Story image

42% of Alexa-ranked websites are open invites for attackers

07 Feb 18

Many of the internet’s supposedly safe websites could actually be a breeding ground for risk – or at least that’s what Menlo Security’s third annual State of the Web report says.

Of the 100,000 top websites on the web as ranked by Alexa, 42% of those either use software that leaves them wide open to attack, or they are already compromised.

Many of those vulnerabilities are due to background sites that present online media such as video clips and online ads. The average website connects to 25 background sites for this content, Menlo Security says.

The company believes that most security administrators don’t have the resources or tools to monitor these connections, which leaves them vulnerable to backdoor attacks.

“This report confirms what most CISOs already know: that a false sense of security is a dangerous thing when using the web,” comments Menlo Security CEO Amir Ben-Efraim.

 “Despite website operators' best efforts, cyber-criminals can now exploit widespread vulnerabilities to compromise even the most trusted brands on the web." 

Sorting sites into ‘good’ or ‘bad’ sites doesn’t necessarily work, particularly as hackers are using trusted hosting services to set up genuine-looking phishing sites with safe-looking URLs.

The report found that 4600 phishing sites used legitimate hosting services and many ‘typosquatters’ formed in trusted categories such as financial services.

Typosquatting is the method of setting up fake domains that look similar to a company’s actual website, for example yaoo.com appears to look like yahoo.com.

“To prepare this report, we tracked the web activity of our users over a 30-day period. During that time, we saw traffic to 78 malicious sites that had been misspelled to deceive people trying to visit Alexa’s top 1,000 domains,” the report says.

It also says that business and economy sites received more than their fair share of risky activity last year. They hosted more phishing sites than any other category and experienced the most security incidents in the last 12 months. 12,307 business and economy sites had been used as attack vectors or malware delivery systems.

Menlo Security also analysed the script origin servers for both primary and background sites, and correlate known CVE vulnerabilities. The company found that more than 32,649 sites use Microsoft IIS 7.5, which was released in 2009.

Those results suggest that organisations are using aging software technologies to run their websites – technologies that may have been compromised multiple times since they were released.

“Many sites use software that is no longer fully supported. Microsoft’s Internet Information Services (IIS) 5 was released in 2000, and reached mainstream support end” in 2005, the report indicates.

Menlo Security says organisations must have a ‘healthy distrust' for the web.

“Website owners need to make sure their servers run the latest software updates, and should investigate technologies such as Content-Security-Policy (CSP), which can reduce introduction of malicious code via background sites.”

Using blockchain to ensure regulatory compliance
“Data privacy regulations such as the GDPR require you to put better safeguards in place to protect customer data, and to prove you’ve done it."
A10 aims to secure Kubernetes container environments
The solution aims to provide teams deploying microservices applications with an automated way to integrate enterprise-grade security with comprehensive application visibility and analytics.
DigiCert conquers Google's distrust of Symantec certs
“This could have been an extremely disruptive event to online commerce," comments DigiCert CEO John Merrill. 
One Identity a Visionary in Magic Quad for PAM
One Identity was recognised in the Gartner Magic Quadrant for Privileged Access Management for completeness of vision and ability to execute.
Gartner names newcomer Exabeam a leader in SIEM
The vendor landscape for SIEM is evolving, with recent entrants bringing technologies optimised for analytics use cases.
52mil users affected by Google+’s second data breach
Google+ APIs will be shut down within the next 90 days, and the consumer platform will be disabled in April 2019 instead of August 2019 as originally planned.
Symantec releases neural network-integrated USB scanning station
Symantec Industrial Control System Protection Neural helps defend against USB-borne cyber attacks on operational technology.
Ramping up security with next-gen firewalls
The classic firewall lacked the ability to distinguish between different kinds of web traffic.