Top Client Web Application Attacks

Some of the most dangerous Web based threats today are targeted against the client’s Web browser and associated plugins and don’t require a user to take any action like traditional virus attacks. These attacks use malicious Java or Active-X scripts to compromise the system as soon as a user visits or “drives by” the Web site hosting the malicious code.

The majority of Web sites hosting these attacks are legitimate sites that have been compromised without the owner’s knowledge. Traditional anti virus or reputation-based defenses are not very effective in providing protection against these types of threats, which is why these attacks are becoming so popular with hackers.

The tables below list the most active exploits, the exploits that are showing the most rapid growth and the types of Web sites that have been delivering the malicious code to users on the Web.

Top Web Exploits (Feb 09)
MS09-032
MS06-014
CVE-2010-1297
MS00-059
Top Movers Web Exploits (Feb 09)
MS10-002
MS09-002
CVE-2010-1423
MS03-030
MS09-002
Top Compromised Categories (Feb 09)
Sex
Advertisements
Business and Economy
Message Boards and Forums
Information Technology