Protecting your ID

You are here: silicon.com > Research > Special Reports > Protecting your ID

Protecting your ID

Bloggers become spyware spreaders

Unwitting accomplices...

By Stefanie Olsen

Published: 24 February 2005 09:05 GMT

Hackers are using blogs to infect computers with spyware, exposing serious security flaws in self-publishing tools used by millions of people on the web.

The problem involves the use of JavaScript and ActiveX, two common methods used to launch programs on a web page. Security experts said malicious programmers can use JavaScript and ActiveX to automatically deliver spyware from a blog to people who visit the site with a vulnerable web browser.

Spyware tools also have been hidden inside JavaScript programs that are offered freely on the web for bloggers to enhance their sites with features such as music. As a result, bloggers who use infected tools could unwittingly turn their sites into a delivery platform for spyware.

Richard Stiennon, chief of technology at Webroot Software, a maker of anti-spyware technology, said: "It is one more link in the commerce chain of illicit adware."

"If auto-generated websites such as blog sites allow the inclusion of ActiveX and JavaScript, they are a great place for spyware writers to try to induce the blogger or web page owner into including some active code," he said.

Spyware has plagued web surfers and companies in recent years. Creators of malicious code take advantage of security vulnerabilities in email software, web browsers and desktop applications to spread code used to siphon personal information or litter a PC with advertisements. Now such rogue outfits are using blogs as a tool to increase their number of installations.

The problem only affects web surfers using Microsoft's Internet Explorer who fail to choose the highest IE browser security settings, security experts said.

The blog vulnerability has cropped up most visibly in Google's Blogger, the most widely used blog-publishing tool. But it could affect other services as well.

Visitors to Blogger's Blogspot.com network have complained that they were exposed to infected sites when they used the "Next Blog" link. The feature was designed to help people discover new journals and takes web surfers to a random Blogspot site.

Ben Edelman, a Harvard University researcher who has documented the vulnerability on his site, referring to Blogger, said: "They left the back door wide open."

A Google representative responded by saying the company is "aware of this issue and we are looking into it".

Visitors to Blogger sites at Blogspot.com say they have been targeted with pop-up ads seeking to deliver malicious code to their computers. One ad erroneously warns people that their computers are vulnerable to spyware and prompts them to click the ad to protect themselves. Clicking the ad launches a download that infects a machine with spyware.

Edelman said that one major culprit of malicious code was a service called iWebtunes.com, which lets people add music to the web sites in the form of a couple lines of JavaScript code. Bloggers using Blogspot might embed the iWebtunes code into their template and then pass on the spyware unwittingly to visitors to their site.

iWebtunes will likely get a fee each time it spreads the spyware or it might benefit from the sale of advertising. The bloggers, on the other hand, will get nothing.

Attempts to contact iWebtunes were unsuccessful. The company does not publish contact information on its website and uses a third party to protect its identity in the Whois database, the public registry of website owners. The company provided a phone number in its Whois registration, but the number was busy for several hours on Wednesday morning.

Google is hardly the only one to blame in this scenario. Microsoft has long been criticised for security weaknesses that let code writers take advantage of its Internet Explorer, the most widely used web browser.

"You could blame users for clicking on the pop-up, blame Microsoft for designing the insecure software installation system, blame iWebtunes for delivering the pop-ups, or you could blame the blog's author for embedding iWebtunes," Edelman said.

Webroot's Stiennon advises people to switch to the Mozilla Foundation's Firefox web browser for reading blogs. Either do that, or change IE security settings to deactivate ActiveX or JavaScript in the web browser, he said.

Stefanie Olsen writes for CNET News.com.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure
Protecting your ID News

BT plans passport checks to slash ID fraud
But you'll still need to keep an eye on your bin...

'Witness intimidation' hampering fraud convictions
Courts and legal system are ill-prepared for hearing technical cases...

Zombies are after your ID
Bot nets are increasingly looking to steal valuable personal information...

SurfControl rides the spyware wave
But warns time is running out for anybody favouring "buy" rather than "build" as an entry strategy...

Bloggers become spyware spreaders
Unwitting accomplices...

RELATED RESEARCH

Make your voice heard

silicon.com and the Bathwick Group have created an opportunity for business and IT executives to share their experience with each other and thus enhance their knowledge of the IT marketplace.

Join our research panel, and you'll be asked to participate in short surveys - and then will be privy to the answers of all your colleagues, as we send you tailored versions of the results.

Extras include complementary passes to silicon.com events and survey prizes such as iPods. Plus, there are the obvious networking opportunities with your fellow panellists.

For more about the Research Panel and how to join, click here



Quick Sitemap Links: