Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Applications
    • Applications
    • Cybersecurity
    • Development
    • IT Management

    Web Application Attacks Dominate IT Landscape

    Written by

    Matt Hines
    Published September 25, 2006
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Attacks that capitalize on vulnerabilities in popular Web browsing software and targeted malware and phishing efforts dominated the first six months of 2006, according to Symantecs latest Internet Security Threat Report.

      Published on September 25, the twice-yearly analysis highlights continued growth of the browser vulnerability issue, finding that 69 percent of all the new threats unearthed by the company between Jan. 1 and June 30 attempted to take advantage of flaws in Microsofts Internet Explorer, Mozillas Firefox and other popular Web applications.

      The anti-virus market leader, based in Cupertino, Calif., said the relative ease with which malware code writers can isolate vulnerabilities in browsers and other Web-based programs continues to drive popularity of the attacks, compared to threats targeting client-side applications.

      Internet Explorer remains the most frequently targeted Web browser, accounting for 47 percent of all such attacks, followed by Firefox, which accounted for 20 percent.

      Threats that were designed to target vulnerabilities in multiple browsers, including Explorer, Firefox, Apples Safari and others, made up 31 percent of attacks on the programs.

      In total, Symantec detected 47 new vulnerabilities in Firefox and the Mozilla browser, 38 flaws in Explorer, and 12 issues in Safari, representing a 52 percent rise in browser-based problems compared to the 25 vulnerabilities recorded over the last six months of 2005.

      In another browser-related trend, malware writers are increasingly attempting to exploit vulnerabilities in sites that use AJAX (asynchronous JavaScript and XML) a so-called Web 2.0 development technique meant to accelerate interaction between browsers and online applications.

      The malware threats tracked by Symantec also sought to propagate themselves more slowly than previous generations to help prevent their detection. The top 10 new strains of malicious software observed by the security company were so-called Trojan attacks, which are typically disguised as legitimate programs.

      For example, Symantec pointed to the Mdropper.H Trojan attack, which exploited a zero-day vulnerability in Microsoft Word and installed a subsequent back door program.

      /zimages/6/28571.gifSpyware, bots, rootkits flood through unpatched IE hole. Click here to read more.

      Sent to a smaller, select user group, the attack attempted to convince people receiving it to open it using several different types of social engineering.

      By using such targeted methods to attacks users, Symantec said the programs are less likely to be found and reported to anti-virus researchers. In the enterprise arena, the attacks most commonly seek to gain access to sensitive corporate information.

      Lending further credence to its assertion that malware and phishing attacks are driven by criminal efforts to make money, Symantec reported that financial services companies were the second most targeted group of users over the first half of 2006, behind only home computers.

      Such attacks attempt to steal companies customer information including credit card or bank account numbers to carrying out identity theft and other forms of fraud.

      “Money is clearly the motivating factor in most of the attacks we see, and the threats are moving downstream as people have become wary of phishing schemes and other attacks meant to appear that they come from large banks, and other well-known companies such as eBay,” said Alfred Huger, senior director of development for Symantecs Security Response unit.

      Next Page: Phishing attacks to get more complex.

      Phishing Attacks to Get


      More Complex”>

      “The attackers are going so far as trying to find out who the customers of a specific bank or credit union may be and targeting them directly. Theyre spending more time doing the upfront work to try and yield greater success from their work.”

      Symantec reported phishing attacks have continued to grow in volume as well as complexity. The company said that over the first six months of 2006 its researchers unearthed a whopping 157,477 unique phishing messages, representing an 81 increase compared to the 86,906 phishing schemes it saw during the second half of 2005.

      Financial services companies continue to draw the most attacks, accounting for 84 percent of the phishing sites discovered by the Symantecs Phish Report Network and Brightmail AntiSpam organization.

      /zimages/6/28571.gifApple ships patch for MacBook Wi-Fi hack. Click here to read more.

      Another increasingly popular trend highlighted in the report is the use of applications designed to appear as legitimate software that actually harbor malware attacks such as spyware and adware.

      Symantec said that three of the top 10 new security risks it observed during the first half of 2006 were misleading applications. A popular format for the attacks is to promise users free desktop security software that actually attempts to steal their personal information or load malware including rootkits onto desktops once installed.

      Looking forward, the anti-virus specialist predicted that polymorphic viruses, or malware strains that change their own signatures each time they infect a new machine to avoid detection from security programs, will continue to grow in popularity.

      The company predicted that code writers at every level of the malware industry, from seasoned criminals to amateurs who buy their threat code from other parties, will adopt the technique to help their work have a more widespread affect and remain hidden on computers for longer periods of time.

      Symantec contends that the use of AJAX and other Web 2.0 technologies will also increase in frequency, specifically leading to an increased number of cross-site scripting and content injection attacks.

      That development has the potential to expose even greater numbers of users to attacks that can be detected by most traditional security tools, researchers said.

      Symantec, which is increasingly competing with software giant Microsoft, is also predicting that vulnerability-finding efforts aimed at its rivals next-generation Vista operating system will ramp up over the latter half of 2006.

      Symantec is one of two companies, along with Adobe Systems, that is expected to present arguments to officials with the European Union about Microsofts push with Vista into new market sectors, specifically the anti-virus arena.

      /zimages/6/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

      Matt Hines
      Matt Hines

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.