AplusWebMaster
Topic Starter
FYI…
- http://www.theregister.com/2007/09/11/yaho…on_malware_ads/
11th September 2007 - "A Yahoo-owned advertising network became the unwitting ally of cyber crooks after it spewed millions of Trojan-laced banner ads on MySpace, PhotoBucket and other websites. The banner ads, which were brokered by Right Media, were served an estimated 12 million times over a three-week period starting in early August, according to ScanSafe, a managed security provider. Earlier this year, Yahoo paid $650m to acquire the 80 percent of the company it didn't already own. The banners contained a Flash file that silently installed a Trojan back door on unpatched Windows machines that visited the popular web destinations. Using an unpatched version of Internet Explorer while visiting MySpace or PhotoBucket was all that was necessary to become infected. The ads also ran on TheSun.co.uk, Bebo.com and UltimateGuitar.com. Security Fix reported the story earlier*… The Trojan, identified by some security firms as Trojan Downloader.VBS.Agent.n, was distributed on more than 70 ad servers, which alternated between serving legitimate banners and those infected with the malicious payload. The Flash file checked to see if users were 1) using IE on a Windows machine that 2) had not installed the patch described in Microsoft Security Bulletin MS07-009 and 3) were not attached to a domain that didn't belong to Right Media. When all three conditions were met, the Flash file dropped an iframe that directed the vulnerable computer to download the Trojan from a server located in the Netherlands…"
* http://blog.washingtonpost.com/securityfix…d_on_mys_1.html
.
- http://www.theregister.com/2007/09/11/yaho…on_malware_ads/
11th September 2007 - "A Yahoo-owned advertising network became the unwitting ally of cyber crooks after it spewed millions of Trojan-laced banner ads on MySpace, PhotoBucket and other websites. The banner ads, which were brokered by Right Media, were served an estimated 12 million times over a three-week period starting in early August, according to ScanSafe, a managed security provider. Earlier this year, Yahoo paid $650m to acquire the 80 percent of the company it didn't already own. The banners contained a Flash file that silently installed a Trojan back door on unpatched Windows machines that visited the popular web destinations. Using an unpatched version of Internet Explorer while visiting MySpace or PhotoBucket was all that was necessary to become infected. The ads also ran on TheSun.co.uk, Bebo.com and UltimateGuitar.com. Security Fix reported the story earlier*… The Trojan, identified by some security firms as Trojan Downloader.VBS.Agent.n, was distributed on more than 70 ad servers, which alternated between serving legitimate banners and those infected with the malicious payload. The Flash file checked to see if users were 1) using IE on a Windows machine that 2) had not installed the patch described in Microsoft Security Bulletin MS07-009 and 3) were not attached to a domain that didn't belong to Right Media. When all three conditions were met, the Flash file dropped an iframe that directed the vulnerable computer to download the Trojan from a server located in the Netherlands…"
* http://blog.washingtonpost.com/securityfix…d_on_mys_1.html
.