All the latest UK technology news, reviews and analysis

Malware authors cut out attachments

by Iain Thomson

More from this author

26 Apr 2007

Comment: 1

  • Tweet this
Infosecurity Europe 2007
Infosecurity Europe 2007

Malware authors are shifting attack vectors from emails containing infected attachments to web pages embedded with malicious code, according to experts at Infosecurity Europe 2007.

Security firm Sophos is reporting that the traditional method of sending malware via attachment is now falling out of favour and that the authors can now bury the code in web pages and just send out links to that page.

"We are seeing an average of 5,000 infected web pages every day," said Graham Cluley, senior technology consultant at Sophos.

"Some days it goes as high as 20,000. Visit these sites, even if your browser is fully patched, and you run a risk of infection."

By exploiting vulnerabilities in the website server with a PHP attack or other technique, the malware author can imbed code in the site with little chance of detection.

Around 70 per cent of infected web pages are contained in legitimate sites from established companies.

"It is not just porn or gambling sites that are risky," said Carole Theriault, senior security consultant at Sophos.

"They are appearing everywhere, even in gardening sites. Content is no longer an indicator to risk."

PODCAST: Interview with Graham Cluley and Carole Theriault

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Information Security Manager

My client is a well established, non profit organisation;...

PHP Web Developer

PHP Web Developer – £30,000 - £35,000 PHP, MySQL, HTML...

HEAD OF DIGITAL - London - £80-95K+

HEAD OF DIGITAL - London - £80-95K + Excellent Bens...

Agile C# Developer - (North London)

Agile C# Developer - (North London) £55,000 - £65,000...

To send to more than one email address, simply separate each address with a comma.