Feeds

IE exploits top web security threat list

Another attack of the browser blues

  • alert
  • submit to reddit

New hybrid storage solutions

Internet Explorer exploits posed the fastest growing web security threat to enterprises in the last quarter, according to web security services firm ScanSafe. The top exploit (Exploit.HTML.Mht) was used to attack twice as many businesses as any other web security threat in Q2 2004.

While Trojans and worms remain the most significant type of threat, exploits, which accounted for 19 per cent of all attacks recorded by ScanSafe, are growing in prevalence. ScanSafe reckons the many vulnerabilities recently exposed in popular web browsers, such as runaway market leader Internet Explorer, are creating a ready mechanism for crackers to compromise systems simply by conning users into visiting websites hosting malicious content.

"ScanSafe forecasts exploits driven by browser vulnerabilities will become an increased threat to enterprises," said John Edwards, technical director, ScanSafe. "As vulnerabilities continue to emerge in Microsoft Internet Explorer and other browsers, and administrators struggle to update patches, attackers will be quick to take advantage."

Webmail pages remain high risk with 10 per cent of all web attacks monitored by ScanSafe occurring on these sites. Spyware accounted for 12 per cent of all monitored attacks, a continued increase in activity on previous quarters. These sneaky applications secretly monitor a user's online activities and may transmit confidential data to third parties.

London-based security outfit ScanSafe markets a net-based filtering service designed to counter web-borne viruses and malicious code. ScanSafe scans for all web viruses by integrating anti-virus engines from three leading AV vendors with its own proprietary internet-level detection technology, Outbreak Intelligence. The idea is similar to that pioneered by MessageLabs but applied to HTTP traffic instead of email. ®

Related stories

A bumper crop of browser glitches
Germans develop nasty case of IE jitters
Companies adapt to a zero day world
Unpatched IE vuln exploited by adware
Webroot: Spyware is Windows-only

Secure remote control for conventional and virtual desktops

More from The Register

next story
Leak of '5 MEELLLION Gmail passwords' creates security flap
You should be OK if you're not using ANCIENT password
Google recommends pronounceable passwords
Super Chrome goes into battle with Mr Mxyzptlk
Reddit wipes clean leaked celeb nudie pics, tells users to zip it
Now we've had all THAT TRAFFIC, we 'deplore' this theft
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Enigmail PGP plugin forgets to encrypt mail sent as blind copies
User now 'waiting for the bad guys come and get me with their water-boards'
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.