Nellie2

Personal Ramblings on a Security Theme

Entries Comments



Who Is Responsible For The Content On Your Website?

5 November, 2007 | Internet, Security, websites | By: Nellie2

From Sophos Labs

At the end of last week, SophosLabs received a report from a customer saying that when they visited a certain site they received virus reports for Mal/ObfJS-A, Exp/Animoo-A and Mal/JSShell-B. The site in question is a household name which made the customer initially query the virus detections believing that such a global brand could not be infected. When I visited the site I found that the site did indeed link to malicious files.

So what had happened? Was the global brand’s website compromised? Or was something more sinister happening?

The global brand’s site loaded some content from a third party marketing company. However, the marketing company’s site had been compromised so that it now linked to malicious content on a remote server (we are aware of several thousand other sites similarly compromised). The net effect of this for users browsing the global brand’s site is that they are exposed to the malware.

Who is to blame?

The hacker and then the marketing company. The global brand, in this case, was an innocent party. However, from a customer perspective the big company appears guilty - when their site was browsed, the machine was hit with malware.

Remember, adding third party content can be a risky business. You have to make sure that their security policies match yours, otherwise you lose your reputation.

Pob, SophosLabs, UK

I’ve blatantly pinched this content from the Sophos site… I hope I’m forgiven! But I couldn’t pass this one by as it is a timely reminder to all webmasters that ultimately it is your responsibility to make sure your content is safe, whether you put it there or whether it is provided by a third party.

Comments

Comment from luai
Time: November 30, 2007, 4:01 pm

hi, i have the same problem with my web site, when i start to browse http://www.eueomecuador.org the anti virus give me this message: The page you’ve been trying to access was blocked.

Reason: Virus Detected! The page or file you requested is infected with the following virus: Mal/ObfJS-A.
The ID of the transaction is DF9038BC

any one can help me please to remove it

thanks

Luai

Write a comment