Hackers Target Web Services

Posted
By: As more people turn to Web applications for everyday tasks like e-mail, friendship and payments, cyber criminals are following them in search of bank account details and other valuable data, security researchers said.

Users of Yahoo Inc.'s e-mail service, Google Inc.'s Orkut social networking site and eBay Inc.'s PayPal online payment service were among the targets of attacks in recent weeks. All three companies have acknowledged and plugged the security holes.

The attacks come as Microsoft Corp., whose Windows operating system runs about 90 percent of the world's computers, has plugged many of the most easily exploited holes in its e-mail program, browser and other products following dozens of embarrassing breaches over the past several years.

They also come amid the growing popularity of online communities such as MySpace.com and of Web-based calendar, messaging and other services offered by Google, Yahoo and others.

As larger audiences flock to Web sites that run on ever more powerful programming scripts, malware writers are finding them fertile ground.

''People are just now realizing that there are a ton of scripts that are vulnerable to hacking,'' said Eric Sites, vice president of research and development at Sunbelt Software, which sells security products to businesses. ''It's much easier to go after these applications that haven't been as exploited.''

One of the latest discoveries, announced earlier this month by FaceTime Security Labs, is a worm attacking Orkut.

It tricks visitors into clicking a link that promises photos but instead loads a malicious program, which automatically logs and sends to the worm's anonymous creator data such as names and passwords along with Windows files that often store banking details.

''The bad guys are just stepping up a level and becoming a lot more malicious in what they're trying to do,'' said Chris Boyd, a FaceTime security research manager who discovered the worm. ''Sadly, it's quite a brilliant idea, and we'll probably see a lot more of it in the months to come.''

Statistics detailing the rise of Web sites as security targets are hard to come by because companies such as Secunia and Symantec Corp., which track computer attacks, generally don't break them out that way.

But anecdotal evidence isn't hard to find.

In October, MySpace.com, which now has 88 million registered users, was hit by a malicious program that allowed a single user to automatically add millions of others as friends. The attack caused performance problems for MySpace -- and underscored for security researchers the potential risks Web applications and services face.

Security experts say that attackers are having to look for new avenues because users have become better at running security software and applying security updates.

''In some ways, we've forced them to be more clever because we've shut down the old means they had of infecting people,'' said Dave Cole, director of security response at Symantec. ''What we see the attackers doing is trying to slide under the radar by moving into new areas where people's guards may be down.''

Comments

No comments on this item Please log in to comment by clicking here