misasia logo
Hackers are more frequently infecting mainstream websites with malicious code By Jared Heng
17 Sep 2008

SINGAPORE, 17 SEPTMBER 2008 -- Hackers have attacked BusinessWeek’s website in a bid to infect its readership with malware, according to Sophos.

Hundreds of web pages in a section of the weekly magazine’s website were affected, the IT security firm said. The section contains information about where MBA students might find future employers.

According to Sophos, the hackers used an SQL injection attack, which exploits a vulnerability to insert malicious code into the website's underlying database. Last week, Sophos informed BusinessWeek of the infection, which peppers pages with code that tries to download malware from a Russian web server.

“It’s worrying when any site suffers from a malicious SQL injection attack, but when it's also one of the 1,000 busiest websites on the internet, the stakes are even higher,” said Graham Cluley, senior technology consultant at Sophos.

Cluley noted that the potentially large number of people visiting the site and accessing career information may be putting their finances or personal data at risk if they are not properly protected.

Increasing attack rate

Earlier this year, Sophos reported that it identified some 16,000 new infected web pages every day. Ninety per cent of these were on legitimate sites like BusinessWeek that had been hacked.

The IT security firm said that it currently discovers a new malicious web page every five seconds, three times faster than the rate seen last year.

While the Russian website is currently down and not delivering further malicious code against BusinessWeek, the attack could be revived at any time, according to Sophos.

“BusinessWeek and many other firms hit by SQL injection attacks need to move fast to not only remove the malicious scripts, but also to ensure that they do not get infected again,” Cluley said. “Companies whose websites have been struck by such an attack often clean up their database, only to be infected again a few hours later.”

Cluley said that all web surfers need to ensure that visited pages are scanned for dangerous code. “That’s because an increasing number of sites are being discovered each day hosting malware.”


Comments

Be the first to comment.


Post your comment

  • Please use English to post and reply to comments
  • Please do not use offensive language in the form of racial or ethnic slurs, abuse or personal insults
  • We welcome opinion and debate geared towards finding solutions
  • Please keep comments relevant to the topic
  • All comments are moderated
** Mandatory Field

Name
    **

Email
    **

Country


Comments
Maximum characters allowed: 2000
Disclaimer: All the content posted in this category comes independently from readers of Fairfax Business Media (FBM) Asia publications, unless specified otherwise. Fairfax Business Media (FBM) is not responsible for the opinions of its readers and the content posted by them does not represent the views and opinions of FBM.

Feature

Zafar Anjum

Techlightenment

Are cell phones more dangerous than terrorists?

Is there a connection between cell phones, bees and global food security?
By Zafar Anjum | 17 Mar 2010

RSS Feeds

Add this section to your favourite feed reader.