Drive By Download Sites Using New Tricks To Avoid Detection
Amid an increase in defacements of legitimate websites over the past few weeks, Fraser Howard, a researcher from Sophos, has discovered that the groups behind the attacks are increasingly using sophisticated filtering and dynamic content to avoid detection by search engines and web filtering firms.
If an older generation of drive-by Web attacks were dumb, this new generation is intelligent, Howard said. According to his report, many sites that Sophos found hosting attacks are using complex logic to limit who is served malicious content include - or block - malicious code injection depending on the source of Web traffic requests to the compromised sites.
Howard's study of the malicious payloads found logic that allowed the attackers to automatically check for requests from bot-infected hosts versus uninfected hosts or search engine Web crawlers. The goal was to serve malicious attacks (either iFrame attacks or malicious Javascript) to uninfected hosts, while steering clear of search engines or other monitoring outfits looking to blacklist compromised pages. The code analyzed by Howard included local IP blacklists that ensured search engine bots were only served clean HTML pages, while users who had already been hit didn't get reinfected, which Howard says makes it harder to investigate the problem.
Head over the Naked Security to read Howard’s entire report and check out a diagram that illustrate this type of attack.
Commenting on this Article is closed.
Today's Most Popular
- Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops
- Dear Jailbreaker, Apple Wants to Have a Word with You
- ZTE Score M Android Phone Found to Have Backdoor Installed
- OPINION: Are Anonymous Members Forged in the Crucible of IT Compliance?
- New P2P Zeus Variant Targets Popular Sites with Bogus Offers
Most Commented Stories
-
Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops (5)
-
Spammers Targeting Pinterest Using Point-And-Click Tools (1)
-
White House Security Czar Howard Schmidt Retiring (3)
-
Hijacked Web Sites Among The Most Visited On Google's Black List (2)
-
New P2P Zeus Variant Targets Popular Sites with Bogus Offers (1)
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.



