Finjan Uncovers More Than 8,700 FTP Server Credentials in the Hands of Hackers - Top Global Domains

Printer-friendlyE-mail this news to a friendYour comment

In its latest Malicious Page of the Month report, Finjan reveals the commercialization of stolen FTP server credentials, owned by legitimate companies, by hackers who are using the NeoSploit Crimeware toolkit

Finjan Inc., a leader in secure web gateway products, today announced it has uncovered a database containing more than 8,700 harvested FTP account credentials, including username, password and server address - in the hands of hackers. These stolen credentials enable criminals to compromise servers and automatically inject crimeware to infect users visiting them. Among those stolen accounts are those of Fortune-level global companies in a wide range of industries including manufacturing, telecom, media, online retail, IT, as well as government agencies. The stolen FTP accounts include some of the world’s top 100 domains as ranked by Alexa.com.

Finjan’s Malicious Code Research Center (MCRC) has detailed the workings of an insidious new application, especially designed to abuse and trade stolen FTP account credentials of legitimate companies around the world. A trading interface is used to qualify the stolen accounts in terms of country of residence of the FTP server and Google page ranking of the compromised server. This information enables the cybercriminals to devise cost for the compromised FTP credentials for resale to other cybercriminals or to adjust the attack on more prominent sites. The trading application also allows the cybercriminal to manage FTP credential information to automatically inject IFRAME tags to web pages on the compromised server.

"Software-as-a-Service has been evolving for sometime, but until now, it has been applied only to legitimate applications. With this new trading application, cybercriminals have an instant ‘solution’ to their ‘problem’ of gaining access to FTP credentials and thus infecting both the legitimate websites and its unsuspecting visitors. All of this can be easily achieved with just one push of a button,” said Yuval Ben-Itzhak, CTO of Finjan.

Finjan invites IT security personnel from legitimate organizations to inquire if their FTP servers’ credentials are among those identified as stolen. Finjan can be contacted at http://www.finjan.com/contactFTP

According to Finjan, the NeoSploit 2 toolkit marks a serious escalation of Crimeware potential, since it uses the Software-as-a-Service business model.

Both the NeoSploit Version 2 toolkit and the application were detected using Finjan’s patented real-time code inspection technology while diagnosing users’ web traffic. The attack is described in detail in Finjan’s latest "Malicious Page of the Month” report released today.

To download the report, please visit http://www.finjan.com/mpom

27.02.2008, Finjan Software Inc.




Comments on this news 


Write your comment on this news

Subscribe to the newsletter

Never miss a story and stay informed with our newsletter.
Your email:  
RSS-Feed: All current newsOur News on your website

More current news

Delivering to the inbox and winning the war against spam
Prof. Howard A. Schmidt Appointed First President of the Information Security Forum
Companies Have a False Sense of Confidence in Their Backup Solutions
Nominum DNS Protects Over 120 Million Internet Users from New Vulnerability
Secure Computing Introduces Secure Web Reporter for Complete, Real-Time Viewing of Web Activity etc.

News on other topics

Pironet NDH new SAP Software Solution Partner in the SAP PartnerEdge Program
Four in one fell swoop: NZZ Media Group from Switzerland re-launches Intranet Portal with contentXXL
Deutsche Messe soon to run Intershop software
Management Supervisory Board Press Archive Image Database News Career Events Awards Histor
Intershop continues on positive growth path with renewed profit

Erotik Fotografen
The Content Management PortalThe Document Management PortalThe IT Security PortalThe Customer Relationship Management PortalThe E-Commerce PortalThe Enterprise Resource Planning PortalPortal on VoIP and mobile communication The directory of Clinic IT SolutionsThe directory for IT professionals
homeimprintprivacy policycontactadvertising

know how

news

events

security alerts

Quick search




Current survey


Do you use antivirus software at your workplace?



Recommended reading


Understanding Digital Signatures