March 19, 2010

Malware Spreading via News Sites

Hackers are exploiting vulnerabilities in appleinsider.com, lawyer.com, news.com.au and a dozen other sites.

"The ongoing attacks are notable because they use exploits based on XSS, or cross-site scripting, to hide malware links inside the URLs of trusted sites," writes The Register's Dan Goodin. "That's something [Zscaler] application security expert Mike Geide doesn't see often. As a result, people who expect to visit sites they know and trust are connected to a page that tries to trick them into thinking their computer is infected."

"The links work because appleinsider.com and the rest of the sites being abused fail to filter out harmful characters used in XSS attacks," Goodin writes.

Click here to read the story at The Register.

1



IT Offers





Partners