All the latest UK technology news, reviews and analysis

Nine ball attack was 'overstated'

by Phil Muncaster

More from this author

20 Jun 2009

Be the first to comment

  • Tweet this
hacker
The Nine Ball attack could be less dangerous than at first thought

Security as a service firm ScanSafe has poured cold water on claims that the so-called 'nine ball' attack discovered earlier this week compromised over 40,000 legitimate websites.

In a blog posting on Monday, security vendor Websense claimed that it had detected a "large mass injection attack" in the mould of Beladen and Gumblar.

“We’d been monitoring Nine Ball 'sleeping' for couple of weeks before it woke up," said Websense threat manager Carl Leonard.

"In its dream state it benignly redirected users to a search engine, almost as a decoy. But a couple of days ago the alarm clock went off and now it sends the user on a series of redirects to malicious sites.

"The attacker records the visitor's IP address so, once the damage has been done, the user can be recognised. If they visit one of the 40,000 infected sites again, they're benignly redirected to a search engine once more."

However, writing on the ScanSafe blog in response, senior security researcher Mary Landesman said the attack was almost "non-existent". She argued that ScanSafe's data indicated that the total number of requests to sites involved in the attacks is 333, while the number of compromised sites is just 62.

ScanSafe also looked at the popularity of the compromised sites and found them to have very low ratings, according to web information company Alexa.

"Our view is also shaped by the fact that we see well over a thousand unique web attacks every month, some that are big like Gumblar and some that are very small like 'nine-ball'," she wrote.

"From our unique perspective, 333 requests involving 62 compromised web sites is certainly not something we would brand a 'massive injection'."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Oracle Appplications Support - HR and Payroll

Position:Oracle Applications eBusiness Suite Suport...

Developer

Software Developer A leading UK Software Application...

Senior Drupal Developer - PERM - £55K - URGENT

I am looking for a permanent senior Drupal Developer...

Retail Consultant - Data Transformation and Migration

Retail Consultant - Data Transformation and Migration...

To send to more than one email address, simply separate each address with a comma.