Sophos warns of web site malware spike

Annual report reveals almost 30,000 infected web pages blocked daily during June

Written by Phil Muncaster

Web site owners are being advised to lock down their web servers after anti-malware vendor Sophos reported a huge increase in the number of infected web pages from legitimate sites on the internet.

In its biannual Security Threat Report, the vendor found 49,629 new pieces of malware, 24 percent more than during the second half of 2006, and said it had blocked nearly 30,000 web pages daily during the month of June alone.

Of those infected web pages, the vast majority – around 80 percent – were legitimate sites injected with malicious code exploiting vulnerabilities in the web server, according to Sophos senior technology consultant, Graham Cluley. Simply visiting one of these pages is enough to infect a user's PC with Trojans, spyware, adware or other unwanted applications, he added.

"Hackers are trying to infect firms via the web browser because most companies are scanning emails for viruses now," explained Cluley. "It's no good for firms to block access based on category [or URL], they need to scan every site for malware as the user accesses it."

The report also found that Apache servers were the most likely to be compromised. Over half of the web-based vulnerabilities were discovered on sites running Apache, compared to 34 percent running Microsoft IIS 6. Cluley advised firms to ensure their servers are up-to-date with patches and to conduct regular scans of content on the site, especially if it allows a lot of user-generated content to be uploaded.

"We contact some of the more well-known sites we find that are infected, but some of them just get immediately re-infected and some don't know what we're talking about," Cluely said. "We think it could be in the public's interest to name the ones who aren't listening to us."

Graham Titterington of analyst firm Ovum argued that naming and shaming those sites which fail to take down known malware from their sites could work for a few high-profile web sites, as it may act as a warning to others. But he added that public apathy would mean a long-term campaign may have limited effect.

Titterington also argued that complacency with patch management may be the cause of the high number of Apache servers found to have been compromised. " They must lock down their sites as much as they can and monitor changes in the configuration files," he advised.

The Sophos report also found that hackers are trying to spread malware via removable USB devices, taking advantage of PCs which have auto-run enabled to automatically execute the code as soon as a removable device is attached.

"It's a boomerang back to the old days when PCs were infected by floppy disks," said Cluley.

Titterington added that it reinforces the need for protection at the endpoint as well as the gateway, as traditional web filtering technology would not be able to spot infection via USB.

"The volume and the speed at which USBs execute and run when plugged in make it quite potent, but it's still a relatively cumbersome channel [of infection], " Titterington argued. "It will only really work for targeted attacks, not mass mailers."

In related news, email security specialist Tumbleweed has reported that spammers are now expoliting Excel applications as a way of bypassing traditional filtering technology. The new trend follows a similar technique of using attached PDF documents containing embedded images, which was flagged up by several security vendors in recent weeks.

  • Have your say
  • Send to a friend
  • Print this
  • Share

Tags:

reader comments

related articles

Web app security still overlooked

Firms at risk from vulnerabilities in their web sites, according to new report 21 Mar 2007

 

IT teams urged to rethink web and network security

Industry could see more convergence soon, says security expert 09 Jul 2007

Trend enhances web security portfolio with reputation feature

Trend Micro releases software to stop workers straying onto malware sites 28 Mar 2007

Faster-changing viruses and Web 2.0 threaten security

There are new problems brewing for firms, say Symantec researchers 25 Sep 2006

Web 2.0 deployments hit by JavaScript flaw

Fortify software has uncovered a flaw affecting the Javascript programming language 02 Apr 2007

Social networks urged to tighten security

New Sophos report warns against complacency 22 Jul 2009

Websense warns of web-based malware epidemic

Security firm sees 600 per cent rise in malicious sites 15 Sep 2009

Twitter under attack again

Scammers taking advantage of heightened public interest to spread malware 20 Apr 2009

related whitepapers

today's top stories

Telepresence: coming to a screen near you?

Telepresence systems enable organisations to hold boardroom-style meetings with far-flung participants without the hassle and expense of arranging travel and accommodation. But while the technology is impressive, it does not come cheap, as Martin Courtney discovered when he sat in on a virtual meeting with executives from Philips 10 Mar 2010

Users give their verdict on Azure

Some of the first wave of UK adopters met in London recently to air their views on Microsoft’s cloud computing platform. Dave Bailey listened in 10 Mar 2010

Protests greet new Digital Economy Bill amendment

ISPs, digital rights groups and Liberal Democrat supporters cry foul 05 Mar 2010

Publishing special - Publishers innovate to survive

1) IT could hold the key to the future of publishing 2) Case Study: The Guardian harnesses social and mobile apps 3) How publishers are reacting to the iPad 02 Mar 2010

IT Leaders' Forum in association with IBM

A unique opportunity to hear from expert speakers and engage in a debate about the future of the CIO job function 29 Jan 2010

Advertisement

Keys to successful Service‐Oriented Architecture implementation

This white paper explores best practices and general design patterns for service oriented architecture (SOA).

The Roadmap to IT Maturity — Matching Strategy to Infrastructure for Business Success

This paper defines a roadmap for matching infrastructure strategy to business success.

Advertisement

Keep up to date with the latest products, services and technologies from the world's leading IT companies; ITHound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

NHS centralised data

NHS centralised data

Do you think the NHS can be trusted to safely look after personal data electronically?

View poll results

Latest audio and video articles

Video

HP unveils S Series notebooks

'Prosumer' line overhauled 01 Mar 2010

Web Seminar Listings

Preparing for enterprise-scale Windows 7 migration

The web seminar on 18 Feb will discuss how Windows 7 migration can increase IT efficiency in large enterprises, freeing up budgetary and personnel resources to focus on business innovation. Our panel of experts will examine the strategies, tools and services IT leaders can use to migrate successfully and reap the rewards of increased efficiency. 19 Feb 2010

Latest in-depth articles

Martin CaveComment

Lessons to be learned from cricket's internet outing

Imagine the scene. It’s the final of one of the most popular sporting events in the Indian subcontinent and millions of people are glued to their laptops and PCs in anticipation of the four runs required off the last ball of the match. Suddenly the connection jitters and 20 seconds later you see the jubilant crowd flooding onto the field of play… 12 Mar 2010

Wayne GibbonsComment

Social networks are key to cracking China

Business social media can unlock the door to the world’s second-largest economy 10 Mar 2010

Primary Navigation