Drive By Download Sites Using New Tricks To Avoid Detection
Amid an increase in defacements of legitimate websites over the past few weeks, Fraser Howard, a researcher from Sophos, has discovered that the groups behind the attacks are increasingly using sophisticated filtering and dynamic content to avoid detection by search engines and web filtering firms.
If an older generation of drive-by Web attacks were dumb, this new generation is intelligent, Howard said. According to his report, many sites that Sophos found hosting attacks are using complex logic to limit who is served malicious content include - or block - malicious code injection depending on the source of Web traffic requests to the compromised sites.
Howard's study of the malicious payloads found logic that allowed the attackers to automatically check for requests from bot-infected hosts versus uninfected hosts or search engine Web crawlers. The goal was to serve malicious attacks (either iFrame attacks or malicious Javascript) to uninfected hosts, while steering clear of search engines or other monitoring outfits looking to blacklist compromised pages. The code analyzed by Howard included local IP blacklists that ensured search engine bots were only served clean HTML pages, while users who had already been hit didn't get reinfected, which Howard says makes it harder to investigate the problem.
Head over the Naked Security to read Howard’s entire report and check out a diagram that illustrate this type of attack.
Commenting on this Article is closed.
Today's Most Popular
- Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops
- Iranian Students Claim to have Stolen Thousands of Researcher's Records
- Report: Diablo III Users Find Accounts Hacked, Gold Stolen And New 'Mystery' Friends
- Why Google Won't Protect You From Big Brother
- Forget 'Brogrammers,' Women Have The Edge In DEFCON Social Engineering Contest
Most Commented Stories
-
Forget 'Brogrammers,' Women Have The Edge In DEFCON Social Engineering Contest (9)
-
Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops (9)
-
HULK DDoS Tool Smash Web Server, Server Fall Down (3)
-
Author of LilyJade Facebook Plugin Ignores Facebook Cease-and-Desist (3)
-
Report: Diablo III Users Find Accounts Hacked, Gold Stolen And New 'Mystery' Friends (2)
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.



