Report: Attackers Adopt Stealth Tactics

LOS ANGELES — Computer security systems provider Symantec has released its 13th Internet Security Threat Report, which analyzed Internet attacks and vulnerabilities such as malicious code, phishing, spam and other security risks over the past six months.

One of the report's findings is that long-known vulnerabilities still exist, due to mistakes made by webmasters that allow hackers to gain control of their websites — and the computers of unsuspecting visitors to their websites.

Despite decade-old solutions for dealing with some of these problems, the Symantec report revealed that the number of these readily compromised (and readily secured) websites doubled in the latter part of 2007, providing many attractive opportunities for tech-savvy criminal enterprises that do not have to lure surfers into "bad neighborhoods" before launching attacks from legitimate — but poorly coded — websites.

"It overturns the whole notion that if you stay away from gambling and porn sites you are okay," said Kevin Hogan, Symantec director of security operations.

Cross-site scripting, or XSS, is the culprit behind some of these malicious attacks, and works by targeting improperly secured data transfers between web browsers and servers.

For example, XSS vulnerabilities can provide member login information to hackers, complicating paysite owners' efforts to fight password sharing.

XBIZ previously reported on a Flash bug that used XSS and that may be particularly common on adult websites.

The Symantec report attributes attackers' adoption of stealth tactics targeting individual computer users via the Internet to the effectiveness of enterprise networks in fighting "brute force" and other attacks on their systems.

End-users are more easily compromised by malicious activity because of their typically inadequate approach to security — a situation that is compounded by the fact that the site containing the compromised code is unlikely to detect it, guaranteeing further infections.

The Symantec report claims that social-networking sites are a favorite target for attackers, as they present a large audience that is likely to trust the site and reveal confidential or personal information, which could lead to fraud and identity theft.

According to the report, 11,253 specific XSS vulnerabilities were discovered in the final six months of 2007 — up from 6,961 during the first six months of the year — though many other cases have gone unreported.

"There are a lot more websites out there that are prone to this," Hogan said. "It's a much bigger proposition to make a safe website than it is to patch a browser."

Related:  

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Georgia Gov. Brian Kemp Signs Age Verification Bill Into Law

Republican Gov. Brian Kemp signed into law on Tuesday a bill that includes Georgia’s version of the age verification of adult content provisions being sponsored around the country by anti-porn religious conservative activists.

AEBN Publishes Popular Searches by Country for February, March

AEBN has released the popular searches from its straight and gay theaters in more than three dozen countries during February and March.

HardWerk Relaunches Through YourPaysitePartner

HardWerk.com has relaunched through YourPaysitePartner (YPP).

Aylo Asks Judge to Trim Sweeping GDP-Related Lawsuit

Aylo asked a California federal judge during a hearing on Monday to drop trafficking claims from a sweeping lawsuit brought by a former GirlsDoPorn model.

California Republicans, Democrats Team Up to Advance Age Verification for Porn

Both Republicans and Democrats in the California Assembly’s Privacy and Consumer Protection Committee voted last week to move forward a version of the age verification bills being sponsored around the country by anti-porn religious conservative activists.

Cosplayground Releases 'Furiosa XXX: A Porn Parody'

Cosplayground has released its seventh original production, “Furiosa XXX: A Porn Parody.”

Washington Post Spotlights ECP VP Solomon Friedman's Appearance at XBIZ LA

The Washington Post published this weekend a lengthy feature about Pornhub and Aylo, focusing on Ethical Capital Partners’ VP of Compliance Solomon Friedman’s keynote address and other appearances at XBIZ Los Angeles in January.

'Sex Workers Deserve Protections': Congressional Candidate Joe Cohn Reaches Out to Adult Community

Veteran civil rights attorney Joe Cohn, who is currently running in a New Jersey Democratic primary for a seat in the U.S. House of Representatives, says he is reaching out to the adult community to champion an inclusive approach to civil liberties that encompasses all sex workers and adult businesses.

Mile High Unveils New Unscripted Studio 'Sex on Sight'

Mile High Media has launched a new unscripted-content studio, Sex on Sight.

Belgian Producer Dennis Black Magic Sentenced to 7 Years for Rape, CSAM

Belgian adult producer and director Dennis Black Magic has been sentenced to seven years in prison and a $4,000 fine for the rape of eight models and distribution of CSAM.

Show More