The Web sites of three of the security industry's best-known companies include security flaws that could be used to launch scams against customers, according to a new report.
The report, from security watchdog site XSSed, verified 30 cross-site scripting (XSS) vulnerabilities across the sites of McAfee, Symantec and VeriSign. The flaws could be used to launch scams or implant malicious code on the systems of visiting users, according to XSSed.
Recent research has shown that attackers are increasingly - even predominantly - now using legitimate sites to host their malware, a tactic that makes the malware distribution sites more difficult to shut down.
XSSed's results show that even major security firms are not exempt from the problem, according to XSSed.
In January XSSed found that 60 Web sites that had received a "Hacker Safe" certification from McAfee's ScanAlert service were in fact vulnerable to XSS attacks.
McAfee and other major security firms have downplayed the seriousness of XSS flaws, compared for instance to flaws that allow an attacker direct access to customer data stored on a server.
In recent months the real-world exploitation of XSS flaws has boomed, exploiting major Web sites such as MySpace, Paypal and a major Italian bank.
Last week ScanSafe reported that 68 percent of all malware it blocked in May was found on legitimate sites that had been hacked, more than quadruple the level of a year earlier.
Such flaws can be used to steal user cookies, to steal website login credentials and to exploit users' trust of a site in other ways, and in theory can be shut down quickly once the owner of the site is made aware of the problem.
However, the techniques used by hackers are highly automated, allowing them to "colonize" large numbers of vulnerable sites at once, ScanSafe noted. By contrast, the fixes are not necessarily so easy, researchers have noted.
In a research note in May, F-Secure noted that one legitimate site had been repeatedly hacked and used to spread malicious code, and each time it needed to be contacted to fix the problem.
"The site cannot simply be pulled offline without collateral damage to the legitimate business. So the website's administrator must be contacted to repair the damage," said F-Secure's Sean Rowe in the research note.
References
Latest on Authentication & Access Control
- Blind phone hacker gets 11-year sentence
- PCI Security Council seeks industry comments on current standards
- Blogger: Windows 7 UAC feature still vulnerable
- Police say hacker stole phone time from AT&T, others
- International telecom hacker group busted
- T-Mobile data was not taken by hacking, company says
- T-Mobile confirms stolen data is genuine
- Web mail company to pay prize after CEO hacked
- 'Google-like' tool aids network security
- FBI e-mail clobbered after virus
Security Essentials
- Good security in recessionary times
- Security ROI: Fact or Fiction?
- NetWitness releases free version of security software
- Study: critical infrastructure often under cyberattack
- Crooks can make $5M a year shilling fake security software
- Sun exec: IT security should follow business needs
- Clumsy staff more dangerous than hackers: survey
- When the watchdog is the underdog
- Mafiaboy grows up; a hacker seeks redemption
- Ouch! Security pros' worst mistakes
TechWorld Jobs (beta)
Recent Jobs
TechWorld Blogs
-

TalkingTech
The view from the top of IT with TechWorld Editor Rodney Gedda
-

Entrenched
Cooking up better code, IDG's developers reveal some of their secrets
-

Broadband Voice
Darren Pauli digs in from the front line of Australia's broadband battleground
Recent blog posts
- Nokia remains 'open' to Android amid Symbian renaissance
- KDE's Seigo gives sneak peek at version 4.3
- Was the iPhone 3G S worth queuing up for?
- Has Oracle started its mammoth technology consolidation?
- iPhone 3.0: the detail is the process, not the features
- TechWorld.com.au goes mobile
- Should Dell buy Palm? Stranger things have happened
- A big week for Linux: is user friendliness finally in sight?
- Apple, Android rain on Palm's Pre parade
- The clone attack is becoming unstoppable
Recent comments
- PSP Nintendo
13 hours 11 min ago - Interesting report. You were
1 day 9 hours ago - Are you sure it is in Sydney?
1 day 20 hours ago - The mobile market has
2 days 4 hours ago - Great news.
Sms spam should
3 days 1 hour ago - now what am I gonna do with
3 days 4 hours ago - ozlotteries.com not ozlotto.cm
3 days 5 hours ago - OLAT Release
3 days 15 hours ago - and i was sure i would win...
3 days 20 hours ago - Hi SolidRadicle,
I am looking
3 days 20 hours ago - Not if I can help it
3 days 20 hours ago - Ozlotto Tips Scam
4 days 58 min ago - Great post.
It's very
4 days 1 hour ago - Excellent review! I'm glad
5 days 22 hours ago - iTunes Helper
1 week 1 day ago - Update the link to OrangeHRM web site
1 week 2 days ago - Very informative article
1 week 2 days ago - Google Chrome is still being directed to bing instead of google
1 week 2 days ago - regd: Software Magazine
1 week 2 days ago - I seem to have missed a point
1 week 3 days ago










Comments
Post new comment