IT Management Begins With Security
SecurityProNews > News > Security News > Exploit Prevention Labs Releases August Exploit Survey Results
Search:
[ news_security_news ]

Exploit Prevention Labs Releases August Exploit Survey Results



SecurityProNews
Staff Writer
2006-09-12

SecurityProNews: News RSS Feed Security News RSS Feed


Findings of the August 2006 Exploit Prevalence survey as reported by Exploit Prevention Labs were announced today.

The company has added "orphaned lure sites" to the survey this month. These are described as "trusted web sites that have been hacked and which contain IFRAME links that call out to exploit servers that are dead or dormant". The company elaborates:
An IFRAME is a common HTML tag, and is the primary mechanism used by cyber criminals to infect web site visitors with exploits via drive-by downloads. When a user with an unpatched system hits the site, the IFRAME command causes the user's browser to silently connect to another server, often an exploit server, that then attempts to force-download exploit code onto the user's computer.

"Although these sites are not actively serving exploits right now, we keep a close eye on them because cyber criminals frequently reactivate their exploit servers at a later date," said Roger Thompson, CTO of Exploit Prevention Labs and the survey's primary author. "The orphaned lures are also interesting because the site owners remain oblivious to the fact that they've been hacked and that they most like remain vulnerable to further hacks by the exploit distributors."
The top five most-reported exploits in August according to the survey are as follows:

1. WebAttacker

2. Iframers launcher script

3. WMF (CVE-2005-2124) with known payload

4. Orphaned Lures

5. CreateTextRange (CVE-2006-1359)


For more details about the individual exploits and more on the survey in general, check out the company's press release.

Add to Del.icio.us | Digg | Yahoo! My Web | Furl

Get all the updates in RSS:



About the Author:
SecurityProNews is a daily online and email publication focusing on internet security issues.

More news_security_news Articles

SecurityProNews: News RSS Feed Security News RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds