Hacking
Hackers are creating web pages that install and run malware automatically

Hackers turn to drive-by downloads

Organised crime exploiting browser vulnerabilities

Written by Robert Jaques

More than three million unique URLs on over 180,000 sites are automatically installing malware

Niels Provos Google Anti-Malware Team

Organised criminal hackers are waging a highly sophisticated war by exploiting vulnerabilities in end users' web browsers using drive-by downloads, security experts warn.

The extent of the threat was exposed in a recent Google Online Security Blog post and the 2007 Trend Statistics Report from IBM's X-Force.

"It has been 18 months since we started to identify web pages that infect vulnerable hosts via drive-by downloads, i.e. pages that attempt to exploit visitors by installing and running malware automatically," the Google blog stated yesterday.

"During that time we have investigated billions of URLs and found more than three million unique URLs on over 180,000 sites automatically installing malware."

Google's team also reported that around two per cent of malicious websites are delivering malware via advertising.

IBM reported recently that criminals are directly attacking web browsers in order to steal identities, gain access to online accounts and conduct other illicit activities.

Yuval Ben-Itzhak, chief technology officer at security firm Finjan, said: "Our research teams have already identified more and more criminal hackers using these techniques with a great success."

Tags:

Further reading

Users tricked by promise of celebrity porn

Phoney video used to push malware   More...

Microsoft pushes out 17 security fixes

'Critical' patches for Windows, Office and Internet Explorer   More...

P2P clampdown to fuel Wi-Fi hijacking

Digital pirates will steal connectivity to continue downloading   More...

Russia emerges as spam superpower

Dramatic rise in junk email from compromised Russian computers   More...

Related articles

Hackers turn to new genre of evasive attacks

Finjan report warns of malicious code 'affiliation networks'   More...

China accused of Trojan onslaught

Trail leads back to China-based operations including a government website   More...

Hackers unleash 'insidious' crimeware attack

Trusted websites turned into traps   More...

Hackers exploit widget security holes

Security firm warns of imminent danger   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

09 May 2008

2.51 MBWiMax muddle, Google tactics and asteroid bunkum More...

08 May 2008

3.26 MBBroadband Anywhere, phone-free transport and Web 3.0 More...

07 May 2008

3.19 MBUK success, a paucity of IT women and robot wars More...

Poll

DATA ENCRYPTION

DATA ENCRYPTION

Should encryption be mandatory for all personal data held by companies and governments?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Ofcom

Ofcom outlines future wireless vision

Wi-Fi healthcare and intelligent car brakes in the pipeline   More...

HP

HP Labs opens doors to academia

Innovation Research Program invites proposals related to current research   More...

Advertisement

Asteroid

Nasa plans manned mission to asteroid

Bruce Willis thankfully not going   More...

MySpace

MySpace offers opt-in data sharing

Deals signed with Photobucket, Twitter, eBay and Yahoo   More...

Advertisement