Newsletter:

Skip Navigation LinksHome > News > Security > Global web threats go local

Global web threats go local

By Phil Muncaster
25 February 2008 03:22PM
Tags: global | web | threats | local

The increasing sophistication of malware writers has been highlighted once again in a new report by web security firm McAfee.

The annual Global Threat Report found that internet criminals are now concentrating on configuring their attacks to specific geographic locations and languages to achieve greater success rates.

Spam and phishing emails for example are increasingly being written so that they appear in the native language of the recipient, while malicious web sites serve up malware in a language determined by the country the target is located in.

Criminals are also looking to exploit popular local applications such as banking web sites, crafting software which can determine specifically which user details need to be intercepted to ensure a successful attack, according to Toralv Dirro, McAfee Avert Labs Security strategist.

The report also drew attention to the exploitation of the user-generated content on many so-called web 2.0 sites such as Wikipedia and MySpace, to embed malicious code in these web pages.

"For the operators of these sites it would be a good idea to automatically convert pictures from one format to another to remove some of the exploits," he explained. "And for enterprises, if you allow your users to visit these sites you should make sure you filter not just email but http traffic."

itweek.co.uk @ 2008 Incisive Media

   


Ads by Google


Thoughts on this article? Add a comment below.
Comments: 1
If website owner would take more care about their web applications and use a scanner (ie. maui security scanner), spammers and hackers wouldn't be able to abuse their server so easy.

Seems like the companies still think that firewalls would solve all their security problems.
iTnews - comments icon Posted by MichaelMar 2, 2008 5:55 AM
Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch





Product Reviews

Star Rating
The Cyber-Ark Enterprise Password Vault, or EPV, is a high-end password management powerhouse.
Star Rating
The Hitachi ID-Archive sets its focus on password randomisation.
Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Star Rating
On the surface, RoboForm Enterprise starts out looking like a single sign-on product, but that is just on the...
Unified Communications Podcast Centre

TopTopics
(7043) -  microsoft
(6494) -  iinet
(6485) -  copyright
(6485) -  afact
(6426) -  internet
(5935) -  servers
(5935) -  mipi
(4305) -  telstra
(4106) -  phone
(3755) -  broadband
(3672) -  nvidia
(3606) -  nbn
(2439) -  avg
(1972) -  onecare
(1924) -  google