FYI…

- http://www.pcworld.com/resource/printable/…d,126508,00.asp
July 25, 2006
"…Each of the sites… has been hacked by someone with the same modus operandi. The hacker has secretly inserted what is called an "iframe vulnerability" in the site's HTML code, without the site owner's knowledge. When you visit one of the hacked sites, a third party can try to install software onto your PC. Right now the hackers behind the iframe vulnerability are not distributing malicious code through any of the hacked sites. But at any time, they could flip the switch and start pumping out malware… It used to be that if you stayed away from the unsavory portions of the Web you could avoid getting hit with a drive-by download–where an attacker downloads malicious content to your PC without requiring any action from you. Today the Web bad guys have managed to penetrate nice Web neighborhoods. And some of the Web victims don't know what's hit them… A recently updated browser would most likely block malware from infecting a PC. But hackers hope that Web surfers who haven't installed the most recent Windows software patches or antivirus software will become their next victim… The trick these hackers use is to create a tiny, 1-by-1-pixel element on a Web page that links to a third-party Web site. The hacked site doesn't appear to be booby-trapped, enabling the hacker to keep a low profile. All the bad guy has to do to launch an attack is to load up the rigged site with malicious code; anyone who then visits the site is prey to a drive-by download. Cybercriminals are no longer mainly interested in defacing Web sites they break into, says Roger Thompson, chief researcher for Exploit Prevention Labs. Today they are more intent on quietly infecting PC users through vulnerabilities in Microsoft's Internet Explorer browser… One way to protect yourself from Web threats without obsessing about your PC's security deficiencies is to use programs that put extra locks on your Web browser. One excellent option comes from McAfee SiteAdvisor*… Another option comes from security firm Amust: Its 1-Defender** program attempts to lock down a browser so that when malicious code attempts to infect your PC, it hits a dead end. Other entrants include GreenBorder's GreenBorder Pro*** and Exploit Prevention Labs' SocketShield****…"

* http://www.siteadvisor.com/

** http://www.amustsoft.com/1%2Ddefender/download/

*** http://www.greenborder.com/consumer/

**** http://explabs.com/ss/trial.html

.