Advertisement
Promo

Security threats Toolkit

Google warns of 'drive-by download' risk

Tim Ferguson silicon.com

Published: 15 May 2007 10:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Google has warned web users of the increasing threat posed by malware that can be dropped onto a computer as a web surfer visits a particular site.

The search giant carried out in-depth research on 4.5 million websites and found one in 10 web pages could successfully launch a "drive-by download" — such as a Trojan — onto a user's computer.

The software potentially allows hackers to access sensitive corporate information or install rogue applications.

Sentry Posts Blog

Sentry Posts Blog
Guarding the network

What you need to know — and what you and your peers have to tell us — about security management in our new community group blog

Read more +

Graham Cluley, senior technology consultant at Sophos, said Google is right to highlight what he said is a worsening trend and "a considerable problem" for businesses and end users.

Cluley said an average of around 8,000 new URLs containing malware emerged each week during April.

Most worryingly, 70 percent of URLs hosting such malware are found on legitimate websites that have been targeted by hackers. The notion that malware only resides in the darker corners of the internet is now outdated.

The means used to place malware on websites include breaches of web server security, user-posted content, rogue advertising and third-party widgets.

Cluley said: "They [hackers] used to spread malware by email attachment. What they do now is spam out URLs."

He warned businesses: "You cannot protect users by restricting what sites they go to. You need to start protecting your web access, as well as your email gateway."

Google's The Ghost in the Browser report said the rise in web-based malware has been aided by the increasing role the internet plays in everyday life, along with the ease of setting up websites.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
48 out of 50 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters