All the latest UK technology news, reviews and analysis

Unchecked blogs a boon to hackers

by Iain Thomson

15 Apr 2005

Be the first to comment

  • Tweet this

Blogging sites that fail to check software stored by users are proving useful to hackers, according to web monitoring firm Websense.

The company claims to have identified hundreds of cases of hackers using blogs to store Trojan software and other malicious code, because blogging firms seldom check to see what code they are hosting.

"Blogs allow you anonymously and freely to gather and create accounts," said Dan Hubbard, senior director of security and technology research at Websense.

"Most have quite a bit of hosting space available too. Some blog site hosters allow you to post attachments, but most do not check the code that is posted so it could be anything."

Hubbard explained that hackers exploit blogs in a number of ways. In March a hacker placed key-logging software onto a blog site. The URL was then spammed out purporting to be a message from a popular messaging service.

The message offered a new version of an instant messaging program, but when users clicked on the link the key-logging software was installed.

A more advanced technique is to use a blog page to store malicious code updates. Many so-called zombie PCs update the Trojan software regularly, and a blogging site offers an anonymous and free website that can be used to store the update software.

Both methods use browser attacks, which experts warn are becoming increasingly popular. These attacks bypass firewall and intrusion detection software by entering systems through improperly patched browsers.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

36%

2%

12%

50%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Lotus Notes Domino Administrators

Lotus Notes Domino Administrators Due to the expansion...

Account Manager / Project Manager - Saas Accounting Financial Software

Account Manager / Project Manager - Saas Accounting Financial...

Channel Account Manager

Channel Account Manager One of the UK's most innovative...

Incident and Problem Manager

My client is looking for an Incident & Problem Manager...

To send to more than one email address, simply separate each address with a comma.