Interesting read and propaganda from Websense report for 2007, namely that compromised web sites serve more malware than malicious ones.
http://blog.washingtonpost.com/securityfix/Security%20Labs%20Report%20Q4_011808.pdfSo the Chicken/Egg question begs to be asked:
What came first; The compromised site or the malicious one? Isn't the compromised site serving malware considered a malicious site?
