This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Hackers seed malware on AV site

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.theregister.co.uk/2008/02/08/in…ite_compromise/
8 February 2008 - "Hackers planted malicious script on the site of an Indian anti-virus firm this week. The website of AVsoft Technologies was attacked by unidentified miscreants in order to distribute a variant of the Virut virus. AVsoft Technologies makes the SmartCOP antivirus package. One of the download pages of the site was boobytrapped with malicious code that used the infamous iFrame exploit to push copies of the Virut virus onto visiting unpatched (or poorly patched) Windows PCs. The technique is a popular method for turning the websites of legitimate organisations into sites for drive-by malware downloads. Virut opens up a backdoor on infected PCs, allowing hackers to download and run other malware (or anything else they fancy) onto infected computers…"
> http://annysoft.wordpress.com/2008/02/06/a…te-is-infected/
8 Feb 2008 - "Malicious IFRAME has been removed… This all is used by the infamous (underground networks!!) tool 'IcePack'…"

Hackers seed malware on U.K. landmark site
- http://www.techworld.com/security/news/ind…amp;pagtype=all
02/08/08 - "The Web site of one of the U.K.'s most famous landmarks, the Forth Road Bridge, has been torn open in embarrassing fashion to serve malware, researchers are reporting. According to the security blog of a small consultancy, Roundtrip Solutions, the Web site is now hosting an 'obfuscated' Javascript hack created using the Neosploit Crimeware Toolkit, dishing out payloads including, the blog reports, porn pop-ups… The actual code embedded on the site's web server appears to point to a server in Turkey, returning instructions directing visitors to the BBC Web site, only -occasionally- delivering a more serious Javascript payload, essentially anything its creators wished… The hack doesn't appear to have been hard for the researchers to spot using Exploit Labs' (now AVG's) Linkscanner Pro firewall-oriented scanning software. Security vendor Finjan confirmed the hack as genuine… Website hacks of this sort are becoming more common, with Neosploit, Icepack, and the well-known Mpack attack kits now in common circulation…"

:ph34r: :ph34r:
More on this…

- http://preview.tinyurl.com/3b5ddu
February 07, 2008 (Infoworld) - "…According to Roger Thompson, chief research officer with security vendor AVG… "They let one of their pages get hit by an iFrame injection," he said. "It shows that anyone can be a victim… It's hard to protect Web servers properly." The technique used on the site has been seen in -thousands- of similar hacks over the past few months…"

:ph34r: :ph34r: