The booming hacking business
- 26 July, 2007 20:43
- Comments
It's a good time to be a malicious hacker. That's because even though it's not a time of revolutionary new techniques in hacking for profit, business is booming for the established methods. Despite increased investment in information security defenses, the good guys continue to lag badly behind. According to one report by Sophos, which called the recent uptick in malware a "deluge," by April 2007, more than 250,000 websites were hosting malicious code and more than 8,000 were being added to that total every day.
A sample of the deluge:
Hackers compromised Google AdWords so that links on certain sponsored ads were redirected to the attackers' website first, where an attempt was made to install a keylogging bot.
Zero-day exploits in Windows were discovered, including a critical flaw in animated cursor files that would allow an attacker to commandeer a PC.
Incidents of iFrame malware--code that lives in an invisible-to-the-eye frame on a website and delivers bots onto the PCs of people visiting the site--have increased.
Credential-stealing bots like Gozi and Torpig continued to troll for personal banking information on infected computers.
A hacker won US$10,000 breaking into a Mac through the Safari browser, which was followed by Apple releasing a patch for 25 vulnerabilities.
A researcher announced she is planning to demo ways to install rootkits and perform encryption attacks on Microsoft's new Windows Vista product at this summer's Black Hat conference.
A 17-year-old was charged with hacking into AOL, using a phishing scheme against AOL employees and using unauthorized instant messaging accounts, with the intent to transfer confidential data.
The only response for many information security professionals is to stay on top of the latest developments and prioritize response according to need. But that's getting harder to do with the sheer volume of information on new attacks.
Many are also met by apathy or skepticism when trying to shed light on the problems. "It is hard to discuss solutions when no one believes there is a problem," says Eric Hacker, a CISSP who works for a technology company. "The culture cannot mix security and business for whatever reason."
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- Collaborative software delivery: Managing today’s complex environment to improve software quality
- Improving Productivity in the Connected Enterprise Through Collaboration
- Reconciling Datacenter consolidation and security: It starts with an integrated approach
- Configuration, Not Coding
- A Governance Guide for Hybrid SharePoint Migrations
-
Australia's first 4G smartphone is the HTC Velocity 4G
-
Swedish e-commerce startup's execs linked to NYC sex crime
-
Face Time - Interview with John Brennan and Robert DiStefano
-
How to implement next-generation storage infrastructure for Big Data
-
Pfizer's Future Depends on IT Transformation
-
IDC Insight: V-Ray Gives Symantec NetBackup a Competitive Advantage Today and into the Future
Over a decade ago, Veritas software announced NetBackup FlashBackup to address the millions of small files problem, which had been and often remains the nemesis to fast and efficient backup of large file servers. Today, the FlashBackup technology is used to provide a logical understanding of what is stored with a VMDK- or VHD-image-level backup, without the necessity to install an agent inside each virtual machine. Read more. -
INFORMATION FOR SUCCESS - Customers Achieve Extreme Performance at Lowest Cost with Oracle Exadata Database Machine
How do you prioritize IT investments to ensure support for growing volumes of data and still meet your business users’ evolving requirements—such as competing more effectively, reducing IT costs, meeting compliance requirements, or anticipating changing market conditions? Read on. -
Look both ways - Protecting your data with content inspection
Today’s threat environment is as dynamic as the business world in which we operate. As the communications channels we use continue to proliferate and evolve, so too have the vulnerabilities. Finding the right balance between ensuring the security of sensitive data, enabling the free flow of information and making full use of the latest web-based technologies can be a challenge. Deep content inspection is a vital layer in any unified information security strategy, helping organisations to take control over their information assets while proactively protecting against malware and data leakage. Read on.
-
Teach Yourself Visually Windows 7
-
Computers for Seniors for Dummies, 2nd Edition
-
Office 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Dummies®
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Dummies® Dvd+book Bundle
-
MYOB Software for Dummies 6E Australian Edition
-
Office 2007 for Dummies
-
Windows 7 for Seniors for Dummies®








Comments
Post new comment