Report: Attackers Adopt Stealth Tactics

LOS ANGELES — Computer security systems provider Symantec has released its 13th Internet Security Threat Report, which analyzed Internet attacks and vulnerabilities such as malicious code, phishing, spam and other security risks over the past six months.

One of the report's findings is that long-known vulnerabilities still exist, due to mistakes made by webmasters that allow hackers to gain control of their websites — and the computers of unsuspecting visitors to their websites.

Despite decade-old solutions for dealing with some of these problems, the Symantec report revealed that the number of these readily compromised (and readily secured) websites doubled in the latter part of 2007, providing many attractive opportunities for tech-savvy criminal enterprises that do not have to lure surfers into "bad neighborhoods" before launching attacks from legitimate — but poorly coded — websites.

"It overturns the whole notion that if you stay away from gambling and porn sites you are okay," said Kevin Hogan, Symantec director of security operations.

Cross-site scripting, or XSS, is the culprit behind some of these malicious attacks, and works by targeting improperly secured data transfers between web browsers and servers.

For example, XSS vulnerabilities can provide member login information to hackers, complicating paysite owners' efforts to fight password sharing.

XBIZ previously reported on a Flash bug that used XSS and that may be particularly common on adult websites.

The Symantec report attributes attackers' adoption of stealth tactics targeting individual computer users via the Internet to the effectiveness of enterprise networks in fighting "brute force" and other attacks on their systems.

End-users are more easily compromised by malicious activity because of their typically inadequate approach to security — a situation that is compounded by the fact that the site containing the compromised code is unlikely to detect it, guaranteeing further infections.

The Symantec report claims that social-networking sites are a favorite target for attackers, as they present a large audience that is likely to trust the site and reveal confidential or personal information, which could lead to fraud and identity theft.

According to the report, 11,253 specific XSS vulnerabilities were discovered in the final six months of 2007 — up from 6,961 during the first six months of the year — though many other cases have gone unreported.

"There are a lot more websites out there that are prone to this," Hogan said. "It's a much bigger proposition to make a safe website than it is to patch a browser."

Related:  

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

XBIZ LA Conference Website Goes Live, Registration Now Open

The event website for the XBIZ LA conference is now live, offering comprehensive information about the upcoming event, taking place Jan. 7-10 at the JW Marriott L.A. LIVE.

CrakRevenue Rolls Out 'Aff Companion' Real-Time Mobile Notification App

CrakRevenue has launched Aff Companion, a mobile app that sends affiliates real-time notifications about clicks, conversions, and revenue.

Goddess Lilith Launches New Official Website Through PAYSITE

Goddess Lilith has rolled out her new official site, QueenGoddessLilith, through PAYSITE.

Pineapple Support to Host 'Reclaiming Intimacy' Support Group

Pineapple Support is hosting a free online support group for performers with trauma-impacted intimacy issues.

Ofcom Cites Web Prime, Porntrex for Alleged AV Violations

U.K. media regulator Ofcom on Tuesday notified two operators of adult websites of the agency’s provisional determination that the companies have failed to comply with provisions of the Online Safety Act.

FSC: Utah Excise Tax on Adult Content Goes Into Effect October 1

The Free Speech Coalition (FSC) has issued an advisory that the Utah Excise Tax goes into effect tomorrow.

Segpay Parent Company Names David Press to Board

Segpay parent company Toccata Inc. has named payment industry veteran David Press to its board of directors.

Platform Pulse: Inside the Technology and Trends Powering the Direct-to-Fan Economy

For a brief, glittering moment, the fan-platform boom felt like a modern-day gold rush. The premise seemed simple: Open an account, post some tantalizing content and watch the subscriptions roll in. OnlyFans became a household name, "selling feet pics" became a cultural punchline and creators poured into the market hoping to claim their share of the action.

FSC Sets Dates, Qualifiers for December Board of Directors Election

The Free Speech Coalition (FSC) has published dates and qualifiers for its upcoming board of directors election.

Aylo Wins Preliminary Injunction Against Utah AV Law's VPN Rule

A federal court on Thursday issued a preliminary injunction preventing the state of Utah from enforcing a legal provision that would make adult websites liable if minors in the state circumvent geolocation efforts in order to bypass age verification.

Show More