Welcome! Register for a free account (or login) > How does it work?
|
|


Apr 22 2008, 02:27 PM
Post
#1
|
|
![]() AplusWebMaster ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 4,575 Joined: 30-December 03 From: USA Member No.: 1,643 Operating System: XP/SP3 |
FYI...
- http://securitylabs.websense.com/content/Alerts/3070.aspx 04.22.2008 - "...malicious JavaScript injection that compromised thousands of domains at the start of this month, just 2-3 weeks ago. The attackers have now switched over to a new domain as their hub for hosting the malicious payload in this attack. We have no doubt that the two attacks are related... In the last few hours we have seen the number of compromised sites increase by a factor of ten. This mass injection is remarkably similar to the attack we saw earlier this month. When a user browses to a compromised site, the injected JavaScript loads a file named 1.js which is hosted on hxxp ://www.nihao[removed].com The JavaScript code then redirects the user to 1.htm (also hosted on the same server). Once loaded, the file attempts 8 different exploits (the attack last April utilised 12). The exploits target Microsoft applications, specifically browsers not patched against the VML exploit MS07-004 as well as other applications. Ominously files named McAfee.htm and Yahoo.php are also called by 1.htm but are no longer active at the time of writing. There are further similarities too between the two mass attacks. Resident on the latest malicious domain is a tool used in the execution of the attack. An analysis of that tool can be found in the ISC diary entry here*... It appears that same tool was used to orchestrate this attack too. When we first started tracking the use of this domain, the malicious JavaScript was still making use of hxxp ://www.nmida[removed].com/... Sites of varying content have been infected including UK government sites, and a United Nations website as can be seen by the Google search... The number of sites affected is in the hundreds of thousands..." * http://isc.sans.org/diary.html?n&storyid=4294 Last Updated: 2008-04-16 19:14:00 UTC This post has been edited by AplusWebMaster: Jul 4 2009, 08:29 AM |
|
|
|
![]() |
Sep 29 2008, 06:07 AM
Post
#2
|
|
![]() AplusWebMaster ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 4,575 Joined: 30-December 03 From: USA Member No.: 1,643 Operating System: XP/SP3 |
FYI...
ASPROX mutant - http://isc.sans.org/diary.html?storyid=5092 Last Updated: 2008-09-29 10:22:25 UTC - "...ongoing SQL injections... The injection itself (starting with DECLARE...) looks a lot like the technique used by ASPROX (see our earlier diary*), but that the injection attempt here is made not via the URL but rather via a cookie is a new twist... in the end delivers a file called "x.exe" that looks like yet another password stealer, but has poor detection at this time (Virustotal**)..." * http://isc.sans.org/diary.html?storyid=4565 ** http://www.virustotal.com/en/analisis/5584...41d7ae62c126fff |
|
|
|
AplusWebMaster Thousands of sites infected - attack in progress Apr 22 2008, 02:27 PM
AplusWebMaster FYI...
- http://preview.tinyurl.com/6mgej5
July 1... Jul 19 2008, 05:24 AM
AplusWebMaster FYI...
SQL Injection List - Format Update
- http:... Jul 21 2008, 10:04 AM
AplusWebMaster FYI...
- http://isc.sans.org/diary.html?storyid=4... Jul 24 2008, 05:17 AM
AplusWebMaster FYI...
SQL Injection Attacks Targeting Chinese-or... Aug 8 2008, 07:36 AM
AplusWebMaster FYI...
More SQL Injections ...active NOW
- http:/... Aug 8 2008, 10:54 AM
AplusWebMaster FYI...
Sunkist site - mass JavaScript injection
-... Aug 22 2008, 07:08 PM
AplusWebMaster FYI...
- http://www.darkreading.com/document.asp?... Aug 29 2008, 06:08 AM
AplusWebMaster FYI...
SQL injection ...BusinessWeek.com
- http:/... Sep 16 2008, 07:03 AM
AplusWebMaster FYI...
SQL threat: All Your (Data)base Are Belong... Sep 18 2008, 03:48 AM
AplusWebMaster FYI...
China Business Network Rail Site Infected ... Oct 14 2008, 12:04 PM
AplusWebMaster FYI...
Adobe site - SQL injected...
- http://www.... Oct 17 2008, 09:34 AM
AplusWebMaster FYI...
ECPAT NZ INC Courtesy Site: Mass Injection... Nov 4 2008, 06:24 PM
AplusWebMaster FYI...
- http://www.viruslist.com/en/weblog?weblo... Nov 8 2008, 03:43 PM
AplusWebMaster Shadowserver - Full list of Injected Sites updated... Nov 25 2008, 08:48 AM
AplusWebMaster FYI...
CBS website iFrame hack
- http://www.infow... Dec 1 2008, 12:40 PM
AplusWebMaster FYI...
Mass Injection on John Sands Greeting Card... Dec 24 2008, 04:46 AM
AplusWebMaster FYI...
Multiple Chinese sites compromised...
- ht... Dec 31 2008, 01:42 PM
AplusWebMaster FYI...
Paris Hilton website infected with malware... Jan 13 2009, 10:08 AM
AplusWebMaster FYI...
"Warning: We strongly suggest that re... Jan 27 2009, 05:19 AM
AplusWebMaster FYI...
IEC website compromised
- http://securityl... Jan 27 2009, 10:36 AM
AplusWebMaster FYI...
- http://www.pcmag.com/article2/0,2817,233... Jan 28 2009, 02:23 PM
AplusWebMaster FYI... (It appears the hacks have been busy - CYA)... Jan 30 2009, 09:04 AM
AplusWebMaster FYI...
- http://www-935.ibm.com/services/us/index... Feb 3 2009, 11:57 AM
AplusWebMaster FYI...
Kaspersky USA site hacked...
- http://www.... Feb 8 2009, 12:02 PM
AplusWebMaster FYI...
500,000 Websites Hit By New Form Of SQL In... Feb 27 2009, 10:53 AM
AplusWebMaster FYI...
DNS redirect attack - Puerto Rico
- http:/... Apr 29 2009, 11:05 AM
AplusWebMaster FYI...
SQL injections through Search Engine recon... Apr 30 2009, 04:20 AM
AplusWebMaster FYI...
- http://preview.tinyurl.com/rbxxwa
May 14... May 15 2009, 05:42 AM
AplusWebMaster More...
- http://isc.sans.org/diary.html?storyid=... May 18 2009, 01:50 PM
AplusWebMaster FYI...
- http://preview.tinyurl.com/qlr9ba
05-19-... May 19 2009, 10:39 AM
AplusWebMaster FYI...
Gumblar/Martuz/Geno attack
- http://isc.sa... May 22 2009, 10:37 AM
AplusWebMaster FYI...
Mass Injection Compromises More than Twent... May 29 2009, 05:02 PM
Shadab So how are the webpages getting compromised in the... May 29 2009, 11:30 PM
AplusWebMaster QUOTE So how are the webpages getting compromised ... May 30 2009, 02:49 AM
AplusWebMaster FYI...
- http://www.theregister.co.uk/2009/05/30/... May 30 2009, 01:08 PM
AplusWebMaster FYI...
- http://securitylabs.websense.com/content... Jun 1 2009, 10:23 PM
AplusWebMaster FYI...
Malware payload site changes to Shkarkimi
... Jun 4 2009, 05:29 PM
AplusWebMaster FYI...
- http://blog.trendmicro.com/another-wave-... Jun 7 2009, 04:02 AM
AplusWebMaster FYI...
- http://www.securityfocus.com/brief/970
2... Jun 8 2009, 01:04 PM
AplusWebMaster FYI...
- http://windowssecrets.com/comp/090611#st... Jun 11 2009, 04:32 AM
AplusWebMaster FYI...
Gumblar invades Best Buy
- http://blog.tre... Jul 3 2009, 06:17 AM
AplusWebMaster FYI...
SQL injection attacks hit 57K sites
- http... Aug 24 2009, 04:06 PM
AplusWebMaster FYI... [Please DO NOT visit these domains as they ... Aug 26 2009, 08:07 PM
AplusWebMaster FYI...
Another mass compromise attack
- http://bl... Aug 28 2009, 09:23 AM
AplusWebMaster FYI...
2009 - Top Cyber Security Risks
- http://w... Sep 15 2009, 09:24 AM
AplusWebMaster FYI...
Gumblar attacks surge again
- http://www.p... Oct 21 2009, 03:17 AM
AplusWebMaster FYI...
6 million pwnd - Mass web infections spike... Oct 28 2009, 03:18 AM
AplusWebMaster FYI...
Media-servers.net compromised
- http://sec... Nov 5 2009, 01:09 PM
Doug Happily, anyone protected by MVPS Hosts File alrea... Nov 5 2009, 05:29 PM![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
7 | Helpless Oldie | 163 | 19th March 2010 - 03:09 AM Last post by: CatByte |
|||
![]() |
10 | stech | 278 | 18th March 2010 - 08:35 PM Last post by: Conspire |
|||
![]() |
11 | pacificjade | 137 | 18th March 2010 - 05:00 PM Last post by: LDTate |
|||
![]() |
10 | larryri42 | 185 | 18th March 2010 - 10:51 AM Last post by: CatByte |
|||
|
Time is now: 21st March 2010 - 12:17 AM |