All Your iFRAMEs Point to Us
With the rate of web-page infections getting as high as 1 in every 4.5 seconds*, “drive by downloads” are clearly one of the most immediate threat to everybody using the WWW.
So what can we do about it?
Well, for starters: there are many tools (http://www.siteadvisor.com/, http://www.mywot.com/) available that warn users about the threat level of websites by using different methods (what are they?).
While some (http://code.google.com/apis/safebrowsing/) even help web-application developers to secure their web-sites from being used as launch pads to trigger attacks.
And, sometimes it is just better to be safe than sorry. (http://www.willamette.edu/wits/spyware/)
Find out how you can get involved in efforts (http://www.stopbadware.org/home/action) against “drive by downloads”.
While we discuss the next paper:- “All your iFrames point to us”, lets take this opportunity to look at how “drive by downloads“ work, starting from their construction, distribution and finally their relationships with weakest link in security - the user.
*http://www.sophos.com/sophos/docs/eng/marketing_material/sophos-security-threat-report-jan-2009-na.pdf