Iain Thomson at Infosecurity Europe 2007, vnunet.com26 Apr 2007
ADVERTISEMENT
Malware authors are shifting attack vectors from emails containing infected
attachments to web pages embedded with malicious code, according to experts at
Infosecurity
Europe 2007.
Security firm Sophos is reporting that the traditional method of sending
malware via attachment is now falling out of favour and that the authors can now
bury the code in web pages and just send out links to that page.
"We are seeing an average of 5,000 infected web pages every day," said Graham
Cluley, senior technology consultant at Sophos.
"Some days it goes as high as 20,000. Visit these sites, even if your browser
is fully patched, and you run a risk of infection."
By exploiting vulnerabilities in the website server with a PHP attack or
other technique, the malware author can imbed code in the site with little
chance of detection.
Around 70 per cent of infected web pages are contained in legitimate sites
from established companies.
"It is not just porn or gambling sites that are risky," said Carole
Theriault, senior security consultant at Sophos.
"They are appearing everywhere, even in gardening sites. Content is no longer
an indicator to risk."
Technical Hosting Engineer Location - Reading Job Description: This is an applications infrastructure and engineering role within the team. This role is primarily focussed on developing and evolving a quarantine application hosting service. The quarantine ... more >
Description: This vacancy is for an information security consultant to join EDS' Information Assurance team based in Hook. The successful applicant will provide information security support to one or more of EDS' major Defence projects. ... more >
London, United Kingdom | Royal Borough of Kensington and Chelsea
Web Content Manager - c.£40,000 plus bonus - London As one of the country's best-performing councils, we're always looking for new ways to improve on excellence. Providing an innovative, high-quality internet site for our ... more >
Central London, United Kingdom | MI5 Security Services
Messaging System Engineer - Competitive salaries + excellent benefits - Central London Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use your skills and experience to help ... more >More job opportunities