Skip to main content

LizaMoon attack infects millions of websites


NEW YORK (CNNMoney) -- Have you heard the scary news about 'LizaMoon,' a malicious code attack that has already infected more than a million websites?
Don't panic. This particular bit of hacker mischief is setting off alarms among online security watchdogs for its speed and scope, but built-in software safeguards mean few actual users will end up suffering.

The exploit drew headlines because it's affecting a surprisingly large number of websites -- nearly 4 million so far -- and because some of those sites feed into Apple's iTunes platform. Websense, the security software vendor that first broke the news about LizaMoon in its blog, played up the iTunes connection in its first warning about the attack.
But Apple (AAPL, Fortune 500) has iTunes designed to automatically neutralize this kind of threat. That means there's zero risk of an iTunes user's computer actually getting infected by this bit of malware. Websense acknowledged that in its latest LizaMoon update.
"Every time there's a mass-injection like this, and there really hasn't been anything this big before, we try to identify larger systems and sites that have been affected," the company wrote in its blog. "There are few systems out there bigger than iTunes, so when we saw that content on itunes.apple.com contained the injected link we wanted to make people aware of that, even if the script didn't work."
LizaMoon is what's called a SQL code injection attack, where a Web application vulnerability is exploited to inject malicious code into affected websites. If a Web surfer visits an affected site, they'll be redirected to a rogue website that tries to install a "scareware" file. The file generates messages warning the user that their computer is infected with viruses, and offers to sell them antivirus software in defense. Most actual, legitimate antivirus programs will detect and eliminate the malicious file.
And most websites have protections in place to prevent them from getting infected in the first place. While LizaMoon has infested million of websites, security experts say it's a run-of-the-mill threat that is mostly hitting obscure, low-traffic sites.
"Defense against your sites getting infected is the standard things we ought to be doing anyway," the SANS Internet Storm Center, a security monitoring site, wrote in its LizaMoon analysisTo top of page

Comments

Popular posts from this blog

Evolution Of Computer Virus [infographic]

4 Free Apps For Discovering Great Content On the Go

1. StumbleUpon The granddaddy of discovering random cool stuff online, StumbleUpon will celebrate its 10th anniversary later this year — but its mobile app is less than a year old. On the web, its eight million users have spent the last decade recommending (or disliking) millions of webpages with a thumbs up / thumbs down system on a specially installed browser bar. The StumbleUpon engine then passes on recommendations from users whose interests seem similar to yours. Hit the Stumble button and you’ll get a random page that the engine thinks you’ll like. The more you like or dislike its recommendations, the more these random pages will surprise and delight. Device : iPhone , iPad , Android 2. iReddit Reddit is a self-described social news website where users vote for their favorite stories, pictures or posts from other users, then argue vehemently over their meaning in the comments section. In recent years, it has gained readers as its competitor Digg has lost them.

‘Wireless’ humans could backbone new mobile networks

People could form the backbone of powerful new mobile internet networks by carrying wearable sensors. The sensors could create new ultra high bandwidth mobile internet infrastructures and reduce the density of mobile phone base stations.Engineers from Queen’s Institute of Electronics, Communications and Information Technology are working on a new project based on the rapidly developing science of body-centric communications.Social benefits could include vast improvements in mobile gaming and remote healthcare, along with new precision monitoring of athletes and real-time tactical training in team sports, an institute release said.The researchers are investigating how small sensors carried by members of the public, in items such as next generation smartphones, could communicate with each other to create potentially vast body-to-body networks.The new sensors would interact to transmit data, providing ‘anytime, anywhere’ mobile network connectivity.Simon Cotton from the i