Home > Information Security News > World's most visited websites vulnerable to malware
Information Security News:
EMAIL THIS LICENSING & REPRINTS

World's most visited websites vulnerable to malware

By Ron Condon, UK bureau chief
03 Mar 2008 | SearchSecurity.co.uk

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

The discovery of a criminal database containing more than 8,700 harvested FTP account credentials has revealed the extent to which legitimate websites are open to malware infection.

Security company Finjan, which made the discovery, is not making public the names of the vulnerable web domains, but its figures reveal that 160 out of the world's top 1000 domains have had their credentials stolen. Companies wanting to check if their domain is on the list can contact Finjan.

The database contains the username, password and server address of 8,700 domains, which would allow any hacker who rents the information to access the servers and plant malware. Users going to that website would then be open to infection, such as having a Trojan secretly downloaded on to their machine.

The stolen accounts include global companies in a wide range of industries, Government agencies and even some security companies.

The discovery underlines a problem that has been growing over the last year or so, with hackers targeting legitimate websites to avoid being detected by URL blacklists.

Security company Sophos says it detects around 6,000 new infected webpages every day, although last June the daily figure surged to more than 29,000 for a short period.

"83 of these infected webpages actually belong to innocent companies and individuals, unaware that their sites have been hacked," said Graham Cluley, a senior consultant at Sophos.

"Criminal gangs are not only infecting webpages, they are also trading usernames and passwords which means they can spirit themselves onto corporate websites and plant dangerous code without having to exploit a vulnerability. Even if your website does not have a vulnerability on it which can be exploited, the hackers can effectively walk straight in through a side door."

The Finjan research uncovered what it calls "an almost unnoticeable standalone application" that the criminals use to trade stolen the FTP account credentials. It allows the server administrator to manage FTP credential information to inject iframe tags to any webpage it finds on the compromised FTP account. And it even helps the server administrator put a price tag on the stolen credentials by rating them by their country of residence and their Google rating.

The database that Finjan discovered certainly shows that many of the stolen domains have been chosen for their maximum commercial value. Ten of the accounts relate to websites that are ranked in the world's top 100 according to Alexa.com.

Of the total 8,700 stolen accounts, most are based in the US and Russia. Just 78 came from the UK.

Yuval-Ben Itzhak, CTO at Finjan, summed up the risks: "If your FTP server credentials are on the list, criminals may use it to add crimeware on to your site - so people visiting your site will get infected with crimeware and may sue you. And if the FTP server includes confidential documents and data, that can be in the hands of the criminals." He suggested that a good place to start is to change FTP passwords frequently.

Cluley said IT departments should regularly audit the usernames and passwords which have FTP access to their website, and ensure that passwords are changed regularly so that if they do fall into the wrong hands they cannot be abused for too long. "Some firms may wish to implement additional authentication methods to ensure that the person uploading code to the website really is who he or she claims to be," he added.

"Web servers are the backbone of the internet. Ensuring that servers are secure from outside attack is a prime concern for any organisation that relies on them."

His tips for protecting webservers are:

  • Don't install any unnecessary components on the server – more code means more vulnerabilities for hackers to exploit
  • Sign up to your operating system security notifications
  • Patch all operating systems and any applications with official security fixes
  • Run up-to-date anti-virus software on the web server, regardless of what operating system you are using.
  • To download the Finjan report, go to http://www.finjan.com/mpom

    Tags: Platform Security SolutionsWeb Application SecurityVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts