In a sense, this crimeware as a service (CAAS) was inevitable. According to an earlier report from Finjan, more than 51 percent of websites that pushed malicious content in the second half of 2007 were legitimate destinations that had been commandeered by bad guys. The service is evidence that there's money to be made in automating that process - and one more sign that cyber-crime has grown into a full-fledged business where no opportunity to turn a profit is passed up.
"You can imagine the magnitude of this marketplace now," he said in an interview. "They really commercialize everything in this eco-system."It's not the number of the compromised websites that is a worry, but their prominence. The information was likely gleaned by keyloggers intercepting File Transfer Protocol information being sent from infected computers to webhosting servers. Once you have that, you can change anything you like on even the most securely encrypted page because you have access to the source code at the publishing level. It's a wake-up call for webmasters to use only secure FTP to update servers.
|Intel Core i7-3970X Sandy Bridge-E CPU...||7|
|Nintendo Demanding Copyright Royalties...||6|
|Bill Gates Once Again World's Wealthiest...||6|
|Archos Hits The $200 Spot With 8-Inch 80...||5|
|Angry iPhone 4 Owners Sue Apple Claiming...||5|
|Google Fiber Slow March East Continues:...||5|
|Antsy Pants NVIDIA Starts Accepting...||4|