Home > Information Security News > Top social networking websites present new 'battleground for malware'
Information Security News:
EMAIL THIS

Top social networking websites present new 'battleground for malware'

By Ron Condon, U.K. Bureau Chief
30 Jul 2009 | SearchSecurity.co.uk

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Top social networking websites are becoming the new "battleground for malware," according to a new report from security company Sophos Plc.

As Sophos explains in its "Security threat report: July 2009 update," which covers the first six months of 2009, hackers are increasingly using sites such as MySpace, Facebook and Twitter to gather valuable information and launch phishing attacks.

In response, many organisations say they are blocking access to the sites from work systems, partly to prevent a loss of productivity, but also because of security fears.

"Social network sites need to take time to bolster security; otherwise the hackers and cybercriminals will take advantage of them in a big way," said Graham Cluley, a senior consultant at Sophos.

Cluley said the social networking websites need to "grow up," and he singled out Twitter for special criticism, saying: "You can set up a Twitter account without giving it an email address, so they have no way of sending you a confirmation email. Furthermore, if you want to run a dictionary attack against a Twitter account, the service allows you to try as many times as you like. Any sensible website would allow you three or four tries before blocking access. It is basic stuff."

The sites could also provide users with better feedback on the strength of their passwords, and help them create passwords that are more difficult to guess. "It would be terrific if more of these sites actually graded your password, and gave you an idea of how strong it is," he said. "They could block the use of dictionary words, for instance. Those things are relatively trivial for social networking sites to implement, but they haven't really grown up yet. Their businesses have grown so quickly that they are running before they can walk."

Cluley advised organisations not to ban use of the sites altogether, but rather to educate users about the dangers and to instil best practices. "Social networks are going to become key to the way some businesses work," he said. "Many companies now use the sites to reach out to their customers, and for recruitment. If you take the tools away from people, then they will not be as productive."

The Sophos report reveals that more than half of all organisations currently block access to social networking websites, primarily to prevent time-wasting. But security concerns are also growing, with 63% of system administrators admitting that they worry about employees sharing too much personal information via their social networking sites.

In other areas of security, Sophos also identified increasing dangers, and what it calls a "conveyor belt of crime," as Internet crime becomes more professionally organised.

Sophos notes that instead of simply looking for operating system and browser vulnerabilities, hackers are also exploring security holes in other widely used programs and tools such as Adobe Flash and PDFs.

"The rise in malicious Flash and PDF files can be partly explained by the use of malware construction kits that build Web attack pages incorporating booby-trapped code," the researchers said. "The inclusion of the Flash and PDF content targets vulnerabilities that have been found in the widely used Adobe browser plug-ins, underlining the importance of keeping these up to date."

In the wake of these attacks, Adobe has followed Microsoft's lead by instituting a regular patch update of its products on the second Tuesday of every third month. The first took place in June.

Graham Cluley, senior consultant at Sophos, reviews how social networking sites should be managed in an enterprise setting.

Tags: Data Protection Solutions and StrategyWeb Application SecuritySecurity Policies and User AwarenessVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Data Protection Solutions and Strategy
Pros and cons of Skype security for encrypted phone calls
NHS smart card devices enable secure access to health care apps
Company files at risk of employee data theft
McAfee-Intel: Why the McAfee acquisition is being met with scepticism
Mobile digital pad/pen helps secure patient data collection
Hard-disk erasure: Using HDDerase and Secure Erase hard-drive eraser
In any given app for smartphone, security risks are being neglected
First of data loss prevention vendors touts downloadable DLP software
Ministry of Justice asks for input on UK privacy laws
PCI PTS: Understanding PCI PIN security requirements

Web Application Security
Social networking: Workplace productivity, security no match for Facebook
Adobe vulnerability: Pen test firm finds ColdFusion admin page flaw
Survey: Web 2.0 security issues cause concern
Twitter settles with FTC over security issues, careless policies
Report: Google to phase out Windows, cites security issues
New tool enables botnet command and control via Twitter
Pwn2Own results: The most secure Internet browser for enterprises
Google cloud applications: Secure enough for the enterprise?
Symantec Internet threat report highlights botnet, malware trends
Researchers aim to smarten Web application security scanners

Security Policies and User Awareness
Company files at risk of employee data theft
Employee security training for Data Protection Act compliance
Spy recording devices can be thwarted by portable USB security policy
Background employment screening decreases insider threats, study says
Risk management in information technology
Information security awareness lacking in laptop users, according to study
Kent company offers 'low-tech' hard disk destruction product
Survey: Compliance efforts drive security, but may not produce results
Using resource allocation management to prevent DoS and other attacks
Cloud-based services require stalwart business continuity plans

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Data Protection Act 1998  (SearchStorageUK.com)
Information Commissioner's Office (ICO)  (SearchStorageUK.com)
UK Identity Cards Act  (SearchSecurityUK.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary







IT Solutions for the UK: Data Security, Network Security, Application Security
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2008 - 2010, TechTarget | Terms of Use | Read our Privacy Policy
  TechTarget