Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 20th, 2012, 05:02 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,218
Default The Rise of the “Blackhole” Exploit Kit: The Importance of Keeping All Software Up To

Quote:
Tim Rains - Microsoft
19 Jul 2012 9:30 AM

According to data we recently published in the Microsoft Security Intelligence Report volume 12 (SIRv12), drive-by download attacks continue to be a favorite tactic used by many attackers attempting to compromise large numbers of systems around the world. I have written about drive-by download attacks in the past (What You Should Know About Drive-By Download Attacks part 1, part 2) and the need to keep all software up-to-date in an effort to mitigate this type of attack.

In the second half of 2011 (2H11) there was a dramatic increase in detections of exploits delivered through JavaScript. This increase was due primarily to the emergence of JS/Blacole, a family of exploits used by the so-called “Blackhole” exploit kit to deliver malicious software through infected web pages.
https://blogs.technet.com/b/security...edirected=true
  #2  
Old July 20th, 2012, 06:05 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: The Rise of the “Blackhole” Exploit Kit: The Importance of Keeping All Software Up To

Funny how when they were pushing SmartScreen their statistics lumped so much into what they considered "Social Engineering."
__________________
  #3  
Old July 20th, 2012, 07:50 PM
funkydude's Avatar
funkydude funkydude is online now
Incredibly Massive Poster
 
Join Date: Apr 2004
Posts: 6,003
Default Re: The Rise of the “Blackhole” Exploit Kit: The Importance of Keeping All Software Up To

Quote:
Originally Posted by Hungry Man
Funny how when they were pushing SmartScreen their statistics lumped so much into what they considered "Social Engineering."

What about the social engineering involved in getting people to these sites?
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #4  
Old July 20th, 2012, 08:01 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: The Rise of the “Blackhole” Exploit Kit: The Importance of Keeping All Software Up To

That's my point. Most attacks have some element of both - people aren't just hacked, they have to end up on a webpage somehow (or they don't have ot, but typically are) and at that point an exploit takes over.

With the SmartScreen stats they reported most infections being due primarily to social engineering. Almost every other report has shown that there's a ton of vulnerabilities being exploited in the wild.
__________________
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:54 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums