ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Hundreds of sites infected with dynamic malware

Tom Espiner ZDNet.co.uk

Published: 18 Jan 2008 16:58 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Approximately 230 UK websites have been infected with malware that is being delivered dynamically, according to security vendor ScanSafe.

The malware being delivered ranges from backdoor Trojans to rootkits, said ScanSafe researcher Mary Landesman.

The companies hosting the sites are being hit with dynamic modules of JavaScript that are proving very difficult to get rid of, according to Landesman.

"Even though the hosts are working diligently, their systems are being recompromised repeatedly," Landesman told ZDNet.co.uk on Thursday. "This is not just a matter of wipe and restore. The attack is extremely sophisticated."

The complexity lies in discovering how the hosting companies are being infected and reinfected, said Landesman, who declined to name the companies involved. ScanSafe is in the process of investigating the infection process, with security researchers from SecureWorks.

"The million-dollar question is how the [JavaScript] modules are getting onto the host server," said Landesman. "It's that initial entry we're still trying to figure out."

The researchers initially suspected reinfection to be the result of a rootkit-enabled Loadable Kernel Module planted on the host servers. However, Landesman said this is now looking less likely, as a number of the hosts rebuilt their Apache kernels, and suffered reinfection.

"There could be some underlying compromise, but a rootkit on the server is seeming less likely," said Landesman. "There could be a rootkit or backdoor on a managing workstation in the host."

Not only are the hosts being mysteriously reinfected, but the malware delivery process is itself dynamic, making detection via antivirus signatures difficult, said ScanSafe. When a user visits an infected site with JavaScript enabled on their browser, they are infected by JavaScript files with randomly assigned five-character names.

"Once they are in the door, the attackers are leveraging the promiscuous behaviour of modules on Apache servers to accept and run scripts — they're responsible for controlling the impact of malware we're seeing on the websites," said Landesman. "The scripts are randomly generated."

Read this

Feature
Feature: Cracking open the cybercrime economy

Hacking for fun has evolved into hacking for profit, and created a business model that is nearly as sophisticated as that of legal software

Read more +

The JavaScript files can infect users with up to a dozen exploits, including an Apple QuickTime Real-Time Streaming Protocol vulnerability, an older Microsoft Data Access Components vulnerability, as well as sophisticated Trojans and rootkits, according to a post on the ScanSafe blog.

The randomly named and dynamically created JavaScript references and files are also randomly delivered, said ScanSafe. That delivery is not based on whether malware has been delivered to that user before; it will deliver the script to the same IP address multiple times.

Another piece of the puzzle is the high amount of traffic to infected sites, which ScanSafe describes as "unexpectedly high".

While 230 predominantly UK sites are known to be infected, exact numbers of infected sites and hosts are difficult to gauge, said Landesman.

Compromised sites in the past have predominantly had static iframe code pointing to malicious sites, served by a host. This makes it relatively easy to detect which hosts are infected, said ScanSafe, as a search on the contents of the HTML iframe results in a list of infected sites. However, in this attack the referenced JavaScript doesn't "exist" until the user accesses the page, and it doesn't persist on the site.

"We don't know how many hosts are infected," said Landesman. "An admin perusing the site looking for these rogue JavaScript files [on a host server] would not find any visible signs."

ScanSafe advised concerned businesses to inform users of the attack, and said that one possible workaround was to encourage users to disable JavaScript in web browsers, even though this would severely limit web functionality.

Another alternative is for users to scan search results using free tools such as ScanSafe's Scandoo beta, the company said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
15 out of 17 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

WebMaster opportunity - Worlds leading Sports and Media Company

You must have strong commerical experience in web development or design or as a Webmaster as well as a technical understanding (the more the better) ...

C# HTML CSS JavaScript Web Developer Huddersfield Up To 30,000

Our client specialises in providing bespoke web based applications and websites for a whole host of branded clients. In this role you will be working ...

ASP / Web Developer - Professional Association - 35k - London

In the role you will be managing the day to day running of the technologies needed to support the online services including hosting all of their ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment