Malware's next big trends?
Always on the lookout for new and less-noticeable means for carrying out online fraud and other cyber-crimes, hackers are increasingly moving to adopt techniques including response splitting and cross-site forgery as they continue to mature their attacks, according to Web security and testing expert Jeremiah Grossman.
Grossman, founder and CTO of Web site vulnerability testing specialists WhiteHat Security, said that he has recently begun noticing more attacks in the wild that employ the two methods -- both of which have been understood for some time, but were thought to be avoided by most hackers based on their complexity and the availability of easier means to trick Web sites and end users.
While cross-site scripting (XSS) threats remain by far the most widespread method in use today by advanced hackers who seek to defraud online businesses and end users -- and Grossman expects that to be the case for the foreseeable future until more Web sites are secured from the technique -- the expert indicated that response splitting and cross-site forgery could represent the next big things in terms of vulnerability exploitation trends.