The Web sites of three of the security industry's best-known companies include security flaws that could be used to launch scams against customers, according to a new report.
The report, from security watchdog site XSSed, verified 30 cross-site scripting (XSS) vulnerabilities across the sites of McAfee, Symantec and VeriSign. The flaws could be used to launch scams or implant malicious code on the systems of visiting users, according to XSSed.
Recent research has shown that attackers are increasingly - even predominantly - now using legitimate sites to host their malware, a tactic that makes the malware distribution sites more difficult to shut down.
XSSed's results show that even major security firms are not exempt from the problem, according to XSSed.
In January XSSed found that 60 Web sites that had received a "Hacker Safe" certification from McAfee's ScanAlert service were in fact vulnerable to XSS attacks.
McAfee and other major security firms have downplayed the seriousness of XSS flaws, compared for instance to flaws that allow an attacker direct access to customer data stored on a server.
In recent months the real-world exploitation of XSS flaws has boomed, exploiting major Web sites such as MySpace, Paypal and a major Italian bank.
Last week ScanSafe reported that 68 percent of all malware it blocked in May was found on legitimate sites that had been hacked, more than quadruple the level of a year earlier.
Such flaws can be used to steal user cookies, to steal website login credentials and to exploit users' trust of a site in other ways, and in theory can be shut down quickly once the owner of the site is made aware of the problem.
However, the techniques used by hackers are highly automated, allowing them to "colonize" large numbers of vulnerable sites at once, ScanSafe noted. By contrast, the fixes are not necessarily so easy, researchers have noted.
In a research note in May, F-Secure noted that one legitimate site had been repeatedly hacked and used to spread malicious code, and each time it needed to be contacted to fix the problem.
"The site cannot simply be pulled offline without collateral damage to the legitimate business. So the website's administrator must be contacted to repair the damage," said F-Secure's Sean Rowe in the research note.
References
Latest on Authentication & Access Control
- Apple can't stop ongoing iTunes charge scam
- Swedish prosecutor aims to decide on Assange case on Tuesday
- NBN liked, ISP filter dogs Labor in election wake
- Hackers claim 'jailbreak' victory with PS3 USB key
- Greens drop Net filter in cyber safety policy
- Cloud still too dark for legal information
- Russian charged with selling credit card numbers online
- Facebook bug could give spammers names, photos
- Network admin Terry Childs gets 4-year sentence
- Coalition to dump internet filter
Security Essentials
- Good security in recessionary times
- Security ROI: Fact or Fiction?
- NetWitness releases free version of security software
- Study: critical infrastructure often under cyberattack
- Crooks can make $5M a year shilling fake security software
- Sun exec: IT security should follow business needs
- Clumsy staff more dangerous than hackers: survey
- When the watchdog is the underdog
- Mafiaboy grows up; a hacker seeks redemption
- Ouch! Security pros' worst mistakes
- WebSphere Solution Design (S20) - CBD, contract role3/09/2010
Other
I.T. & T
WebSphere Solution Design (S20) - CBD, contract role - Solution Architect - Web Application Architecture Project!3/09/2010
Other
I.T. & T
Solution Architect to provide strategic and operational consulting for the end-to-end Web Application System project! Experienced with J2EE or .NET?! - Principal Consultant - ITIL2/09/2010
Other
I.T. & T
Excellent opportunity for an experienced ITIL Principal Consultant to join an innovative leading IT Service management consultancy. Attractive packag - Mainframe Developer - COBOL - 12 Month Contract2/09/2010
Other
I.T. & T
Mainframe Developer - COBOL - 12 Month Contract - Business Systems Analyst2/09/2010
Other
I.T. & T
Perm CBD based role for an experienced Business Systems Analyst - Senior SAP Project Manager2/09/2010
Other
I.T. & T
Senior SAP Project Manager - SAP FICO Consultant - 6 week contract - West Sydney2/09/2010
Other
I.T. & T
SAP FICO Consultant - 6 week contract - West Sydney
Whitepapers
TechWorld Blogs
Recent blog posts
- Windows Phone 7: how big can it get?
- NBN gets a turn at political football
- Internet filter gets caught up in politics
- TechWorld Forums goes live
- Selective sourcing the hybrid of cloud services
- Social networks catch more business attention
- RIP Kin
- Telstra’s copper and NBN’s fibre: will the two ends meet?
- RIP Windows 2000, XP lives on
- Does the world need another iPhone? Why not
Recent comments
- java development
12 hours 49 min ago - When mine called they
13 hours 33 min ago - 3D TV cannot fall - no way! Why?
16 hours 46 min ago - Thanks for taking the time to
1 day 5 hours ago - Windows scam
1 day 12 hours ago - My only anti fraud method is
2 days 7 hours ago - Private Cloud Taxonomies
2 days 7 hours ago - ...however...
2 days 16 hours ago - This Guy
2 days 16 hours ago - Glasses Free technology
2 days 17 hours ago - FOSS community
3 days 24 min ago - i have dv6000 with nvidia
3 days 1 hour ago - i have dv6000 and suddenly
3 days 1 hour ago - This is an awesome comment.
3 days 5 hours ago - Real Estate
3 days 7 hours ago - Scam - eventvwr scammers
3 days 12 hours ago - Well I never...
5 days 2 hours ago - Too bad Microsoft was mentioned
5 days 4 hours ago - Phone card is a better option to make calls at a lower rate
5 days 8 hours ago - In other words: "Developers,
5 days 14 hours ago










Comments
Post new comment