Audio By Carbonatix
Thousands of small web shops have been unwittingly poisoned with malicious code that infects PC users who visit.
Security experts said the sophisticated attack had succeeded on a larger scale than many other similar attacks.
Once installed on a Windows machine the malicious code steals passwords, browser data as well as login names for bank accounts and online games.
The attack is proving hard to defend against for both sites being hit and PC users who are caught out.
Big hitter
Security researchers at ScanSafe, Finjan and Secure Works separately discovered the nest of poisoned websites. Estimates of how many sites have been enrolled into the attack vary. ScanSafe said it knew of about 230 but Secure Works and Finjan believe the total could be as high as 10,000.
Yuval Ben-Itzhak, chief technology officer of Finjan, said it had been following the attack since early December when it noticed an increase in the number of attacks using poisoned websites.
"It's safe to say that there are thousands of these out there," he said. He added that it was hard to get an accurate picture of just how many had been hit because security firms had limited resources to scan all potential targets.
The attack exploits loopholes in many Windows programs
Writing on the ScanSafe blog Mary Landesman said many of the poisoned sites were small "mom and pop" web shops rather than large web retailers. Despite this, she wrote, many had large numbers of visitors because they did well in web searches for particular products and services.
Sites enrolled by the ongoing attack include trade papers, travel firms, ad brokers, estate agents, butchers, hotel booking sites and car spare specialists.
Although all the websites that have become poisoned hosts use the same server and remote administration software, researchers have struggled to spot all the ways they are being compromised.
"We know some of the methods," said Mr Ben-Itzhak, "they are trying to exploit known vulnerabilities in open source content management software that the sites are using."
Spotting the attack code on a site was very difficult, he said, because every time a new user visited, the code got a new, random five character name. If a visitor returned the malicious code identified them and did not launch a second attack.
Open Windows
Simon Heron, managing director of security firm Network Box, said: "It looks like the rootkit type technique that we have been worried about for the last two or three years. It's very clever."
A rootkit hides itself deep inside an operating system in an attempt to avoid detection.
Mr Heron said the code injected on the websites scanned the machine of any visiting Windows user to see if any one of 13 separate vulnerabilities were present.
It looked for vulnerabilities in browsers, instant messaging programs, document readers and media players, he said.
The code installs a small Trojan through any one of these loopholes, then lies dormant until a user types in data that it is interested in - such as login names for online banks or games such as World of Warcraft.
As yet the Trojan installed on a PC is not recognised by many widely used anti-virus programs.
Philippe Courtot, founder and head of security firm Qualys, said small web shops and companies were increasingly becoming a target for criminally-minded hackers.
"Small businesses do not have the money to protect themselves," he said.
He added that hosting firms who owned and ran the servers on which these firms place their websites, viewed security as something extra they had to do rather than build it in.
SOURCE: IOL NEWS
DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.
Tags:
DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.
Latest Stories
-
USA boss Pochettino holds initial talks with AC Milan
27 minutes -
‘Not a robot’ – Sinner had ‘no energy’ in shock defeat
32 minutes -
Canada signs landmark LNG energy deal with Germany
40 minutes -
EU fines Temu €200m for allowing sale of illegal products
52 minutes -
Sir David Adjaye breaks silence on vision behind Ghana’s National Cathedral
1 hour -
Beyond the Party T-Shirt
2 hours -
IGP promotes five police officers over Kwafokrom GOIL robbery arrest
2 hours -
Tragedy at Senchi: Two crushed to death as tipper truck somersaults near market
3 hours -
Government to unveil “The New Economy” Programme in 2027 Budget
3 hours -
GIZ, Zoomlion and Blue Skies launch InnoWaste Project to create jobs and tackle plastic waste in Ghana
3 hours -
‘The emotional journey is difficult, but you don’t stop’ – Antoine Semenyo’s mother on diaspora struggle
3 hours -
‘Football in Ghana is about blood and legacy’ – Antoine Semenyo’s mother urges diaspora parents
3 hours -
QNET, Manchester City bring world-class football coaching to Ghana’s young talent
3 hours -
Emma Ankrah: Between quiet questions and the will to continue
3 hours -
Ghana’s economy shows strong recovery after “inherited crisis” – Ato Forson tells Parliament
3 hours