Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Securing Web Applications: The Open Web Application Security Project | Main | Attack on Vulnerability Disclosures Part 2: They Actually Do Some Good, Just Not What is Intended »

Hacking as a Business - More from the Frontlines

Following up on an earlier post about the increasingly business like model of hacking, the Journal News is also reporting the same findings.

According to a recent report from Websense, a San Diego
computer-security company, "True 'companies' have emerged, producing and selling toolkits and developing business-partner programs that enable less-technical, 'traditional' criminals to steal data and make money - lots of it."

It used to be that the biggest threats came from e-mail infected with pernicious worms and viruses. No longer.

Ben-Itzhak of Finjan Software said the Web itself is spreading infections, thanks to tens of thousands of sites carrying code that is designed to steal information from visiting computers.

According to Websense, during the first half of 2006 there was a 100 percent increase in sites designed to install "crimeware" that could log keystrokes. Websense counted 16,663 sites that carried code for stealing passwords, including banking passwords.

Defense in depth strategies are critical here. Keep desktop and network security measures up to date, especially anti-virus, firewalls, spyware scanners and content filters.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/176

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net