iFrame attacks: Blame your Web admin guy

With one new Web site compromised every 14 seconds, including some of the biggest names, it's almost impossible to tell what's a "trustworthy" Web site. But who's at fault for exposing Internet users?

Around 165,000 Web sites have been compromised in recent weeks, indicating a mass outbreak in the use of malicious iFrames to attack Internet users.

Just last week the input fields of several popular Web sites have been exploited to deliver iFrame attacks on potentially millions of visitors. By inserting HTML code into the search fields of the affected sites, the attackers have been able to launch iFrames which redirect users to Web sites hosting malware.

The attacks have targeted visitors to tech publication Wired.com, security firm Trend Micro and CNET Networks' own ZDNet Asia, according to security researcher Dancho Danchev.

By exploiting flaws in Web applications on the client side, such as RealPlayer and other lesser known media players, the attackers are able to push browsers to sites that host malicious content.

Similar attacks on PHP bulletin boards (PHPbb) have also exploded, according to security researchers at McAfee Avertlabs. Over the past week 200,000 PHPbb Web pages have been compromised, which McAfee researchers believes to be similar to the Santy worm attacks of 2004.

In 2004, Google managed to put a halt to the Santy worm -- malware which searched Google for Web sites that used a vulnerable version of the phpBB bulletin board software. Once the worm had infected one PHP bulletin board, it then used it as a launching pad to infect other vulnerable software.

"With the exploitation of PHP, we're not sure exactly what method may have been used, but we suspect it could be a SQL injection attack," senior McAfee security researcher, Nishad Herath, told ZDNet.com.au.

In just one hour last Friday afternoon, the number of PHPbb infections increased from 11,900 to 28,600 pages, Herath added.

"Depending on the capabilities of the Web server that is hacked -- in terms of the level of access an attacker has [in order] to modify the content -- the payload seems to differ. Sometimes it's just a Java script and others it's a malicious iFrame which hosts other malicious content," he said.

Security experts believe that preventing attackers from using malicious iFrames and PHPbb is a matter of validating input fields, for example, by making sure fields can only contain alphanumeric characters.

As well as preventing malicious iFrames, validating input fields could block complex phishing scams which manipulate Web pages to trick visitors into divulging personal information, according to Danny Allan, US director of security research at IBM Rational Software. Ninety percent of all phishing could be prevented if this process was done correctly, he said.

The fact that a Web server does not need to be fully compromised to be harmful to site visitors is also important, Sophos's chief technology officer, Paul Ducklin told ZDNet.com.au -- only a single line of HTML code is necessary to make the exploit work.

"People think the only way to threaten others is if malware infects the Web server in first place, but the bad guys don't need an active process on your computer if they can get static Web pages," Ducklin told ZDNet.com.au.

"The vast majority of affected Web pages are statically infected, so you're not actually dealing with active processes."

Because most malware is developed for Microsoft Windows while most Web servers are Linux machines running Apache, Web administrators mistakenly believe that this protects their servers and by default their site's visitors, said Ducklin.

Sophos's 2007 research also shows that 53 percent of all malware used malicious iFrames to exploit computer systems. The second most popular method was using hidden Java script, with nine percent.

Google's own researchers have also blamed the 300 percent rise in sites delivering drive-by downloads on poor security practices of Web administrators.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

RT @zdnetaustralia: Android fragmentation threw a spanner into Victorian Health's app strategy: http://t.co/4pkmnkMB ^LH

What Microsoft won't tell you about Windows 7 licensing http://t.co/Y2e6sXdI #Win7

#Android fragmentation steers Vic Health - @ZDNet Australia : http://t.co/chrmWl7B

RT @zdnetaustralia: Android fragmentation threw a spanner into Victorian Health's app strategy: http://t.co/4pkmnkMB ^LH

Android fragmentation steers Vic Health - ZDNet Australia: Android fragmentation steers Vic Healt... http://t.co/VTbMBy5A #android #news

by http://t.co/vmlLt4bh: Android fragmentation steers Vic Health: Fragmentation issues in Android were a key conc... http://t.co/wOmHdAav

Android fragmentation steers Vic Health http://t.co/CqTImM5l

Android fragmentation steers Vic Health - ZDNet Australia: Android fragmentation steers Vic... http://t.co/3ssDp1SW http://t.co/KpTZdvuO

Android fragmentation steers Vic Health: Fragmentation issues in Android were a key concern for the Victorian De... http://t.co/NnjPEqSu

Android fragmentation steers Vic Health http://t.co/jcB7UGer

Chrome beats Internet Explorer in global Web browser race | ZDNet http://t.co/7G7xMfJj

Android fragmentation steers Vic Health: Fragmentation issues in Android were a key concern for the Victorian De... http://t.co/HLdurfS5

Mining the social data stream for deeper customer insight | via @ZDNet http://t.co/x4xouPQh)

Android fragmentation steers Vic Health http://t.co/A6SJkfJw

Android fragmentation threw a spanner into Victorian Health's app strategy: http://t.co/4pkmnkMB ^LH

Android fragmentation steers Vic Health - Software - News - ZDNet Australia | @scoopit http://t.co/bpZN1EP8

http://comprareviagracl.com/#7836 bosentan sildenafil viagra naturale urgente ricetta viagra

53 minutes ago by Soobaqualay on Top alternatives to Microsoft Outlook

But this is the thing. There are still plenty of good-quality graduates whose skills can raise seasoned professional eyebrows... if they ...

57 minutes ago by techkid on Skills shortage: companies being too picky?

Govt CIO praises budget's $1bn IT investment - ZDNet Australia http://t.co/HqLE8HTK

Govt CIO praises budget's $1bn IT investment http://t.co/S7fxuowb

McAfee sees 'malware explosion' across desktop, mobile platforms http://t.co/3a8e1u61

I wouldn't have called Vista cheesy. Its GUI was pretty slick (and indeed handed on to Windows 7). It was, however, poorly implemented, h...

