All the latest UK technology news, reviews and analysis

Web site owners warned of growing attacks

by Phil Muncaster

More from this author

09 Dec 2008

Comment: 1

  • Tweet this
Hacker
Many sources of infection are caused by legitimate sites being hacked

Web site owners should accept more responsibility for securing their sites against attack, as Sophos has revealed today that it identified one new infected web page every four and a half seconds during 2008.

The security vendor's annual Security Threat Report found that many sources of infection are caused by legitimate sites being hacked, often via the increasingly popular SQL injection attack in which malicious code is inserted into the database running a site.

Better patching and hardened web code will remove some of the risks, argued Sophos senior technology consultant Graham Cluley.

"Nowadays if you're running a web site of any size you're effectively a software publisher, because you're putting up things, perhaps in PHP, which may have vulnerabilities in them," he said.

"You must ensure that you take responsibility. You have to think differently if you're in e-commerce now."

Sophos also reported a five-fold increase in malicious email attachments during 2008, and predicted that hackers would increasingly attach " booby-trapped" versions of non-executable files like PDFs and Word documents, because users are more likely to open them.

Sophos also "named and shamed" the US for being the number-one host of malware, at 37 per cent, and being home to the largest number of spam-sending PCs.

"When the internet community gets together [as with McColo] things seem to get better for all of us," he said. "But the main problem is the home user population [in the US] is poorly protected, so we need better education of home users and businesses."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Oracle Apps DBA

Our global consultancy client currently seeks a number...

Support Analyst x 1/2 (Apple Mac OSX/Windows) - Bristol/Bath

Support Analyst x 1/2 Skills: Apple Mac OSX, Windows...

Network Consultant - London - 55-65k

Network Consultant - London - 55-65k My client are...

Web Graphic Designer

A leading global provider of critical information to...

To send to more than one email address, simply separate each address with a comma.