Superguide: the death of 'trusted' Web sites?

The explosion in drive-by download attacks continues to grow. How has the situation got so dangerous? Are there any "trusted" Web sites left?

In May 2007, Google joined the security community in warning users about the threat from drive-by download attacks, which is where users' computers are infected with malware when they visit an affected Web site.

By February 2008, the number of drive-by download attacks had increased by 300 percent and showed no signs of abating. Google's researchers investigated billions of URLs and found more than three million unique URLs on over 180,000 Web sites were attempting to automatically install malware.

The drive-by download phenomenon has destroyed the concept of a "trusted" Web site. In the first half of 2007, Sophos claimed to have discovered around 30,000 malicious Web sites appearing every day. Only 20 percent of these were actually run by the criminals deploying the malware -- the rest were genuine, and previously "trusted" sites that had been hacked by criminals to deliver their malware.

"It's no surprise to see legitimate Web pages targeted for these attacks," said Carole Theriault, senior security consultant at Sophos. "Businesses generally aren't too strict about stopping their employees accessing these Web sites, while the sites themselves will already have their own daily flow of user traffic, saving hackers the trouble of trying to entice unenlightened Web surfers."

The appearance of toolkits, which makes it a simple process turning any Web site into a malicious one, has exacerbated the problem.

The best-known toolkit, Mpack, uses cross-site scripting to place malicious iframes on legitimate Web sites. Iframes are used by Web designers to open additional windows (often hosted on other sites) within a main Web page; iframes can also be used by criminal hackers to redirect browsers to malicious-code sites.

The criminals perpetrating these attacks rely on users stumbling on a site that contains their malware with unpatched browsers, operating systems and applications.

Unfortunately, the sheer volume of software on the average PC makes it near impossible for the majority of users to remain completely safe from such attacks.

Sites that have recently been discovered dishing out malware to unsuspecting surfers include The Sydney Opera House, The Bank of India, Facebook, MySpace and at least ten of the AFL team Web sites.

ZDNet.com.au has compiled this guide to help you understand, and better deal with, the threat from drive-by downloads.

Web sites and applications that have been attacked

  • Bank of India is hacked and dangerous

    Security experts are warning Bank of India customers to steer clear of its official Web site because it is serving up several information-stealing Trojans.

  • AFL teams a danger on the Web: Google

    Google has flagged the Web sites of 10 Australian Football League (AFL) clubs as potentially dangerous, preventing visitors from accessing the teams' sites via the search engine.

  • Sun denies Java patch release put billions at risk

    Sun has denied its staggered patching schedule for a recent Java flaw put billions of devices at risk.

  • Patch or get PWNED in a flash

    Recently fixed vulnerabilities in Sun's Java Runtime Environment and Adobe's Flash player mean that unpatched systems are vulnerable and could be infected with spyware or recruited into a botnet by simply visiting a Web page with exploit code -- and Google last month warned that 10 percent of Web sites contain this kind of malicious code.

  • Don't fear Sydney Opera House trojan

    The Web site of the Sydney landmark has been found to harbour malware but it has been described as an "irritant" rather than a "major security risk".

  • Cursor flaw gives Vista security a black eye

    Microsoft's release of a "critical" patch on Tuesday poked holes in Vista's security promises, but security experts advise against discounting the new operating system.

  • Skype fixes critical security flaw

    Skype has fixed a critical security hole in the latest version of its Windows VoIP software, which could have allowed specially crafted Web sites to load and run malicious code on victims' PCs.

  • Security product had 60 flaws after being patched

    Vulnerability-testing company Secunia has slammed one security vendor for having "inherent code problems" in its backup and antivirus software.

Related News

  • iFrame attacks: Blame your Web admin guy

    With one new Web site compromised every 14 seconds, including some of the biggest names, it's almost impossible to tell what's a "trustworthy" Web site. But who's at fault for exposing Internet users?

  • "Trusted" Web sites can no longer be trusted

    Restricting your Web surfing to "trusted" sites is no longer enough to keep your machine safe from malware, according to security experts.

  • Web attackers get better at hiding

    Cybercrooks who rig Web sites to break into PCs are getting better at hiding their malicious code, a security expert said this week.

  • Single-line attack infects thousands of Web sites

    Thousands of Web sites have fallen victim to an attack using just one line of code that maliciously re-directs browsers via Javascript to servers that are hosting a variety of drive-by exploits. Multiple browsers and operating systems are affected by this code if not correctly patched.

