Porn sites more infected than thought
By Nicole Kobie
Posted on 11 Jun 2010 at 14:56
Porn sites are more than five times as likely to host malware than expected, according to a new study.
It’s long been assumed that visiting adult sites could lead to a digital infection, but a new International Secure Systems Lab study has shown 3.2% of adult sites host malware - much higher than the 0.6% previously predicted.
If we come up with something like this, you can assume that attackers are already doing this
“It is a very high figure,” researcher Gilbert Wondracek told PC Pro.
The researchers examined 270,000 pages across 35,000 domains, and also set up a pair of porn sites of their own to fully understand why such sites are so dirty.
They discovered that one reason adult sites spread malware so easily is the use of affiliate programmes, where one site will drive traffic to another in exchange for links, cash or simply free pornographic material to use.
Because such programmes don’t check who they’re doing business with, and sites use disguised links and other clandestine methods to drive people to different pages, it’s easy for criminals to abuse the system to spread malware.
To check the theory, the researchers paid $160 to drive 49,000 visitors to their own porn sites. Wondracek said 20,000 were surfing with software that had a known vulnerability of some sort, making it easy for them to pick up infections.
“If you want to set up a malicious site, you can easily disguise it as a porn site and benefit from all this infrastructure that is in place to trick website visitors to going to other sites,” he said.
Despite adult sites hosting more malware than standard web pages, most porn proprietors are not knowingly spreading infections. Almost all – some 98.2% – of the adult sites with malware had themselves been hacked to spread viruses, worms or trojans.
But by relying on “shady” techniques to drive traffic from site to site, the online porn industry has created a problem. “They inadvertently have created an ecosystem that can easily be abused on a large scale by cyber criminals, and that’s worrying,” he said.
“If you’re a malicious entity, you can easily abuse this,” he added. “If we come up with something like this, you can assume that attackers – the bad guys – are already doing this,” he said.
Because of that, Wondracek thinks paid-for and more reputable porn sites could use security as a “great selling point” to draw customers, while smaller, riskier sites might lose out.
From around the web
advertisement
- Chrome's shine getting lost in translation
- BytePac: the cardboard hard disk enclosure
- How tech loosens our grip on reality
- Hokum watch: Safer Internet Day
- Why I'm deleting Adobe from my PC
- Prepare to be patronised: it's Safer Internet Day
- Dear Sony, Samsung and every other tech company in the world: stop trying to be Apple
- Will Apple's Final Cut Pro X update placate the pros?
- Smartr Contacts for iPhone review
- Switching to Office 365's Outlook Web App
- Paying for your crimes with Bitcoin
- Pavement hacking: What it is and how to avoid it
- Google's risky pre-loaded pages
- Mac under attack: how secure is Apple's OS?
- Has your browser been hijacked?
- Can you send a truly anonymous email?
- Is it safe to send bank details over email?
- Sainsbury's Bank bans password storage
- MobileMe triggers credit card blocks
- How to stay safe against session hijacking
advertisement
