Hackers place key-logging software onto blog sites
Hackers place key-logging software onto blog sites
R E L A T E D   C O N T E N T
ADVERTISEMENT

Unchecked blogs a boon to hackers

Free and anonymous hacking tools storage

Iain Thomson, vnunet.com 15 Apr 2005
ADVERTISEMENT

Blogging sites that fail to check software stored by users are proving useful to hackers, according to web monitoring firm Websense.

The company claims to have identified hundreds of cases of hackers using blogs to store Trojan software and other malicious code, because blogging firms seldom check to see what code they are hosting.

"Blogs allow you anonymously and freely to gather and create accounts," said Dan Hubbard, senior director of security and technology research at Websense.

"Most have quite a bit of hosting space available too. Some blog site hosters allow you to post attachments, but most do not check the code that is posted so it could be anything."

Hubbard explained that hackers exploit blogs in a number of ways. In March a hacker placed key-logging software onto a blog site. The URL was then spammed out purporting to be a message from a popular messaging service.

The message offered a new version of an instant messaging program, but when users clicked on the link the key-logging software was installed.

A more advanced technique is to use a blog page to store malicious code updates. Many so-called zombie PCs update the Trojan software regularly, and a blogging site offers an anonymous and free website that can be used to store the update software.

Both methods use browser attacks, which experts warn are becoming increasingly popular. These attacks bypass firewall and intrusion detection software by entering systems through improperly patched browsers.

See also:

Change is vital to keep up with creation and use of digital contentTraditional legislation failing to cope  26 Apr 2005
Panel debate discusses vertical bloggingCommercial blogging firms must tread very carefully  25 Apr 2005
Today's online freedom 'should not be taken for granted'Attempts to muzzle bloggers 'not limited to governments'  25 Apr 2005
UK parties 'ignore blogs at their peril'Lessons from the US suggest blogs will influence results  14 Apr 2005
Bloggers risk the sack as companies clamp downBloggers and podcasters beware ...  24 Feb 2005

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| JAM Recruitment
Software Test Engineer 6 Weeks Contract £ 35 per hour Wiltshire We have an urgent need for a Software Test Engineer. Main Duties: ·Sound understanding of full software lifecycle ·Solid experience in requirements analysis ·Requirements ... more >
| JAM Recruitment
Software Test Engineer 3 Months Contract £35 per hour Wiltshire We have an urgent need for a Software Test Engineer. Main Duties: ·Sound understanding of full software lifecycle ·Solid experience in requirements analysis ·Requirements based ... more >
| Aston Carter
Major Investment Bank requires a Business Analyst to work within reference data IT. The reference data IT function is responsible for the three internal systems. One of the systems is a strategic repository for Client ... more >
| JAM Recruitment
Job Ref: CY - 27021979 Package: £25 – 42,000 +Bens Location: YORKSHIRE Job type: Occupational Health Position type: Permanent Hours: Full time Contact name: Mr Colin Youle Contact Company: JAM HUMAN RESOURCES Are you a ... more >
More job opportunities