The Macrosite for News, Analysis and Opinion about the Future of the Internet
Jonathan Hochman

Nasty Malware Attack Targets Web Developers

Written by Jonathan Hochman
8/19/2009 49 comments
DISCUSS   Digg   Del.icio.us   Reddit   Email This   TWEET THIS

There's a nasty bug going around the Web that targets developers.

When a developer visits an infected site, the page installs a virus on their machine that silently copies the passwords stored in FileZilla, CuteFTP, and possibly other File Transfer Protocol (FTP) client software, and sends them to a central server. The server then runs a bot to access all sites for which credentials have been stolen and installs an iframe injection attack on many pages, further spreading the infection.

Infected sites occasionally break if they use the Web scripting language PHP, but frequently they continue to operate, and thus infect more users with the virus.

When a search engine such as Google detects the infection in a site, they may remove the site from their index, resulting in a financial loss to the site owner. Some browsers may flag the site as infected and show a warning that scares away users.

This attack is interesting because of the way it spreads, and the risk to developers. I would not want to be the freelance Web professional who has to explain to a few dozen clients why their sites all got hacked.

Presumably, this attack vector will eventually be used to install a payload, such as software for sending spam or executing denial-of-service attacks. After all, today's best malware is all about making money.

Big sites have security measures that would probably protect them. But what if a few million small sites are compromised and used to launch a coordinated attack? As we recently saw with Twitter's vulnerability to distributed denial-of-service attacks, there's no such thing as "not my problem" on a shared network like the Internet.

The lessons to be learned here include:

  1. Website owners should provision a unique FTP password for each developer so access rights can be rescinded later without disrupting the system. Hosting providers often issue a master login that provides access to both their hosting control panel (Cpanel or Plesk) and FTP. Typically, users cannot disable or change the password on this account. If the master account gets compromised, you'll need to contact support at the hosting provider, which can be slow. To avoid this risk, don't allow anyone to store the master account password in an FTP program.

  2. Developers should inform owners promptly if a security breach occurs so that the owners can change passwords. If a developer has access to the hosting controls, they should consider changing the passwords immediately, using a secure machine.

  3. Developers must take extra precautions to avoid infection of their machines, including installation of the latest OS, browser, and browser plug=in (e.g., Acrobat) patches. Developers should also use a tool like NoScript, which prohibits unknown scripts from running in a browser, to avoid infection via malicious scripts.

  4. Websites must be checked regularly to reveal any malware infections. Useful tools include Google Webmaster Tools, Unmask Parasites, and the Google Safe Browsing Diagnostic.

Further information about this attack is available in this blog on Unmask Parasites regarding Malicious "Income" IFrames from .CN Domains.

The bug has been wild since April 2009 -- and is still spreading.

— Jonathan Hochman, founder, Hochman Consultants

DISCUSS   Digg   Del.icio.us   Reddit   Email This
Current display:       newest comments first       display in chronological order
Page 1 of 5   Next >
Jason_13
Rank: Cyborg
Wednesday August 26, 2009 10:22:24 PM
no ratings

Ira,

Several products do this, and yes, it should be the standard.  But it is costly.  That's one of the problems we face in the security field.  I know you are well aware.

Limited budgets are the fact of life.  We (security) compete with business groups for money.  When compared to a new project that has the potential to bring an increase in revenue, the security tool fails miserably.

It's only been since the age of regulatory compliance (with financial impact) that we've been able to get an edge in the budget game.

I can only imagine where we would be if the NAC solutions were in place and protecting us on a daily basis... Ah Utopia!

Jonathan Hochman
Thinkernetter
Monday August 24, 2009 10:40:15 PM
no ratings

ISPs could run pen tests on client machines.  They could also scan in and outbound traffic, identify the bots and disconnect them.  The reason they don't do any of that is because it costs an ISP something like $60 per incident in support costs when the consumer starts complaining, "Why did you cut me off?  What did you do to my computer?  I demand that you fix it!"

I'll have to write a column about that soon.  It's perverse incentive: ISPs won't do the right thing because it's against their financial interest, at least until somebody holds them liable for the damages caused by malicious traffic from their networks.

DHCIR
Rank: Cyborg
Monday August 24, 2009 7:13:01 PM
no ratings

Ira,

You are per chance, referring to the Cisco Security Agent I assume. A firm that I worked with used this, albeit an older version 5.0.x(?), which was a tad bit buggy and poorly managed. It liked to whack XP upside the chops with the occasional BSOD. Later versions were more stable. The BIG thing with getting the CSA to work properly was allowing enough experienced, knowledgeable support for it (more pesky 'competence' and 'having enough I.T. budget' shtuff in order to do things right). The company using this flew by the seat of their pants a bit with it = issues, including the new CIO’s laptop Blew Screaming when he was overseas (ah lovely). Later on after we (tech support, Mgmt and end users) complained (more like b1tched readily) enough about it and even UN-installed it a few times; THEN more resources were allotted & issues were ironed out. All in all, 'twas a decent tool when configured & supported "PROPERLY!" Beats the “Hope & Pray for the Best Method” used by all too many computer...f-oh-lks.

Ira Winkler
Thinkernetter
Monday August 24, 2009 6:56:49 PM
no ratings

Thanks for identifying the term I couldnt think of at the time.

Everyone in the technical profession should push for their organizations to implements NAC.  Ironically, the much maligned AOL was a leader in this field, providing malware protection as part of their client software.

Please make sure that your organizations are diligent enough to use this type of protection.  It not only protects the organization, it protects others.

jpmessenger
IQ Crew
Monday August 24, 2009 6:31:53 PM
no ratings

NAC is a concept/technology that has been around for a while, but is still not gaining enough momentum in corporate America. I've actually been a bit surprised that I rarely hear a member of executive management mention it...it's been a buzz word lately, and I know how non-techie people love acronyms. ;-)

Ira Winkler
Thinkernetter
Monday August 24, 2009 4:20:57 PM
no ratings

What is kind of bizarre (surreal that it is not in use) about your comments is that I remember talking to a large university right after Slammer came out.  That was in 2003 or so.

The university implemented a Cisco end point security agent that worked by verifying a system had all patches and anti-malware updates applied, before the system was allowed on the network.  The technology has been readily available for about 5 years, and it is bizarre to me that it is not more in use.

Mike Acker
Rank: Cyborg
Monday August 24, 2009 2:03:07 PM
no ratings

JP : = "Is this yet another issue we want the government stepping in on?"

most certainly not, at least not in my view. government will make a horrible mess if they try to legislate a solution; at most all I would be interested in is in changing the policy on product liability.  all this would tend to do would be to motivate the industry to pay attention to security

security should be built-in on every computer sold. customers have a right to expect that.

it would undoubtably be usefull to discuss what those expectations ought to be

first and foremost customer computer should not be updated with un-authorized programs -- even if the customer is tricked with a phish -- the security software should discover the phish does not have the necessary credentials -- and refuse to install.

in addition, web pages or other executable documents which the customer might process should not be conducting data-mining or other spying, snooping for account numbers, passwords, or other data.

it should be noted that this wish list is just BASIC security: protecting the operating environment from tampering and protecting one application from another.  just the basics.

DHCIR
Rank: Cyborg
Monday August 24, 2009 12:17:37 PM
no ratings

IRA,

Couldn't agree more! Internet Community insanity CAN be good for business (for me anyway in some regards). The Internet is really a COMMUNITY. Is it not?

Q: OK...what community DOES not have crime? What person (realistic person anyway), in a community expects to do nothing, NOT be educated about the dangers of the "bad" parts of the community to know when & where to walk during the day/nighttime etc., and expect to have nothing happen to them! 

A: Insane/unrealistic people! Like the ex-nun I know, who lived down in a "bad" area of the city, but she went jogging in the early am anyway, like EVERYONE told her not to! YEP, she was mugged & assaulted! (True story too!). 

The Internet is a dangerous place ppl, inform & protect yourself or stay away!

Can hardware/software be made better? Of course. Will threats STOP? NEVER! Can the PEOPLE who run the hardware/software do it better? Ha ha ha ha.....ahhhh.....maybe????  I vote for DO DILIGENCE (as mirrored by society).

jpmessenger
IQ Crew
Monday August 24, 2009 11:48:55 AM
no ratings

You're right, Mike. The bigger problem is WHO determines what is realistic and what is practical?

The government steps in on a lot of issue regarding the safety and welfare of consumers and the public in general. The FDA requires warnings on medications and foods. Remember the "shown to cause cancer in laboratory test animals" that used to be on everything with sacharine as an ingredient?

Is this yet another issue we want the government stepping in on? Do we want completely non-technical people who will get all of their policy influence from large technology conglomerates?

To some extent, a little bit or regulation and ownership/acceptance of liability might be comforting, but I have doubts that the government would mandate anything correctly. And, if they do, what price will the consumer pay?

Mike Acker
Rank: Cyborg
Monday August 24, 2009 11:01:37 AM
no ratings

Jason: ="Whose responsibility is it to make sure the end-user is informed?"

excellent post and I think we need to examine

  • what is realistic?
  • what is practicle?

It is not realistic to expect the average customer to effect an A/V defense; the A/V defense must be included in his purchase.

now, from a practicle standpoint how do we get it to happen?  if we can't embarrass vendors into providing an effective a/v defense then we will have to petition government to make it mandatory.

it's looking more and more like it will need to be product liability legislation

Page 1 of 5   Next >
The ThinkerNet does not reflect the views of TechWeb. The ThinkerNet is an informal means of communication to members and visitors of the Internet Evolution site. Individual authors are chosen by Internet Evolution to blog. Neither Internet Evolution nor TechWeb assume responsibility for comments, claims, or opinions made by authors and ThinkerNet bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose.
previous posts from Jonathan Hochman
Jonathan Hochman
Unless you live under a rock, you've no doubt seen those "Google Cash business opportunity” ads from entities like Google Money Tree and Google Treasure Chest. They seem to be everywhere. UPDATED 8/24 6:05 PM
Jonathan Hochman
Websites offer two vectors for spreading email spam: email addresses and insecure forms. Bad guys and their botnets crawl the Web, looking for both. With email addresses they build lists. With forms they hijack servers to send spam.
Jonathan Hochman
Web marketers must constantly manage a long list of domain names, Web servers, ad campaigns, social media profiles, and assorted Web 2.0 services. Facilitating access to these digital assets enables frequent monitoring, better optimization, and improved security.
5
of
IETV: the thinkerNet on film
5
of
2pm EDT
Thu
Sep 30th
an IBM information resource
sponsored content
big blue blog
an IBM information resource
sponsored content
Getting to Work on Smart Work: How IT Is Transforming the Implementation of the 'Internet of Things'
Organizations in all industry sectors are becoming more instrumented, interconnected, and intelligent -- and that's changing the way they approach virtually every facet of their operations. It's up to IT to help organizations adopt a "Three I's" approach that leverages the emerging Internet of Things and enables them to work smarter.

READ THIS eBOOK
your weekly update of news, analysis, and
opinion from Internet Evolution - FREE!

REGISTER HERE
Wanted! Site Moderators
Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

Please email: moderators@internetevolution.com
Internet Evolution – not for thickies
Second Shooter
Your Privacy vs. Google

8|11|10   |   2:10   |   2 comments


Google's problems in Korea and the leaked internal document on exploiting private data show that, if we want to avoid active regulation, we need more explicit disclosure of what companies do and don’t do with what they collect.
Bram Cohen
P2P: Not Always Evil

8|3|10   |   2:12   |   4 comments


Peer-to-peerrrr technology isn’t just for pirates… It’s for the enterprise, too!
Wisdom of the Big Chair
Internet Explorer Rebounds

7|9|10   |   2:31   |   9 comments


After years (no, centuries!) of complacency, competition has forced Microsoft to focus on beefing up its browser.
Reiter's Block
Chrome’s 'Accessibility' Extensions

7|7|10   |   1:51   |   4 comments


Google has created a new category of extensions: accessibility. It's designed to make it easier for people with disabilities to use a browser. But even people without disabilities might find some extensions useful.
what.the.ferraro
Need Google Support? Too Bad!

3|19|10   |   2:52   |   19 comments


Google's far too important to provide any useful support for its lowly users.
Jim Morris
IPV6… Attention!

3|16|10   |   1:27   |   3 comments


The advent of IPv6 will usher in a new era of Internet-enabled warfare.
Reiter's Block
Desktops Will Be 'Irrelevant'? Baloney!

3|11|10   |   3:12   |   4 comments


A top Google executive says desktop computers will be irrelevant in three years. Alan Reiter suspects it won't be desktops that will be irrelevant (snicker).
Reiter's Block
If a Google Phone Arrives, Does It Even Matter?

12|17|09   |   02:41   |   14 comments


Techies are going crazy over the possibility that Google might design and sell its own Android phone. Some writers say it's a very big deal. Reiter questions whether it will happen and, if it does, whether it even matters.
John Soat
E-Discovery Limits Are Set. Maybe

11|30|09   |   3:04   |   4 comments


E-discovery is the requirement to make available all digital information related to, and in conjunction with, a legal proceeding. An appeals court ruled recently to limit the scope of e-discovery searches, which gives corporate counsel and IT executives a bit more power over the e-discovery process.
Second Shooter
Crocheted Windows or Smart Applications?

11|27|09   |   2:17   |   No comments


Google Chrome isn't pretty like other OS GUIs, but it's the first OS ever designed from the Internet inward to the desktop instead of the other way around. Crochet a nice border for a Chrome OS window if you like, as long as you realize the world of the cloud will change our conception of desktop computing forever.
Wisdom of the Big Chair
More Texting, Less Bandwidth

9|2|10   |   1:56   |   No comments


Nielsen’s recent numbers on the increasing use of texting bode well for enterprise networks. Shunning the phone in favor of text messaging could mean reducing bandwidth.
Reiter's Block
RIM Caving on Security

9|2|10   |   2:31   |   2 comments


RIM is giving in to demands by India to snoop on encrypted BlackBerry data. It's time to develop cheap or free encryption software for BlackBerrys and other cellular phones.
Second Shooter
Taking Copyright Protection Too Far

9|1|10   |   2:08   |   No comments


Two studios have filed suit against an ad broker for placing ads to help monetize P2P sites suspected of copyright infringement. That's taking a dangerous step toward what might be a worthy goal.
Singer at C-Level
Video in the Cloud

9|1|10   |   2:16   |   2 comments


Software giants are looking for cloud solutions to support our insatiable appetite for video. There will be blood. Yum.
Mary E. Shacklett
Wish List for Mobile Devices, Part 1

Part 1 of 2   |  
See complete series
8|31|10   |   1:41   |   2 comments


By 2014, mobile devices will overtake laptops as the appliance of choice for consumers. But device makers still have some wishes to fulfill, including mobile app simplification and the ability to better perform word processing/spreadsheet functions.
Second Shooter
Google Shifts From Free Content

8|31|10   |   2:14   |   6 comments


Google's foray into pay-for-view movies may be an indicator that the days of free ad-sponsored content are numbered, or at least that ad sponsorship won't fund nearly enough content.
Sweeney Blog
A Sharp Website

8|30|10   |   2:27   |   6 comments


Pencil sharpening gets the digital and artisanal touch, just in time for test-takers everywhere.
Mary E. Shacklett
Online Education Gets a Boost

8|30|10   |   2:02   |   8 comments


Online education, improving to better replicate the interactions that occur between teachers and students face-to-face, grew in double digits during the recession. Still, there’s more work to be done.
Reiter's Block
Educating Bill Gates About Education

8|27|10   |   2:34   |   8 comments


Bill Gates says where you study is becoming much less important, and the best college lectures will soon be found online. Reiter disagrees.
Second Shooter
Gmail & VoIP: Death to PSTN?

8|27|10   |   2:09   |   18 comments


Google's decision to link VoIP calling of PSTN numbers with Gmail, and to let Google Voice "call" Gmail VoIP clients, will devalue the PSTN and force telcos to fund unprofitable services or create their own VoIP transitions.

Enabling People and Organizations to Harness the Transformative Power of Technology