SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Hacking and Viruses

Why ‘transitive trust’ makes Web 2.0 dangerous

Why ‘transitive trust’ makes Web 2.0 dangerous

By:   On: 06 Dec 2007 For: Network World Canada Creator

The Beijing Olympics and more Mac attacks are also on the radar as Websense releases its Top 10 list of threats for next year. Also: a major hacker bust

Burgeoning Web 2.0 platforms will figure significantly in the IT threat landscape in the coming year, say researchers for security vendor Websense.

The company anticipates hackers will use profile information and the demographics of specific social networking sites to better target their attacks. And the proliferation of social networking applications, widgets and mash-ups increases the likelihood of “weak link” attacks on vulnerable sites and content.

Those are two of the trends the company outlined in its Top 10 list of security threats for 2008.

Attackers are relying on “transitive trust,” says Stephan Chenette, manager of the San Diego, Calif., vendor’s security lab. Ads, mash-ups and widgets that are appearing on trusted sites are hosted in another location. “That site isn’t responsible” for the code, which could draw the user to a malicious site.

“A lot more spam messages are claiming to be from Facebook and other social networking sites,” Chenette says. Because people are used to receiving Facebook messages and clicking on requests, they’re more likely to respond.

“It’s that moment of trust when they see it and click.”

The renaissance of the Apple brand, thanks in large part to phenomenal iPhone sales, means users who were once protected by hackers’ lack of interest in the platform because of its small footprint in the consumer market will see more attacks targeting Macs.

“Both Mac and Linux users in the past assumed security,” says Chenette. “With the increased usage of Macs, there will be more Mac attacks.” And while any smart phone is vulnerable, the iPhone will be particularly targeted because of its popularity.

Malicious sites are also using browser and operating system detection to target attacks to specific platforms, he said.

And the company anticipates large-scale denial of service attacks, fraud and phishing associated with the summer Olympics in Beijing. Event-based attacks are common, Chenette says. The Web site for the NFL football Miami Dolphins franchise was hacked and mined with exploit code last January in the weeks leading up to the NFL championship game, which was hosted in Miami.

“The event occurred just before the Super Bowl, when the hackers knew there would be a lot of traffic,” he says.

Also, China ranks with Russia and Brazil at the top of the list of sources of malware, phishing attacks and other exploits. Chenette predicts an associated spam run or hack of the site.


Sign up for our Newsletters












Print |  Views: 1379   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




dwebb

Related Content

U.S. took China's place for most malware in 2008
U.S. took China's place for most malware in 2008Whether knowingly or not, American computers are making a 'disturbingly large' contribution to the distribution of viruses and span, says Sophos
Companies to spend billions on social networking: IDC
Companies to spend billions on social networking: IDCA study released this week found the market for corporate social networking nearly tripled last year, as companies try to foster communication among employees, customers and partners. Find out what IT managers should keep in mind if they’re thinking of rolling this out
China worries hackers will strike during Beijing Olympics
China worries hackers will strike during Beijing OlympicsHistorically, hackers see the Olympics as a challenge, says a government report. The Chinese government has created a special response team in Beijing to monitor systems for signs of attacks and then respond if one is detected.
Honey I shrunk the threats!
 by joaquim p. menezes - it’s called “honeyjax” and no, it isn’t another donut brand. it’

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.