Target: The Web: No Longer Focused on the Network, Hackers Have a Bull's Eye Now Trained Squarely on Web-Based Applications. What, If Anything, Can School Districts Do to Thwart Them?

John K. Waters · T.H.E. Journal Technological Horizons in Education · 2009

[ILLUSTRATION OMITTED] IN DECEMBER, MICROSOFT ANNOUNCED a major security flaw affecting its: Interact Explorer web browser. The flaw allowed hackers to use hidden computer code they had already injected into legitimate websites to steal the passwords of Visitors to those sites. Reportedly, more than 10,000 websites were infected with the destructive code by the time Microsoft came forward with the news. The announcement grabbed big headlines, emerging as it did during the Christmas season while unsuspecting online shoppers were clicking away. As Eric Schultze, CTO of Roseville, MN-based patch-management solutions provider Shavlik Technologies, explained it, hackers were exploiting legitimate websites via SQL injection techniques. means that visiting supposedly safe websites can lead to compromise via this IE flaw, Schultze said at the time. Attackers were able to exploit poor SQL coding practices on these 'legit' sites that enable hackers to inject evil code on the websites. The fix was simple enough, Microsoft provided a downloadable security patch in record time. Schultze described the company's reaction to the vulnerability as an all-hands-on-deck response that was quite disruptive to its own processes. But the flaw gave critics of the Redmond, WA-based technology empire an excuse to engage in some full-throated Microsoft bashing. Lost in the hubbub faultfinding, says web-application security expert Billy Hoffman, was a larger problem. These kinds of exploits come go, Hoffman says. Next, it'll be a Firefox flaw. A couple of weeks ago it was a problem with QuickTime. At the end of the day, the interesting thing about this IE security issue is that it wasn't about somebody e-mailing you a trojaned WMF image file. Now attackers are setting bear traps on websites. Hoffman manages HP's Web Security Research Group. Formerly a security researcher for SPI Dynamics (which HP acquired in 2007), he earned hacker street cred during his college days at Georgia Tech when he uncovered a security flaw in the school's magnetic ID card system. He later developed a suite of research tools for capturing, modifying, validating data from magnetic stripe cards, called Stripe Snoop. Within a day or two, at least 6,000 websites had been hacked, Hoffman says, explaining the lethal swiftness of the IE attack. That's an extremely fast turnaround time. were able to act that quickly these websites had already been compromised. They had exploit kits just sitting there on the web servers, the attackers just basically updated them to begin serving this IE exploit. It shows how automated these exploits have become. (Exploit kits are software tools that hackers create use for computer attacks. MPack, IcePack, Neosploit are among the best known.) Hoffman sees the speed with which attackers exploited the IE flaw as emblematic of a frightening trend--one that is colliding with an even scarier one: are targeting weaknesses in the application layer. And they are not planting the usual viruses or trojans that can be screened out with a firewall, but are revealing an emerging species of attack growing out of the inherent nature of applications that live on the web. Hackers have compromised hundreds of thousands of legitimate websites through web-app vulnerabilities, Hoffman says, and they are using those compromised sites to serve malware to visitors. This is a worrying development for educators who use online educational software content. What can K-12 technology managers do to cope with this new line of cyber attack? Controlling the Uncontrollable Unfortunately, there's really not much you can do, Hoffman says, because attackers are starting to target sites you trust. USA Today's website was used to serve malware earlier this year. It's not like you can say, 'Don't visit sites that have URLs ending in . …

Read the paper · More papers on PaperTik