Wednesday February 10, 2010 2:51 AM AEST
 
Latest Comments
"I too have been a labor voter for many years and will not be voting for them again. The ..."
by maxt | Feb 9, 2010 7:56 PM
 
"I’ve just had a user receive a rehashed version of this with an attached html file containing a ..."
by Owen Lutz | Feb 9, 2010 6:01 PM
 
"hi"
by manish kumar | Feb 9, 2010 4:27 PM
 
"Hey 'hey con-roy' ... from Google Australia's head of policy Iarla Flynn"We don't believe that ..."
by Keep it real | Feb 9, 2010 3:33 PM
 
"@penno Off-site storage is a good solution unless you have some decent backup software to ..."
by Charmgene | Feb 9, 2010 2:36 PM

Google warns of web malware epidemic

  • Email a Friend
  • Print Page
Google warns of web malware epidemic
By Iain Thomson
May 15, 2007 4:23 PM
Tags: Google | warns | of | web | malware | epidemic
One in ten internet sites are hosting code that attacks browsers, says Google.
A study released today by Google has warned of "very high levels" of malware being hosted on websites.

In a year-long scan of over 4.5 million sites the Google team found code on 450,000 pages that could inject malware onto users' PCs via improperly-patched browsers.

A further 700,000 sites hosted similar code that, while not necessarily malicious, could harm the security of the PC viewing the page.

"In most cases, a successful exploit results in the automatic installation of a malware binary, also called drive-by download," said the five-member team which wrote the Ghost in the Browser paper.

"The installed malware often enables an adversary to gain control over the compromised system and can be used to steal sensitive information such as banking passwords, to send out spam or to install more malicious executables over time."

Web propagation of malware differs from the traditional method of sending via email attachment in that no user interaction is required, merely a visit to the website.

The research highlighted four main attack vectors: web server security; user generated content; advertising; and third-party software.

User-generated content is being used to send malware, particularly if uploading to the site can be done anonymously.

Web advertising software is typically in JavaScript and the unscrupulous operator may simply hide their malware in seemingly legitimate code. Similarly, third-party applications like web counters or online polls may also harbour data.

The team found that much of the malware on the web is very advanced and can bypass some signature-based antivirus software. A small proportion of the code actually changed its signature almost every hour.

Copyright © 2009 v3.co.uk

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Vulnerabilities & Exploits Whitepapers