Hackers harness popularity of blogging

Blogs used to harbour malicious code

Written by Dinah Greek, Computeract!ve

Cyber-criminals are now taking advantage of blog site to snare unsuspecting victims.

It warned webblogs are being used to harbour malicious code such as Trojans and keystroke loggers warned security firm Websense. The company, which said it had uncovered hundreds of bogus blog sites, said blogging was an attractive vehicle for hackers for several reasons.

Hackers can easily publish their own web pages at no cost and offer large amounts of free storage. They do not require any identity authentication to post information, and most blog hosting facilities do not provide antivirus protection for posted files.

Advertisement

In some cases said Websense, the culprits create a blog on a legitimate host site, post Trojans or keylogging software to the page. They attract traffic to the toxic blog by sending a link through spam email or instant messaging (IM) to a large number of recipients.

In other cases, the blog can be used as a storage mechanism, which keeps malicious code that can be accessed by a Trojan horse that has already been hidden on the user's computer.

Websense issued an alert last month detailing a spoofed email message that attempted to redirect users to a malicious blog, which would run a Trojan horse, designed to steal banking passwords. In this situation, the user received a message spoofed from a popular messaging service, offering a new version of their IM program.

When users clicked on a link they were redirected to a blog page that was hosting a password-stealing keylogger. When predetermined banking websites were accessed, the keylogger (bancos.ju) logged keystrokes and sent them to a third party.

"These aren't the kind of blog websites that someone would stumble upon and infect their machine accidentally. The success of these attacks relies upon a certain level of social engineering to persuade the individual to click on the link," said Dan Hubbard, senior director of security and technology research for Websense.

"In addition, the blogs are being utilized as the first step of a multi-layered attack that could also involve a spoofed email, Trojan horse, or a keylogger."

Tags:

Reader comments

More from Computeractive

News

The latest home computing news

Downloads

The best PC tools, applications and more

Reviews

Independent opinions on new hardware and software

Step-by-step guides

Easy-to-follow projects with pictures

PC Help

Solve PC problems with our Q&A

Videos

PC projects demonstrated and product reviews

Articles

An in-depth look at how to get the best from your PC

Magazine

What's coming up in Computeractive

Forums

Get help with your PC problems from our readers

Competitions

Your chance to win computing prizes

Shopping

Great deals on products, services and more

Computeractive CD Rom 10
All 26 issues of Computeractive from 2007 on one CD-Rom.

Ultimate Guide to PC Troubleshooting
Everything you need to know to solve your PC problems.

Create your own calendars softwareCreate your own Calendars
The fun and easy way to create your own calendars!

Computeractive - Issue 280Computeractive Back Issues
Missed an issue? Click here to find a back issue

Blogs

Windows Watch

Windows Watch

Keeping an eye on the latest XP and Vista news

Remember to check the downloads

06 Jan 2009One of the mostly overlooked changes in Windows Vista is the new Downloads folder in a users account....

Download Junkie

Download Junkie

Your daily dose of download discussion

Keep your system clean and problem free using Sandboxie

06 Jan 2009It's safe to assume that we understand that, when we install software, it will write various files to your system and add...

Advertisement

Free email newsletters

Techno babble demystified...

[Display all definitions]

Or type in any computer-related word and click "Go"

Advertisement

Computeractive is not reponsible for content of Google adverts

Primary Navigation

© Incisive Media Ltd. 2009. Incisive Media Limited, Haymarket House,
28-29 Haymarket, London SW1Y 4RX, is a company registered in the United Kingdom with company registration number 04038503

Search computeractive.co.uk