ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Italian develops first multi-site web-mail worm

Nick Gibson Builder AU

Published: 13 Jul 2007 09:31 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

An Italian security researcher this week has developed the first web-based email worm capable of taking advantage of cross site scripting (XSS) vulnerabilities in multiple web-mail services.

Rosario Valotta described the new form of worm on his blog. The proof of concept, called Nduja Connection, could spread faster than a worm targeting only a single web-mail provider, he said.

Email worms propagate by extracting contact information from the address book of each infected user, and then sending out an email with the worm payload to each contact — a user needs only to open an infected email message to spread the worm.

Prior-concept email worms have been restricted to affecting only one email client; however, the Nduja Connection worm has the potential to spread faster due to its ability to infect users of four different web email clients.

The four web-mail services affected by the worm are Italian providers Libero.it, Tiscali.it, Lycos.it and Excite.com. "The choice of the providers of this [proof of concept] has been bound to the presence of an exploitable [vulnerability] (with the above features) within the web-mail domain. Also other popular providers (for example Gmail, Yahoo, Hotmail) suffer from XSS [vulnerabilities] in their web-mails, but their severity is not so high to let worms like Nduja Connection to propagate," Valotta wrote.

Web-mail worms have existed in the wild since 2006, when the Yamanner worm targeted the Yahoo email system and spread quickly throughout users of the system. It is difficult to quickly stop or slow the spread of this kind of worm once it has begun, due to its use of JavaScript. Turning off JavaScript in the browser renders the web-mail system unusable.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
13 out of 13 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

London City - F/o, Excel, VBA dev

London City - F/o, Excel, VBA dev My Client, a leading investment manager require an Excel VBA developer to work on a project for the FX Forward Desk ...

S50829: Market Data Desktop Operations Support Analyst1

Quotes, permissioning, level 1 quote and level 2 quote differences, basic structure of an order book, different types of markets, etc. Understanding ...

Customer Solutions Engineer / Software Engineer - HTTP, HTML, XML, DNS and TCP/IP,C++, Java, PHP or Python - London, South East

Customer Solutions Engineer / Software Engineer - HTTP, HTML, XML, DNS and TCP/IP,C++, Java, PHP or Python - London, South East The area: Customer ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation