Public sector IT & e-Government news, job vacancies, public sector tenders from PublicTechnology.net
Advertise on our sites  |  About us  |  Contact us RSS news feeds
Free news email alerts from Publictechnology.net: Sign up here
Feb 09, 2010 - 11:13 AM
Join & login to submit articles
Want to join?  or  Login
eGov Strategy
Over 10,000 trusted websites infected by new Trojan toolkit


 Tag:  eGov Strategy    Print article: Printer friendly page    Email article: Send this story to a friend       This was published: 15 Jan 2008 - 06:30 am   

In its just-released Malicious Page of the Month report, Finjan explores the “random js toolkit,” the latest example in the trend among cybercriminals to undermine ‘trusted’ web sites.

Farnborough, United Kingdom, 14th January, 2008 – Finjan Inc., a leader in secure web gateway products, today announced that its Malicious Code Research Center (MCRC) has identified yet another significant new web attack -- the latest in a genre of crimeware that threatens to turn highly trusted web sites into insidious traps for unwary visitors. More than 10,000 websites in the US were infected in December by this latest malware. The attack, which Finjan has designated “random js toolkit,” is an extremely elusive crimeware Trojan that infects an end user’s machine and sends data from the machine via the Internet to the Trojan's “master”, a cybercriminal. Data stolen by the Trojan can include documents, passwords, surfing habitats, or any other sensitive information of interest to the criminal.

The random js toolkit was detected using Finjan’s patented real-time code inspection technology while diagnosing users’ web traffic during December 2007. The attack is described in detail in Finjan’s latest “Malicious Page of the Month” report released today. The report explores the new attack vector in depth, providing an illustration of the attack in action, as captured “in the wild”; an analysis of the effectiveness of its evasive techniques; examples of high-ranked and trusted domains that were compromised by this attack technique; and an analysis of a successful exploitation. To download the report, visit http://www.finjan.com/Content.aspx?id=1367

The random js toolkit is a JavaScript code that is created dynamically and changes every time it is being accessed. As a result, it is almost impossible to be detected by traditional signature-based anti-malware products. Explained Finjan CTO Yuval Ben-Itzhak, “Signaturing a dynamic script is not effective. Signaturing the exploiting code itself is also not effective, since these exploits are changing continually to stay ahead of current zero-day threats and available patches. Keeping an up-to-date list of ‘highly-trusted-doubtful’ domains serves only as a limited defense against this attack vector.”

“What’s needed to counter this exploit is dynamic code inspection technology that can detect and block an attack in real time,” Ben-Itzhak said. “This technology doesn’t depend on the origin URL, signature or the site’s reputation, but inspects the Web content in real-time, as served. It analyzes the code’s intentions before enabling it be executed on the end-user browser.”

Over 30,000 new infected web pages are being created every day
Ben-Itzhak noted that the random js toolkit is an example of the recent trend among cybercriminals to undermine ‘trusted’ web sites. “In mid-year 2007, studies showed there were nearly 30,000 new infected web pages being created every day. About 80 percent of those pages hosting malicious software or containing drive-by downloads with damaging content were located on hacked legitimate sites. Today the situation is much worse.”

The random js attack is performed by dynamic embedding of scripts into a webpage. It provides a random filename that can only be accessed once. This dynamic embedding is done in such a selective manner that when a user has received a page with the embedded malicious script once, it will not be referenced again on further requests. This method prevents detection of the malware in later forensic analyses.

Finjan’s research into the random js toolkit found that around 10,000 legitimate domains served the malicious code in December. Among the infected web sites, Finjan identified highly trusted domains. Finjan alerted administrators of both sites, and the malicious code was subsequently removed from the sites and is no longer active.

About MCRC
Malicious Code Research Center (MCRC) is the leading research department at Finjan, dedicated to the research and detection of security vulnerabilities in Internet applications, as well as other popular programs. MCRC’s goal is to stay steps ahead of hackers attempting to exploit open platforms and technologies to develop malicious code such as Spyware, Trojans, Phishing attacks, worms and viruses. MCRC shares its research efforts with many of the world’s leading software vendors to help patch their security holes. MCRC is a driving force behind the development of next generation security technologies used in Finjan’s proactive web security solutions. For more information, visit our MCRC subsite.




e-Government National Awards winners to be announced 22nd January 2008
Winners from among the 81 finalists (detailed at this link) in this year's e-Government National Awards 2007 will be announced at a Ministerial level black tie dinner at the Dorchester Hotel in London on 22nd January 2008. 11 Awards categories will recognise this year's "best of the best" strategies, achievements, teams and individuals in UK public sector web, ICT & e-Government services. The judging panel was headed by Government Chief Information Officer John Suffolk (based at Cabinet Office).

Platinum sponsor is KPMG.
Also sponsors are O2, the Planning Portal and Atos Origin
.

The Awards are supported by the Government Chief Information Officer (Cabinet Office), the Office of Government Commerce, the Society of Information Technology Management (Socitm), and SOLACE (Society of Local Authority Chief Executives and Senior Managers).


Posted by: Neil 



Other latest articles on the subject of eGov Strategy

· Minister for creative industries to step down   (4 Feb 2010 )
· Analyst View: Government shared services perspectives   (2 Feb 2010 )
· Public sector open source body needed   (29 Jan 2010 )
· Suffolk believes OEP target realistic, without off-shoring jobs   (27 Jan 2010 )
· US turns to Cloud Computing ahead of 2010 census   (25 Jan 2010 )
· Suffolk challenges Socitm’s G-Cloud "misgivings"   (22 Jan 2010 )
· 'Father of the web' launches government data site   (21 Jan 2010 )
· Public service technology innovators praised at the e-Government National Awards   (21 Jan 2010 )
· The e-Government National Awards 2009: Summary of winners and highly commended   (21 Jan 2010 )
· UK fourth in UN e-government development report   (20 Jan 2010 )

>>>More articles on eGov Strategy>>>

L A T E S T   J O B S

My TechTenders.net Account:

My Website login
My Subscription login
Subscribe to TechTenders.net


My PublicTechnology.net contributer Account:

PublicTechnology.net Account
PublicTechnology Emails
About:

About us
Contact us
Terms & conditions of use
Privacy policy
RSS feeds: Publictechnology

Copyright:

Copyright Public Technology Ltd 2003-2009. Crown copyright material used under click use licence C02W0007583. Parliamentary material used under click use licence P2005000039, & reproduced with the permission of the Controller of HMSO on behalf of Parliament. EU tender information published under license from the European Commission.

This web site automatically and continually monitors, collects and publishes latest breakings news from a large number of sources. Copyright of content / material may belong to the original source.
Advertise to our audiences:

Advertising options
Directory listings
Advertise Jobs
Advertise Tenders
Promote Events
Sponsor the Awards
Publish press releases
Promote products or services
The Public Technology
digital information network:


Public Technology is the UK's foremost news & information provider for the public sector & its suppliers.

It comprises:
Techtenders.net
PublicTechnology.net
Jobs.PublicTechnology.net
Public Technology email alerts
PublicPolitics.net
PublicPages.net
WhitehallPages.net
EducationPages.net
EUmonitor.net
PublicTenders.net
NHStenders.net
e-Government National Awards