Drive-by-Download

Drive-by Download

Unbemerkter Schadcode-Download beim Seitenbesuch

In a drive-by download, malicious code is loaded onto the device merely by visiting a manipulated website — without the user consciously downloading or clicking anything. Vulnerabilities in the browser or its components are exploited. The attack turns browsing itself into an entry point.

History & facts. Drive-by downloads exploit the fact that a browser automatically processes content when a page is opened — scripts, embedded components, advertising. If an exploitable vulnerability is present, merely loading the page can suffice to execute malicious code. Such pages are distributed via compromised legitimate websites, manipulated advertising networks (malvertising) or links in phishing messages. Often a prefabricated exploit kit is behind it. Outlook & recommendation. The most effective prevention is consistent updating of the browser, extensions and operating system, complemented by reducing attackable components and blocking malicious advertising and scripts. On the detection side, it helps to notice unusual follow-up activity after a page visit — an unexpected process, a new outbound connection. Since the user does nothing „wrong“ here, mere awareness falls short; what counts is the technical safeguard.
Drive-by-Download — Drive-by Download