Google warns of web malware epidemic

One in ten sites hosting code that attacks browsers

Written by Iain Thomson

A study released today by Google has warned of "very high levels" of malware being hosted on websites.

In a year-long scan of over 4.5 million sites the Google team found code on 450,000 pages that could inject malware onto users' PCs via improperly patched browsers.

A further 700,000 sites hosted similar code that, while not necessarily malicious, could harm the security of the PC viewing the page.

"In most cases, a successful exploit results in the automatic installation of a malware binary, also called drive-by download," said the five-member team which wrote the Ghost in the Browser paper.

"The installed malware often enables an adversary to gain control over the compromised system and can be used to steal sensitive information such as banking passwords, to send out spam or to install more malicious executables over time."

Web propagation of malware differs from the traditional method of sending via email attachment in that no user interaction is required, merely a visit to the website.

The research highlighted four main attack vectors: web server security; user generated content; advertising; and third-party software.

User-generated content is being used to send malware, particularly if uploading to the site can be done anonymously.

Web advertising software is typically in JavaScript and the unscrupulous operator may simply hide their malware in seemingly legitimate code. Similarly, third-party applications like web counters or online polls may also harbour data.

The team found that much of the malware on the web is very advanced and can bypass some signature-based antivirus software. A small proportion of the code actually changed its signature almost every hour.

See also:

reader comments

related articles

Infosecurity Europe 2007

Malware authors cut out attachments

Infected web pages now the attack du jour 26 Apr 2007

 

Malware spreading via Skype

Beware URLs bearing gifts 23 Mar 2007

Social networks riddled with malware

One in 600 profiles host infection 10 Aug 2006

Total malware volumes grow 'dramatically'

Malicious code writers target the web in earnest 25 Apr 2007

Hackers unleash 'insidious' crimeware attack

Trusted websites turned into traps 14 Jan 2008

Hackers 'seeding' legitimate websites

SQL injection attacks colonising big name sites 09 Jun 2008

Legitimate web sites hosting malware

"Drive-by" infections used to be the preserve of criminal sites only 25 Jan 2008

latest news

Ballmer highlights aims for New Year

Ballmer announces Windows 7 beta and future alliances designed to improve information sharing 08 Jan 2009

Active Storage completes UK Jigsaw

Jigsaw unveiled as Raid vendor's first non-US Platinum partner as it launches in Europe 08 Jan 2009

Dell quits Irish production

Vendor to slash 1,900 jobs in Limerick as it migrates assembly for EMEA customers to Poland 08 Jan 2009

poll

Challenging times ahead?

Challenging times ahead?

Do you think there will be a lot of channel job cuts in 2009?

Previous poll results

Paul Anderson, Trend Micro

Vendor Q&A: Paul Anderson, Trend Micro

During this Q&A session Paul Anderson, UK country manager of Trend Micro talks about the changing threat landscape and how Trend is working with resellers in 2009

Sara Yirrell and Rick Wallis

Vendor Q&A: Rick Wallis, NEC Computers

In this exclusive vendor Q&A, Rick Wallis, UK sales director at NEC Computers talks to CRN editor Sara Yirrell about his firm’s plans for the channel.

events

Channel Expo 2009 logo

Channel Expo 2009

The UK's top reseller exhibition will return to the NEC on 20 May 2009

CRN Fight Night 2009

The channel's only white-collar boxing event is back

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories

Primary Navigation