scripting (XSS) flaws that could be used to inject malware into computers via a web browser.

The worm could scan IP addresses for vulnerable pages and then spread quickly across the internet.

These flaws are have been gathered in an online archive, XSSED.com, that could be used by malware writers to identify vulnerable sites.

A permanent malware spamming program could spread viruses across the internet by setting up a continuous link to the vulnerable site.

"XSSED.com has the largest archive of real, fully working, XSS vulnerabilities available today," said a site poster known as 'pdp'.

"They even have a list of XSS vulnerabilities found in websites ranked 500 and below. We are talking about high profile websites here."

The only limiting factor would be the ability of the online database to handle the traffic.

"A super worm of this kind could have potentially devastating consequences in the very near future," said Pete Simpson, Threatlab Active manager at Clearswift.

"The technology exists and the key question is one of motivation. A multitude of easy targets within web 2.0 social networks must certainly be attractive to organised crime."

Tags:

Further reading

Websites wide open to attack

Study finds average of 66 flaws in online apps for every website   More...

Month-of-bugs project targets MySpace

Tongue-in-cheek campaign finds flaws in social networking site   More...

Online apps facing barrage of attacks

Abundance of custom code turn online apps into attractive target   More...

Adobe Reader hit by cross-site scripting flaw

Vulnerability could allow malicious code to be tied to files from trusted sites   More...

Related articles

Hackers step up website attacks

Security forecast for 2008 makes grim reading   More...

McAfee paints grim picture for 2008

Huge rise in web 2.0 attacks and smarter botnets   More...

Storm clouds gather again

Reports of death exaggerated   More...

Hackers step up search results attack

Big-name sites compromised in IFrame redirect scam   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement