Manufacturing Computer Solutions - The definitive it guide for UK manufacturers
 
 
Site Search :   Search Help   login

1,000 web domains compromised this month, says Finjan 17/07/2008
 
business web security software More than 1,000 website domains have been compromised by a new round of mass web attacks this month.



Secure web gateway systems developer Finjan detected the attacks using its SecureBrowsing in-the-cloud security tool.

Yuval Ben-Itzhak, CTO of Finjan, says the toolkit being used by the attackers is aliased Asprox, and has been around for some years, gaining cybercrime popularity during 2007.

It’s designed to first search Google for webpages with the file extension .asp. Once found, it launches SQL Injection attacks to append a reference to the malware file, using the iframe tag, making it extremely efficient.

Each of the compromised domains included a reference to a malware that was served by more than 140 different domains across the Internet.

“Since the list of these malware serving domains increases every day, we believe this is just the tip of the iceberg for the scope and impact of this attack,” says Ben-Itzhak.

“Among the compromised websites we found were those of respectable organisations, governmental institutes, healthcare organisations, as well as high-ranked websites… It requires proactive security solutions to safeguard organisations against these kinds of mass web attacks.”
 
Author
Brian Tinham
 
Email this article
 
Bookmark this article using:
 
Del.icio.us digg reddit Facebook StumbleUpon
 
News Item
Linked Companies
 
 Finjan Software
 
 
News Item
Similar News Articles
 
  IT professionals using email to hide file transfer activity
 
  Over one third of firms now say their IP has been stolen
 
  Over half of IT professionals don’t encrypt mobile data
 
  One in 10 IT professionals cheat on their audits
 
  Patch Tuesday only resolves disclosed vulnerabilities
 
 
News Item
Similar Reference Zone Articles
 
  Network practice
 
  Wireless world
 
  Mobile IT: for real
 
  Unlocking business with cyber security
 
  Netting material improvements