Dangers grow on Web from attacks

July 9, 2009 By Elise Ackerman

When people worry about the dangers of the Internet, a Web site built by the producers of "Mister Rogers' Neighborhood" is probably not what they have in mind.

So parents and teachers became highly alarmed when their Google searches earlier this year for the site, Family Communications, turned up dire warnings about a infection.

"The phone kept ringing and ringing," said Kevin Morrison, the chief operating officer for the Pittsburgh production company founded in 1971 by Fred Rogers, the popular children's television host. "They were saying, 'Google says your site is not safe.'"

It took Morrison some time to figure out that fci.org had been hacked. And it wasn't alone. More than a dozen other sites that share the same hosting provider had been targeted, part of a global and growing wave of malicious activity that is forcing ordinary Internet destinations into the online equivalent of quarantine zones.

"Hackers are breaking into every site they can," said Richard Wang, a manager at SophosLab US, a Boston-based security company. "The old advice about avoiding sites offering free software, illegal downloads or adult content is less relevant now. Any site can be a source for infection."

By the end of last year, Microsoft was finding booby-trapped Web pages at the rate of a million a month. These sites, also known as drive-by downloads, can infect a computer without a person taking any action except visiting a Web page. A human isn't required to click on an e-mail link or to agree to install any software. Instead, the sites automatically download software onto visitors' computers.

Once that happens, can do several things. They can implant a keystroke logger on the machine to record passwords or other valuable information. Compromised machines also often become part of "botnets," large collections of computers that are rented out for criminal purposes, including sending spam or phishing, an attack that attempts to trick someone into revealing valuable personal information.

While drive-by downloads have plagued the Web for years, security experts say their numbers are spiking because criminals have automated their attacks, and because sites have become more vulnerable as they have become more complex. Sophos said its Web crawler discovers a new infected Web page every 4.5 seconds, a threefold increase over 2007.

"It's one of the biggest trends we are seeing," said Zulfikar Ramzan, a technical director at Symantec.

Infected Web pages still make up only a tiny portion of the Web itself, which has grown to more than a trillion pages. But by piggybacking on popular destinations -- like the Mister Rogers site -- they turn up with increasing frequency in search results.

Last year attackers broke into sites owned by well-known brands like Sony and Adobe, as well as BusinessWeek and Cambridge University Press.

Ordinary people can largely protect themselves by keeping their operating systems, browsers and anti-virus software up to date. Browser plug-ins from large anti-virus manufacturers such as Symantec and McAfee as well as smaller companies like Web of Trust identify potentially problematic Web sites. And other plug-ins like NoScript for the FireFox browser can cripple malicious code by disabling software scripts, though they can also reduce the "special effects" on some sites.

All major search engines prominently flag risky sites when they show up in search results. For example, Google inserts a link underneath the title of such sites that says "this site may harm your computer."

If someone clicks on the link anyway, Google will take the person to one of its own pages that contains a lengthy warning: "Please be aware that malicious software is often installed without your knowledge or permission when you visit these sites, and can include programs that delete data on your computer, steal personal information such as passwords and credit card numbers, or alter your search results." The Google page does not link to the original URL, or Web address.

At that point, the only way someone can get to the offending site is to type in the URL directly.

The problem with this kind of approach, said Neil Daswani, who worked on the security team at Google for three years, is that a lot of unsuspecting Web site owners are finding themselves blacklisted for reasons they don't understand. There are literally 10,000 ways attackers can break into a Web site. Locating the harmful code they insert and removing it takes specialized skills. Daswani said the average Web site operator can't keep up.

Daswani left in October to co-found a company, Dasient, whose goal is to help ease the load at a reasonable price. Basic diagnostic and monitoring services are free. For an additional fee, ?Dasient will automatically remove dangerous code before the problem is spotted by a search engine without disrupting the operation of the site.

Morrison said he was initially skeptical of Dasient, but after the company quickly found rogue software that was using the Family Communications site to run a phishing scam, he happily signed on as a beta tester. "If you do have a Web site with a lot of pages there is no easy way to know where the bad code is," he said. " doesn't tell you."

___

PROTECT YOURSELF FROM A DRIVE-BY DOWNLOAD

1. Make sure you have the most current version of your operating system and browser.

2. Update anti-virus and anti-spyware software.

3. Pay attention to search-engine warnings.

4. Add a browser plug-in that will provide additional information about problem Web pages.

5. Add a browser plug-in that will prevent automatic launching of Web-page software.

___

(c) 2009, San Jose Mercury News (San Jose, Calif.).
Visit MercuryNews.com, the World Wide of the Mercury News, at http://www.mercurynews.com
Distributed by McClatchy-Tribune Information Services.


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 4 /5 (1 vote)


July 9, 2009 all stories

Comments: 0

4 /5 (1 vote)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • Review: Firefox 1.5
    created Dec 01, 2005 | popularity not rated yet | comments 0
  • Too much YouTube? Lock it up
    created Feb 18, 2009 | popularity not rated yet | comments 0
  • Briefs: Cyber criminals exploit BBC
    created Mar 31, 2006 | popularity not rated yet | comments 0
  • Spyware poses identity-theft risk (Update)
    created Sep 15, 2005 | popularity not rated yet | comments 0
  • Tool Turns Any JavaScript-Enabled Browser into a Malicious Drone
    created Mar 27, 2007 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • Aspiring Engineering major looking for general answers
    created Nov 19, 2009
  • Calculating max load of square tube (steel)
    created Nov 19, 2009
  • Passive Chemical Heating
    created Nov 19, 2009
  • Shortening Boat Trailer
    created Nov 18, 2009
  • Strain Gage Test Advice
    created Nov 17, 2009
  • How Could I do This? Motor to open and close doors on a timer??
    created Nov 17, 2009
  • More from Physics Forums - General Engineering

Other News

Hackers leak e-mails, stoke climate debate

Technology / Internet

created 7 hours ago | popularity 4.3 / 5 (12) | comments 6

(AP) -- Computer hackers have broken into a server at a well-respected climate change research center in Britain and posted hundreds of private e-mails and documents online - stoking debate over whether some scientists have ...


plug-in hybrid electric vehicle

Pulling the plug on hybrid myths

Technology / Energy

created Nov 19, 2009 | popularity 3.8 / 5 (12) | comments 17

(PhysOrg.com) -- Whether you call them myths, urban legends, fables or old wives' tales, there's a lot of misinformation out there about plug-in electric hybrid vehicles. These vehicles, abbreviated PHEVs, ...


UK police make 2 Trojan computer virus arrests

Technology / Internet

created Nov 18, 2009 | popularity 5 / 5 (1) | comments 10

(AP) -- A couple suspected of helping spread some of the Internet's most aggressive computer viruses has been arrested in the English city of Manchester, police said Wednesday.


A sign marks the entrance to IBM Corporate Headquarters

IBM makes Big Blue cloud

Technology / Software

created Nov 16, 2009 | popularity 2.9 / 5 (8) | comments 8

IBM on Monday announced it has created the world's largest business computing "cloud" capable of holding an amount of digital data on a par with 250 billion iTunes songs.


Google SPDY

Google's SPDY will speed up downloads

Technology / Internet

created Nov 16, 2009 | popularity 4.4 / 5 (16) | comments 7

(PhysOrg.com) -- As part of its effort to speed up the Web, Google is experimenting with SPDY, a new application layer protocol, that it hopes will speed up the conversation between browsers and Web servers ...