ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Samsung site hosts Trojan, warns security firm

Munir Kotadia CNET News.com

Published: 11 Sep 2006 16:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Samsung Electronics' US Web site is hosting a Trojan horse that logs keystrokes, disables antivirus applications and steals online banking access codes, according to Internet security company Websense.

"Currently, there is no exploit code on the Web site that attempts to trigger a download of the file without user interaction," Websense said in an alert this week. "The site is hosting and most likely distributing files to users who are lured through instant messaging or email links."

Joel Camissar, Australian country manager for Websense, told ZDNet Australia that Samsung has been informed about the issue but has not yet removed the offending files.

"As of (Friday morning Sydney time), the malicious code on the Web site was still active," he said.

According to Websense's alert, the site "has been hosting a number of directories and files which, when downloaded and run, install malicious code on end-users' machines. The server appears to have been compromised and has been hosting a variety of files for some time."

Camissar acknowledged it was possible that the hackers who compromised Samsung's server would have been able to modify the company's Web site so visitors using a vulnerable browser would become automatically infected with the malicious software.

"Why not hack into a site that people are visiting that is a trusted brand? Trust is so important these days. People are being preached to by banks not to trust links (in unsolicited emails) — that is something people are starting to follow. So if one does go to a site that is trusted, it is certainly a very easy way for hackers to compromise users," Camissar said.

Earlier this week, Dave Cole, director of Symantec Security Response, warned on his blog that hackers are exploiting Web technologies such as AJAX and JavaScript to compromise "trusted" Web sites with malicious software.

"It's worth noting that most high-impact attacks may be performed on popular sites where someone has embedded an attack in an otherwise benign location for user-created content, advertisements or comments. Sure, there will be enticements to bring people to outright nasty sites loaded with exploits, but a more successful and insidious attack would leverage a person's trust of an already known, popular site," wrote Cole.

Cole said these kinds of attacks are still in the early stage. "From port scanning to fingerprinting and basic network mapping, all done using the Ajax group of technologies, it's clear that we've only begun to see what's possible via malicious Web sites," he wrote.

"While they may not have the immediate impact of a WMF-style vulnerability (that is, remote admin-level control), they leave no trace once the browser is closed and don't rely on a researcher uncovering a Godzilla-style hole in a popular Web browser," he added.

Last month, the School of Media, Film and Theater at the University of New South Wales acknowledged that one of its Mac servers had been compromised and used to host a potentially malicious file, which was disguised as a Microsoft security patch.

Samsung was unavailable for comment.

Munir Kotadia of ZDNet Australia reported from Sydney.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
126 out of 216 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

CRM Technical Project Manager

Prime focuses are on having a trusted Practical, experience-based evidence to justify PMI Senior Project Manager equivalency; - Experience of working ...

Helpdesk & Support Administrator (Support Analyst / Desktop Support) - Watford, South East

Confidence; works under pressure without panicking - Trustworthy; can be trusted with commercially confidential information - Reliable; does what ...

.NET / Windows Developer - London - .NET / SQL / Windows

.NET / Windows Developer - London - .NET / SQL / Windows WebFusion, based near Uxbridge, is seeking a .NET Windows developer with sysadmin skills to ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments