This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Bofra/iframe Exploits On More Web Sites

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?date=2004-11-20
Updated November 20th 2004 15:27 UTC
"The Storm Center received a report this morning of a high profile UK website that contains a pointer on their main page to another URL hosting the Bofra/IFrame exploit. We have confirmed that if this site is visited using Internet Explorer the exploit will be downloaded. The site owners have been notified.

I know that everybody wants to know "which site?" but to keep little Johnny from burning his fingers we will not list the URL. Please exercise caution when using Microsoft's Internet Explorer since this issue has no current patch. The Storm Center recommends using an alternative browser when visiting sites other than those you absolutely trust…

UPDATE, 1525 UTC
The site in the UK has been fixed. We have received reports of sites in Sweden and the Netherlands that were also compromised. This may indicate a more wide-spread attack across Europe. One suggestion is that the advertising servers rather than the sites themselves contain the exploit, which of course means that perhaps hundreds of sites are affected."

:ph34r:
FYI…

- http://isc.sans.org/diary.php?date=2004-11-21
Updated November 21st 2004 19:29 UTC
"Update on Bofra/IFrame Exploits
We are still in the process of notifying sites that are hosting the exploit. We still encourage users to consider using another browser, other than IE6, until a patch for this is released by Microsoft. Windows XP SP2 is reported as not being vulnerable, and to this point we have nothing contrary.

Joe Stewart has an excellent writeup of the IFRAMES exploit, and should be read by users and admins both. Excellent piece of work, thank you Joe.

- http://www.lurhq.com/iframeads.html …"

:ph34r: :ph34r: