Feeds

Cybercrooks get faster, further and sneakier

Browser plug-ins flaws help hackers build botnets

5 things you didn’t know about cloud backup

Cybercrooks are becoming faster at utilising newly-discovered browser exploits. More than nine in ten of all browser-related exploits occurred within 24 hours of an official vulnerability disclosure, according to a survey by IBM's X-Force security division.

The cyber-threat survey, which looked closely at information security events that happened during the first half of 2008, also revealed that attacks targeting flaws in browser plug-ins are increasing in prevalence. In the first half of 2008, around 78 percent of web browser exploits targeted browser plug-in bugs.

X-Force operations manager Kris Lamb said that the "acceleration and proliferation" of bugs were key themes for the first half of 2008.

The IBM division reckons the increasing use of automated tools allows hackers to become faster off the mark in exploiting vulnerabilities. It criticised the practice of releasing "exploit code along with a security advisory" as playing into the hands of hackers. According to the study, vulnerabilities disclosed by researchers are twice as likely to have zero-day exploit code published.

The counter-argument to this, of course, is that security researchers publish proof of exploit code to establish that their concerns are valid. Publishing details about flaws encourages vendors to be more proactive about developing patches, benefitting the internet community as a whole over the long run.

More than half of the vulnerabilities tracked by X-Force in 1H 2008 involved web server applications. SQL injection vulnerabilities jumped from 25 per cent in 2007 to 41 per cent of all web server application flaws in the first half of 2008. Such vulnerabilities are often used by hackers to plant malicious code of vulnerable websites, a key component in so-called drive-by download attacks which are displacing poisoned email attachments as the preferred method to serve up malware.

In other developments, spammers have abandoned the use of image-based spam, file attachment spam and other such frippery by going back to basics. Nine in ten spam messages now contain little more beyond a few simple words and a URL. The report adds that Russia continues to be the biggest single originator of spam (the starting point of 11 per cent of the world’s junk). Turkey (eight per cent) and the US (7.1 per cent) also crop up as a frequent source of junk mail traffic.®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Ice cream headache as black hat hacks sack Dairy Queen
I scream, you scream, we all scream 'DATA BREACH'!
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
JLaw, Kate Upton exposed in celeb nude pics hack
100 women victimised as Apple iCloud accounts reportedly popped
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
New Snowden leak: How NSA shared 850-billion-plus metadata records
'Federated search' spaffed info all over Five Eyes chums
Three quarters of South Korea popped in online gaming raids
Records used to plunder game items, sold off to low lifes
Oz fed police in PDF redaction SNAFU
Give us your metadata, we'll publish your data
prev story

Whitepapers

Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Advanced data protection for your virtualized environments
Find a natural fit for optimizing protection for the often resource-constrained data protection process found in virtual environments.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.