Web sites are no longer attacked only for the purposes of defacing the site to gain credibility among hacking peer groups. Today it is about the money to be made for the bad guys in the distribution of malware and spam.

In our Web 2.0 world, legitimate Web sites have become the vehicle of choice in the distribution of malware. Automated JavaScript exploits quickly break through public-facing enterprise Web server defenses, deploying malware that infects each visitor that casually visits the infected Web page.

A recent study by Google confirms the prevalence of malware on legitimate Web sites:
“Google said that in its analysis of several billion URLs and an in-depth look at 4.5 million Web sites over a 12-month period, it discovered 450,000 sites were successfully launching drive-by-downloads of malware”.