This is a great article about the value of a hacked PC to an attacker. While this focuses on personal PCs, all of these reasons can also apply to compromised web servers. Remember, web hacking has evolved. Script kiddies began by defacing web sites and conducting other forms of cyber vandalism. As applications grew in complexity, so did the attacks. Suddenly, it was all about the data as hackers learned how to extract the data contained in applications via SQL Injection and other methods. Now, though, the attacks are designed to compromise a web server and use it as a platform to spread malware (or worse) and conduct other crime. And as the threats grow, so does the need to integrate security throughout the application lifecycle.
http://voices.washingtonpost.com/securityfix/2009/05/the_scrap_value_of_a_hacked_pc.html?wprss=securityfix
Posted
06-02-2009 2:22 PM
by
mark.painter