Report: Attackers Adopt Stealth Tactics

LOS ANGELES — Computer security systems provider Symantec has released its 13th Internet Security Threat Report, which analyzed Internet attacks and vulnerabilities such as malicious code, phishing, spam and other security risks over the past six months.

One of the report's findings is that long-known vulnerabilities still exist, due to mistakes made by webmasters that allow hackers to gain control of their websites — and the computers of unsuspecting visitors to their websites.

Despite decade-old solutions for dealing with some of these problems, the Symantec report revealed that the number of these readily compromised (and readily secured) websites doubled in the latter part of 2007, providing many attractive opportunities for tech-savvy criminal enterprises that do not have to lure surfers into "bad neighborhoods" before launching attacks from legitimate — but poorly coded — websites.

"It overturns the whole notion that if you stay away from gambling and porn sites you are okay," said Kevin Hogan, Symantec director of security operations.

Cross-site scripting, or XSS, is the culprit behind some of these malicious attacks, and works by targeting improperly secured data transfers between web browsers and servers.

For example, XSS vulnerabilities can provide member login information to hackers, complicating paysite owners' efforts to fight password sharing.

XBIZ previously reported on a Flash bug that used XSS and that may be particularly common on adult websites.

The Symantec report attributes attackers' adoption of stealth tactics targeting individual computer users via the Internet to the effectiveness of enterprise networks in fighting "brute force" and other attacks on their systems.

End-users are more easily compromised by malicious activity because of their typically inadequate approach to security — a situation that is compounded by the fact that the site containing the compromised code is unlikely to detect it, guaranteeing further infections.

The Symantec report claims that social-networking sites are a favorite target for attackers, as they present a large audience that is likely to trust the site and reveal confidential or personal information, which could lead to fraud and identity theft.

According to the report, 11,253 specific XSS vulnerabilities were discovered in the final six months of 2007 — up from 6,961 during the first six months of the year — though many other cases have gone unreported.

"There are a lot more websites out there that are prone to this," Hogan said. "It's a much bigger proposition to make a safe website than it is to patch a browser."

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Irish Regulator: EU States to Ramp Up AV Enforcement for Smaller Sites

A representative of Irish media regulator Coimisiún na Meán told legislators that Ireland and other EU states are preparing to expand enforcement of age verification regulations to include smaller adult sites, British newspaper The Times is reporting.

Sansyl Group Acquires Blue Donkey Media

Sansyl Group, parent company of AdultPrime Network, has acquired Blue Donkey Media B.V., owner of Dutch adult site Meiden van Holland, among several other erotic websites and television channels.

Pineapple Support to Hold Mental Health Summit

The annual Pineapple Support Mental Health Summit is taking place Dec. 15-17.

Ofcom Fines AVS Group $1.3 Million for AV Noncompliance

U.K. media regulator Ofcom on Wednesday imposed a penalty of one million pounds, or approximately $1.3 million, on AVS Group Ltd. after an investigation concluded that the company had failed to implement robust age checks on 18 adult websites.

Updated: Aylo to Help Test EU Age Verification App

Pornhub parent company Aylo plans to participate in the European Commission’s pilot program for its “white label” age verification app, a spokesperson for the company has confirmed.

Missouri Lawmaker Attempts to Revive 'Health Warnings' for Adult Sites

A Missouri state representative has introduced a bill that would require adult sites to post notices warning users of alleged physical, mental, and social harms associated with pornography, despite a previous federal court ruling against such requirements.

New Age Verification Service 'BorderAge' Launches

French startup company Needemand has officially launched its subscription-based age verification solution, BorderAge.

Ruling: Italy's 'Porn Tax' Applies to All Content Creators

Italy’s tax revenue agency has ruled that the nation’s 25% “ethical tax” on income generated from adult content applies even to smaller independent online content creators.

Proposed New Hampshire AV Bill Appears to Violate Constitution

A bill in the New Hampshire state legislature, aimed at requiring adult sites to age-verify users in that state, contains a provision that seemingly contradicts the Supremacy Clause in Article VI of the U.S. Constitution.

AEBN Publishes Report on Fetish Trends

AEBN has published a report on fetish categories from its straight and gay theaters.

Show More