  • Hundreds of sites hit with dynamic malware

    In January of 2008, ScanSafe reported that it had discovered more than 200 UK-based Web sites that were using malicious javascript to place trojans and rootkits onto victims' machines.

  • Malware Web sites: now 30,000 a day

    Security experts demand more vigilance by Web-hosts to curb the explosion in malware-infected Web sites, which are appearing at a rate of 30,000 per day, according to Sophos.

  • Web-borne security attacks explode

    Internet-borne security threats have taken over the mantle as a greater risk to companies' security than e-mail attacks, according to security vendor Sophos.

  • Cyberattacks outstripping defences

    Cyberattacks today have become so complex that there may be no real way to completely protect against them, internet security researchers have warned.

Go to next page for related feature articles and Whitepapers.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

Just remember that Google haven't broken any laws here, they're just doing what all their other multinational competitiors do; minimise t...

10 minutes ago by Pachanga on Much ado about Google's tax

ルイヴィトン バッグ : http://www.lovebagjp.com/ Louis Vuitton bags, Louis Vuitton pretension nose about,Louis Vuitton daydre...

28 minutes ago by bundLourb on Reservoir blogs: Fan fakes Tarantino diary

シャネル バッグ : http://www.bagssalejp.org/ Chanel trap,chanel shekels,gucci bags,direct purse,poor recent Louis Vuitton keep...

2 hours ago by bybrinkLync on Reservoir blogs: Fan fakes Tarantino diary

I guess but in both cases, dead body!

12 hours ago by Doubt on National Botnet Network coming: Earthwave

I think it's for the very reasons you mention in your first paragraph that there is no CBA. With the ideological differences and vested ...

12 hours ago by RealismBias on NBN cost-benefit analyses are so 2011

Good points; but how do you establish consensus about the terms of reference of a cost-benefit analysis? What is to be included? How far ...

13 hours ago by Gwyntaglaw on NBN cost-benefit analyses are so 2011

I live in a small country town & have done since 2002. When I got to this town it had no mobile phone & no broadband. The only reason w...

13 hours ago by fibretech on Regional review highlights NBN, mobile

Hi there, just became alert to your blog through Google, and found that it is really informative. I am going to watch out for brussels. I...

13 hours ago by Uttedsips on Fujitsu Stylistic ST5011

Like most things in life, the devil is in the details. If a cost benefit analysis included a societal element, I'm certain nobody on eit...

14 hours ago by RealismBias on NBN cost-benefit analyses are so 2011

The coalition has done nothing else but keep changing their view over the last 2 years. -first it was "there is nothing wrong with the ...

14 hours ago by djz on NBN cost-benefit analyses are so 2011

Use the force Luke... FFS

14 hours ago by Beta on Regional review highlights NBN, mobile

michael kors outlet http://www.michael-kors-discount.com/#5923

14 hours ago by michael kors bag on Best iPhone travel apps

Hey butterflyeffecs and lex, Sorry you're not fans of this piece. But you're dead right in that it is the thoughts and experience of a se...

14 hours ago by LHopewell on Android fragmentation steers Vic Health

teen cams
http://www.aloe-vera.cz handjob

14 hours ago by MyncWenry on Fusion-io ioDrive (80GB)

We have fashional replica bags designer .Replica luxury bags sale here are perfect compromise of quality and price. The replica handbags ...

15 hours ago by Machelle on Telecom NZ CEO Paul Reynolds to leave

It's not a question of whether anyone at HSU would know how to do this, but whether they would have connections with people who could. T...

15 hours ago by meski on CT, phone clone

Fred, I can tell you what the difference between FTTN and FTTH is. FTTH means we will be developing technology and services that we sell ...

15 hours ago by andye on NBN FUD: will Abbott ever learn?

You are 100% right – Abbott is a paragon of tenacity. Now if he could only try that hard to get Malcolm Turnbull's phone number, we co...

15 hours ago by braue on NBN FUD: will Abbott ever learn?

Very interesting to hear Ben and thanks for providing some real-world examples. I suspect the NBN has actually improved things for a grea...

15 hours ago by braue on NBN FUD: will Abbott ever learn?

Hi Geoff, my opening paragraph simply suggests that the leader of the opposition party would rightfully be turning to his communications ...

15 hours ago by braue on NBN FUD: will Abbott ever learn?

This story has been voted 12000 times in the last 24 hours!

18 hours ago, Is Bill Gates a great leader?

This story has been voted 10 times in the last 24 hours!

2 days ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

2 days ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar