AplusWebMaster
Topic Starter
FYI…
- http://preview.tinyurl.com/3cppwr
May 19, 2007 ~ (Computerworld) - "A new, stealthier version of a previously known Russian Trojan horse program called Gozi has been circulating on the Net since April 17 and has already stolen personal data from more than 2000 home users worldwide. The compromised information includes bank and credit card account numbers (including CVV codes), Social Security numbers, and online payment account numbers as well as usernames and passwords. As with its predecessor, the new version of Gozi is programmed to steal information from encrypted SSL streams and send the stolen information to a server based in Russia…. the variant is identical to Gozi, Jackson said*. The Trojan takes advantage of a previously fixed vulnerability in the iFrame tags of Microsoft Corp.'s Internet Explorer to infect systems. Users typically appear to be infected when visiting certain hosted Web sites, community forums, social networking sites and those belonging to small businesses… The original Gozi Trojan stole more than 10,000 records containing confidential information belonging to about 5,200 home users, companies, government agencies, and law enforcement organizations before being detected. The server to which the data was being sent to had a very professional-looking front end that allowed users to log into individual accounts, view indexed data and get results from queries based on certain fields such as URL and form parameters… The server was managed by a Russian group called 76Service, which in turn had purchased the Gozi Trojan code from a set of Russian hackers calling themselves the HangUp Team."
* http://www.secureworks.com/research/threat…zi/?threat=gozi

- http://preview.tinyurl.com/3cppwr
May 19, 2007 ~ (Computerworld) - "A new, stealthier version of a previously known Russian Trojan horse program called Gozi has been circulating on the Net since April 17 and has already stolen personal data from more than 2000 home users worldwide. The compromised information includes bank and credit card account numbers (including CVV codes), Social Security numbers, and online payment account numbers as well as usernames and passwords. As with its predecessor, the new version of Gozi is programmed to steal information from encrypted SSL streams and send the stolen information to a server based in Russia…. the variant is identical to Gozi, Jackson said*. The Trojan takes advantage of a previously fixed vulnerability in the iFrame tags of Microsoft Corp.'s Internet Explorer to infect systems. Users typically appear to be infected when visiting certain hosted Web sites, community forums, social networking sites and those belonging to small businesses… The original Gozi Trojan stole more than 10,000 records containing confidential information belonging to about 5,200 home users, companies, government agencies, and law enforcement organizations before being detected. The server to which the data was being sent to had a very professional-looking front end that allowed users to log into individual accounts, view indexed data and get results from queries based on certain fields such as URL and form parameters… The server was managed by a Russian group called 76Service, which in turn had purchased the Gozi Trojan code from a set of Russian hackers calling themselves the HangUp Team."
* http://www.secureworks.com/research/threat…zi/?threat=gozi