Skip to Content

Free TUAW iPhone app -- try it now!
AOL Tech

Filed under: Internet, Security, News

Web-based malware attacks growing at an astonishing rate


Dasient, the web security firm founded by ex-Google staffers that launched in June of this year, have published a blog post which shows just how dangerous a place the web is becoming.

If you do any computer service - either as a job or a favor to friends and family - you've no doubt seen the end result of these attacks. Fake antivirus applications continue to be the biggest source of business at my day job. That's all thanks to a web that has been slow to adapt to the presence of these threats.

According to the data Dasient has gathered to date, they estimate the number of compromised web sites to be about 640,000. Netcraft puts the total number of sites on the Internet at around 240 million - so compromised sites only amount to .26% of the whole. Still, those 640,000 sites are serving as many many as 5.8 million infected pages says Dasient, up sharply from the 3 million pages earlier this year reported by Microsoft.

Do different methods account for the big change? Not so much, says Dasient. The rapid rate of growth in threats is borne out by the parallel growth of blacklists maintained by companies like Google.

Dasient notes four common weaknesses that are being exploited: compromised FTP credentials, server-side vulnerabilities, unpatched or unknown web application vulnerabilities, and ad networks (even unknowingly) serving malicious ads.

The best "poisoned" advertising example to date would have to be the New York Times website, which was unwittingly serving malicious links just a few weeks ago. The incident underscored just how big a problem this has become. You no longer have to be looking for cracked or pirated software, illegal music, or pornographic pictures and videos to be at risk. Mainstream sites are being targeted, putting even more users at risk.

It's more important than ever to make sure you protect yourself. If you're using Windows, arm yourself with a good antivirus and security tools. Linux and Mac users - yes, you're safe for now from most of these threats but certain attacks - like phishing - can effect you, too. Keep your web browser, plugins, and OS fully updated, and make sure you know what you're clicking before you click it.

For users on any operating system the free WebOfTrust add-on for Firefox, IE, and Google Chrome (read more about the WOT add-on) can help defend you against malicious links and site. It's well worth installing, especially on a Web that is under siege by malware.
jobs & resumes
Lead Blogger

AOL Find a Job - New York, NY (3 weeks ago)

See More Relevant Jobs ›

Reader Comments (Page 1 of 1)

Add your comments

Please keep your comments relevant to this blog entry. Email addresses are never displayed, but they are required to confirm your comments.

When you enter your name and email address, you'll be sent a link to confirm your comment, and a password. To leave another comment, just use that password.

To create a live link, simply type the URL (including http://) or email address and we will make it a live link for you. You can put up to 3 URLs in your comments. Line breaks and paragraphs are automatically converted — no need to use <p> or <br /> tags.

Featured Time Waster

The World's Hardest Game 2.0 - Time Waster

So, just how good at time waster games are you? Think you've got the stuff? Well, The World's Hardest Game 2.0 doesn't think you do. Yes, amazingly, it's possible to have a sequel to a game called "The World's Hardest Game". It doesn't seem logically possible, since if the first one was actually the world's hardest, how could another one come along and share the moniker? It made me doubt the name in the first place. That is, until I tried the game. The mechanics of the game are very simple. You are a small red square, ...

View more Time Wasters

Featured Galleries

Defective by Design, London: Protest Pictures
Microsoft Security Essentials
Chromium Pre-Alpha on CrunchBang Linux
Safari 4 Beta
10 Firefox themes that don't suck
IE8 RC1
Download Squad at the Crunchies After-Party
Download Squad at the Crunchies
WordPress 2.7
Cooking Mama: Mama Kills Animals
Windows 7 Hands On
Comodo Internet Security
Android First-look: Amazon.com MP3 Store
Android First-look: Twitroid
Google Reader Android
Android Hands-On
Twine 1.0
Photoshop Express Beta
Mozilla Birthday Cake
Palm stuff
Adobe Lightroom 1.1

 


Follow us on Twitter!

Flickr Pool

www.flickr.com

More Tech Coverage

AOL Radio

Joystiq

TUAW

Daily Finance

Autoblog

Urlesque

Engadget

WoW

Switched.com

FanHouse