Google warns of web malware epidemic

One in ten sites hosting code that attacks browsers

Written by Iain Thomson

A study released today by Google has warned of "very high levels" of malware being hosted on websites.

In a year-long scan of over 4.5 million sites the Google team found code on 450,000 pages that could inject malware onto users' PCs via improperly patched browsers.

A further 700,000 sites hosted similar code that, while not necessarily malicious, could harm the security of the PC viewing the page.

"In most cases, a successful exploit results in the automatic installation of a malware binary, also called drive-by download," said the five-member team which wrote the Ghost in the Browser paper.

"The installed malware often enables an adversary to gain control over the compromised system and can be used to steal sensitive information such as banking passwords, to send out spam or to install more malicious executables over time."

Web propagation of malware differs from the traditional method of sending via email attachment in that no user interaction is required, merely a visit to the website.

The research highlighted four main attack vectors: web server security; user generated content; advertising; and third-party software.

User-generated content is being used to send malware, particularly if uploading to the site can be done anonymously.

Web advertising software is typically in JavaScript and the unscrupulous operator may simply hide their malware in seemingly legitimate code. Similarly, third-party applications like web counters or online polls may also harbour data.

The team found that much of the malware on the web is very advanced and can bypass some signature-based antivirus software. A small proportion of the code actually changed its signature almost every hour.

Tags:

reader comments

related articles

Infosecurity Europe 2007

Malware authors cut out attachments

Infected web pages now the attack du jour 26 Apr 2007

 

Malware spreading via Skype

Beware URLs bearing gifts 23 Mar 2007

Social networks riddled with malware

One in 600 profiles host infection 10 Aug 2006

Total malware volumes grow 'dramatically'

Malicious code writers target the web in earnest 25 Apr 2007

Hackers unleash 'insidious' crimeware attack

Trusted websites turned into traps 14 Jan 2008

Hackers 'seeding' legitimate websites

SQL injection attacks colonising big name sites 09 Jun 2008

Legitimate web sites hosting malware

"Drive-by" infections used to be the preserve of criminal sites only 25 Jan 2008

related whitepapers

today's top stories

Coding moves with the times

We examine how software development has evolved to better serve the changing needs of business, and speaks to IT leaders who are delivering significant benefits to their organisations by using the latest programming methods 15 Oct 2008

Agile framework simplifies offshore development

Case study: Getronics business application services 15 Oct 2008

Computing launches all-new IT jobs site

Updated Computingcareers.co.uk provides enhanced feature for jobseekers 14 Oct 2008

Q&A: BT Business head of SaaS, Chris Lindsay

BT's head of software-as-a-service explains the benefits of the on-demand delivery model and how the current economic downturn could force firms to re-evaluate how they buy software 14 Oct 2008

WiMax: Threat or opportunity?

We examine the merits of WiMax and its benefits relative to other wireless technologies in our latest video 13 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Are you worried about your job prospects in IT over the next 12 months?

Are you worried about your job prospects in IT over the next 12 months?

Will the economic crisis affect your job prospects?

Previous poll results

Latest audio and video articles

Remote workerVideo

WiMax: Threat or opportunity?

We examine the merits of WiMax and its benefits relative to other wireless technologies in our latest video 13 Oct 2008

programming codeVideo

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Latest in-depth articles

Features

Enter the dragons' den

Getting an innovative IT product off the ground takes cash, commitment and a lot of patience 15 Oct 2008

TimepieceFeatures

Coding moves with the times

We examine how software development has evolved to better serve the changing needs of business, and speaks to IT leaders who are delivering significant benefits to their organisations by using the latest programming methods 15 Oct 2008

Advertisement

Primary Navigation