SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security

Attackers going after end users rather than servers

Attackers going after end users rather than servers

By:  Paul Krill  On: 23 Feb 2010 For: InfoWorld 

The Web traffic study also finds issues with botnets, corporate policies, Adobe Systems Inc.’s Acrobat reader and JavaScript. ZScaler found significant use of Internet Explorer 6, which unlike later versions of Microsoft Corp.’s browser does not maintain malicious URL and phishing block lists. Just what exactly is a darknet?

Rather than targeting Web and e-mail servers, attackers these days are prone to going after enterprises from the inside out, compromising end user systems and then using them to access confidential data, according to a Web traffic analysis report by security-as-a-service provider Zscaler Inc.

Based on a recent study of traffic passing through its global network,  Zscaler's "State of the Web - Q4 2009" report also notes trends including issues with botnets, corporate Internet access policies, and the use of the Internet Explorer 6 browser. Scheduled for release Tuesday, the study analyzes Web traffic volumes covering several thousand Web transactions per second and hundreds of billions of Web transactions.

Zscaler found attackers were prone to embedding JavaScript or malicious iframes to pull content from an attacker's server, whereupon the content is rendered in a user's browser, said Mike Geide, senior security researcher at Zscaler, in an interview on Monday.

"The malicious content will then compromise the end user either through a vulnerable browser or through vulnerable client applications such as Adobe Acrobat Reader," Geide said. Malware then can steal victims' credentials.

"It's recommended that users take extra precaution when doing financial transactions online and if at all possible to utilize Web-based protection," Geide said. He acknowledged Zscaler offered services to remedy the issue but noted the company is not the only vendor to do so.

Zscaler also found significant use of the Internet Explorer 6 browser, even though it has been succeeded by two more secure generations of Microsoft's browser.  Version 6, for instance, does not maintain malicious URL and phishing block lists, the report said.

Botnets present issues, according to Zscaler. "We're seeing a lot of botnets,"  Geide said. Zscaler blocks botnets, which can take over systems, said Geide.  Zscaler also found some users attempting to deploy anonymizers, which hide a client IP address to enable access to undesirable content such as gambling or pornography sites, he said.

Another issue, darknets, involves unallocated IP space and infected hosts on the network. This can lead to disclosures of internal information, said Geide.  Also, attackers have launched phishing attacks from sites such as the recently removed fake social networking site, coolxd.com, according to Zscaler.

In other findings, Zscaler found that content such as JPEG and GIF was more prominent than JavaScript and HTML. "The Web is very media-rich at this point in time," Geide said.

Additionally, ZScaler found that the Firefox browser is slowly gaining wider adoption, although the company needs more time to determine precise browser usage trends. "Internet Explorer is still leaps and bounds ahead of Firefox as far as the enterprise user goes," said Geide. Firefox gained more than 6 percent in market share in December, Zscaler found.  Still, Internet Explorer's share was at about 70 percent by the end of 2009.


Sign up for our Newsletters












Print |  Views: 1823   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




paul krill Paul Krill is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.