1 hour ago by techkid on Microsoft admits Vista was 'cheesy'

CIOview Govt CIO praises budget's $1bn IT investment - ZDNet Australia http://t.co/cn11RoxJ

Thanks Nelson, it should be right now.

-Michael.

1 hour ago by Mukimu on Ausgrid network to talk back to operators

Govt CIO praises budget's $1bn IT investment: Despite a tighter 2012-13 Federal Budget, the government's chief i... http://t.co/4sYpLvu8

Govt CIO praises budget's $1bn IT investment http://t.co/2vHl0Q7W

by http://t.co/vmlLt4bh: Govt CIO praises budget's $1bn IT investment: Despite a tighter 2012-13 Federal Budget, ... http://t.co/SBsAK839

Govt CIO praises budget's $1bn IT investment: Despite a tighter 2012-13 Federal Budget, the government's chief i... http://t.co/uB6PeV5e

Govt CIO praises budget's $1bn IT investment http://t.co/VyIAMrNZ

In praise of #Oracle #Virtualbox http://t.co/YokgSTAr -good enough to tide us #microsoft peeps over until #windows8 at least

beats by dre pas cher suisse casque beats by dre beats by dre solo ou studio casque beats by dre beats by dre quality review bea...

1 hour ago by ichfaheqnbia on Don't add Telstra deal to NBN cost: Quigley

Why don't the underpants of the lover of shock jock Adam Willis fit so well any more? http://t.co/0MHEGxLE

I guess the mouse was a necessary evil at the time. I mean, yes, keyboard shortcuts in the right hands are faster than any mouse action (...

1 hour ago by techkid on Microsoft admits Vista was 'cheesy'

Govt CIO praises budget's $1bn IT investment: Despite a tighter 2012-13 Federal Budget, the government's chief i... http://t.co/qTAJGRTl

fyi google may always lie

1 hour ago by rt luvs youh on Google shows we're killing our language

they probaly always lie about in4mation bout people

1 hour ago by rt luvs youh on Google shows we're killing our language

Despite a tighter 2012 Budget, the Federal Govt CIO has said IT is still an important factor, making up $1.5 billion. http://t.co/Qz5xuGu5

クリスチャンルブタンの靴は、ルブタン靴は以下から入手できます。香港から世界中ブティックや小...

1 hour ago by Zimernereen on Reservoir blogs: Fan fakes Tarantino diary

Govt CIO praises budget's $1bn IT investment - ZDNet Australia: Govt CIO praises budget's $1bn IT investmentZDNe... http://t.co/Co3DkOE8

Despite a tighter 2012 Budget, the Federal Govt CIO has said IT is still an important factor, making up $1.5 billion. http://t.co/idcuxOua

RT @zdnetaustralia: Now that Google has closed its acquisition of Motorola Mobility, what's next? http://t.co/er8mBa4g

by http://t.co/vmlLt4bh: Ausgrid network to talk back to operators: Ausgrid is rolling out upgrades to the electr... http://t.co/GWTVbrJH

The Ark Group Australia Daily is out! http://t.co/oIk1F9iK ▸ Top stories today via @SmartCompany @harleyw @zdnetaustralia

RT @johnW3LLS: #NSW Govt announces shopfront in Silicon Valley + 7 consortia to dev #mobile for public sector http://t.co/daWWcUAw #gov2au #govcampNSW

$6.7million, now we know the price to the tax payer of a government IT project clean up. You've got to ask the question don't you: why o...

2 hours ago by Takenforgranted on Vic scraps HealthSMART system

why some mp4 files with higher frame width can not be played in my 3m mp180??

2 hours ago by cyrusmann_ymail.com on 3M MP180 Pocket Projector

Unfortunately there is NO such place as Nelson's Bay. It's Nelson Bay!! Probably not your fault for the error, as your Media Release prob...

3 hours ago by Nelson on Ausgrid network to talk back to operators

@Wow - thats one of the benefits of the iPad (and tablets in general). They are one of the most generation neutral products ever made. ...

5 hours ago by Gav on Westpac board goes paperless with iPads

and why is this such a super idea? http://www.itnews.com.au/News/301778,thousands-affected-in-billing-cloud-breach.aspx oh, yeah, right...

5 hours ago by btone on Fed Govt steps up on shared cloud plan

Wow, seems like a fantastic initiative that helps to save the environment. It must have taken a lot of convincing to get the Board to mov...

6 hours ago by Wow on Westpac board goes paperless with iPads

I'm a payed up lib member who has voted Labor in the last 2 federal elections. I had the previlege of speaking to Mr Turnball 3 months ag...

6 hours ago by spazmanaught on NBN contracts may be left alone: Turnbull

Good to see Westpac's concentrating on the real IT issues !

6 hours ago by jeff_syd on Westpac board goes paperless with iPads

I am not sure how this issue becomes an attack on Mr Turnbull. But I guess he is fair game. In any event I would have thought a Ddos woul...

17 hours ago by Doubt on National Botnet Network coming: Earthwave

I still use 98SE. Windows ME was an abortion in a bucket and Vista was ME without the bucket. My screen may look boring, but I jumped str...

17 hours ago by Treknology on Microsoft admits Vista was 'cheesy'

This story has been voted 10 times in the last 24 hours!

17 hours ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

18 hours ago, Lenovo ThinkPad 3G tablet (32GB)

Well I don't know what they have done with their EFTPOS machines, local one in WA Coles Express I used this morning and I normally do "ch...

18 hours ago by harryinthesoup on Coles ditches PINs in payment pilot

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar