Jonathan Richards
Pick up your copy of Love: Forever Changes at WHSmith today
Comment: The silent danger of a clever Trojan
A popular travel website based in Croydon is one of hundreds of sites to have been attacked by a mysterious virus that is sweeping across the internet.
Directline-holidays, which offers cheap package holidays, is one of at least 200 sites - many UK-based - to be affected by a sinister computer virus, the likes of which security firms have never seen.
The virus, which was first detected late last year, attacks the computers of people who visit affected sites by installing a piece of software known as a Trojan, which is capable of stealing information and feeding it back to the attacker.
Unlike other viruses of its sort, the new program does not leave 'footprints' on affected sites, meaning that tracking its path across the internet is much more difficult.
"This attack is unlike anything we've seen," Mary Landesman, a researcher at the security firm ScanSafe, which has been helping one of the UK companies affected, said. "We've worked with one company that's been affected to completely rebuild their server from the ground up, and an hour later the problem came back."
ScanSafe said it estimated the number of websites affected to be 200, but two other companies - Finjan and Secure Works - believe the number could be as high as 10,000.
The sites affected were mostly "mom and pop" sites based in the UK running businesses in areas like travel, property and motoring, Ms Landesman said. They still attracted large numbers of visitors, however, because they performed well in search results.
One site listed by ScanSafe as having been compromised rents cottages in Yorskshire. Another provides replacement parts for Vauxhall cars.
A spokesman for Directline-holidays, which attracts 80,000 customers a day and is the top listed site in a Google search for 'cheap holidays', confirmed that one of the site's technical staff had noticed its servers had been behaving abnormally a week ago.
On analysis, the company discovered that the server had been targeted by a version of a virus "that most security software didn't recognise."
The server has now been removed and the remainder are unaffected, the spokesman said, adding that the site was hosted on one of the largest hosting services in the US.
"This is going to be an extraordinarily long-lived attack, because the evasion technique makes it so hard to take down," Don Jackson, a senior security researcher at SecureWorks said. "The underground hacker community is extolling its virtues and praising whoever came up with it."
It is unclear where those behind it were based, experts said, though the virus did not match any typical "attack patterns" of well-known Russian or Chinese groups.
Computer users were at risk, researchers warned, because many anti-virus programs were not capable of detecting 'dynamic' viruses such as this, which constantly changed their form.
Typically when a website is compromised, hackers install additional files on the site's server, directing a visitor's computer to do particular things when it lands on the site. Once these files are located, researchers can search for similar instances of them across web, enabling all affected site owners to be notified.
In this case, the site is hacked in such a way that only when a person visits the page are the malicious files installed on the site, meaning that they are otherwise undetectable to the company hosting it.
"We call it an 'on-the-fly' Trojan," Mikko Hypponen, chief research officer at the web security company F-Secure, said. "It's definitely a much more complex operation than we're accustomed to."
It is understood that only Windows users are affected by the virus.
Mr Hypponen urged computer owners to regularly update their virus protection, and always to download the latest version of browsers and other applications, such as media players, when prompted.
Explore your passion for food with the delights of Thai, Indian & Chinese cooking
In our new series, Tony Hawks takes a dry, wry look at modern life - junk mail, interminable meetings and snooty sales assistants
Read the training tips and advice that helped our London Triathletes
Read our exclusive 100 Years of Fleming and Bond interactive timeline, packed with original Times articles and reviews
The latest travel news plus the best hotels and gadgets for business travellers
Shortcuts to help you find sections and articles
2007
£30,000
2006
£14,337
2008
£39,937
Great car insurance deals online
c.£75,000
GlosFirstmeansbusiness
Gloucestershire
c. £90,000 + PRP
Essex County Council
Essex
£
Not Specified
The Bar Standards Board
London
Competitive Package
Npower
West Midlands
1 & 2 Bed apartments
From £249,995
Great Investment, River Views
Great Dubai Investment Opportunities
from £89,950
low-cost ownership homes in London
Multi–Centre 9 Nights
From only £925pp
View thousands of properties online with your Vacation Rental People
£POA
List your property with two leading travel websites
£POA
Great travel insurance deals online
Contact our advertising team for advertising and sponsorship in Times Online, The Times and The Sunday Times. Globrix Property Search - find property for sale and rent in the UK. Milkround Job Search - for graduate careers in the UK. Visit our classified services and find jobs, used cars, property or holidays. Use our dating service, read our births, marriages and deaths announcements, or place your advertisement.
Copyright 2008 Times Newspapers Ltd.
This service is provided on Times Newspapers' standard Terms and Conditions. Please read our Privacy Policy.To inquire about a licence to reproduce material from Times Online, The Times or The Sunday Times, click here.This website is published by a member of the News International Group. News International Limited, 1 Virginia St, London E98 1XY, is the holding company for the News International group and is registered in England No 81701. VAT number GB 243 8054 69.
Please be careful when asked by a site to download somrthing as contrary to your advice some site download viruses by asking you to download the "latest" or that you need an additional module to your existing programme as I found out by mistake. Only download from trusted sites. If in doubt go to microsoft's own site.
Ernie Goody, Haverhill, Suffolk, UK
Skynet has become aware...
Max, Sydney, Australia
this seems to have affected 2 of our office PC's and the 2 we have at home
Andrew, Caerphilly, wales