About RSS
Search for: in 

Windows Watch - an XP & Vista blog

R E L A T E D   C O N T E N T

Free email newsletters




Jargon Buster

ADVERTISEMENT

Hackers harness popularity of blogging

Blogs used to harbour malicious code

Dinah Greek, Computeract!ve 14 Apr 2005
ADVERTISEMENT

Cyber-criminals are now taking advantage of blog site to snare unsuspecting victims.

It warned webblogs are being used to harbour malicious code such as Trojans and keystroke loggers warned security firm Websense. The company, which said it had uncovered hundreds of bogus blog sites, said blogging was an attractive vehicle for hackers for several reasons.

Hackers can easily publish their own web pages at no cost and offer large amounts of free storage. They do not require any identity authentication to post information, and most blog hosting facilities do not provide antivirus protection for posted files.

In some cases said Websense, the culprits create a blog on a legitimate host site, post Trojans or keylogging software to the page. They attract traffic to the toxic blog by sending a link through spam email or instant messaging (IM) to a large number of recipients.

In other cases, the blog can be used as a storage mechanism, which keeps malicious code that can be accessed by a Trojan horse that has already been hidden on the user's computer.

Websense issued an alert last month detailing a spoofed email message that attempted to redirect users to a malicious blog, which would run a Trojan horse, designed to steal banking passwords. In this situation, the user received a message spoofed from a popular messaging service, offering a new version of their IM program.

When users clicked on a link they were redirected to a blog page that was hosting a password-stealing keylogger. When predetermined banking websites were accessed, the keylogger (bancos.ju) logged keystrokes and sent them to a third party.

"These aren't the kind of blog websites that someone would stumble upon and infect their machine accidentally. The success of these attacks relies upon a certain level of social engineering to persuade the individual to click on the link," said Dan Hubbard, senior director of security and technology research for Websense.

"In addition, the blogs are being utilized as the first step of a multi-layered attack that could also involve a spoofed email, Trojan horse, or a keylogger."

See also:

UK parties 'ignore blogs at their peril'Lessons from the US suggest blogs will influence results  14 Apr 2005

All Online

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Welwyn Garden City, Hertfordshire, United Kingdom | Tesco.com
Subject Matter Expert - Welwyn Garden City  Who's behind the world's most successful online retailer? Just over 10 years ago we started Tesco.com (aka Dotcom). Today, we've an incredible 750,000 active customers and sales at ... more >
Chichester, West Sussex, United Kingdom | West Sussex County Council
Application Support Specialists £26,449 - £28,723 pa (includes Market Rate Supplement) ChichesterIT Services at West Sussex County Council supports and manages a variety of systems that include third party and bespoke applications as well as ... more >
Shinfield Park, Reading, United Kingdom | Foster Wheeler
Our UK-headquartered operations employ more than 6,000 people and we are seeking qualified and experienced IT professionals to work in our head office in Reading, Berkshire. We are currently seeking an Analyst Programmer to join ... more >
Welwyn Garden City, Hertfordshire, United Kingdom | Tesco.com
Database Developer - Welwyn Garden CityWho's behind the world's most successful online retailer? Just over 10 years ago we started Tesco.com (aka Dotcom). Today, we've an incredible 750,000 active customers and sales at just under ... more >
More job opportunities
ADVERTISEMENT