AplusWebMaster
Topic Starter
FYI…
- http://preview.tinyurl.com/6zoezg
April 22, 2008 (Symantec Security Response Weblog) - "We have recently received a new Web exploit pack called Tornado that contains exploits for 14 vulnerabilities by default. The pack also contains the usual stats and admin pages; however, the greatest success of this pack appears to be how well it has stayed under the radar… It shows the number of visitors to the exploit pack and how many of those visitors were successfully exploited, which includes a breakdown by OS and by browser type… It appears that traffic is directed to the pack via “hacked” Web pages. There were ftp logs included with the pack that show this. The method for generating traffic for the exploit site was via logging into legitimate ftp accounts using stolen credentials and searching for all .html files. Whenever an html file was found, an iframe was inserted into the page, which pointed to the Tornado pack. This is a common technique used by many packs… Some people have confused this pack with the Neosploit exploit pack; however, the packs are significantly different. The most obvious difference is the fact that Tornado is written in php… Another interesting point about this pack is that although the pack is Russian owned/written, many of the servers hosting Tornado are in China. Could this be due to RBN moving to China, as has been reported elsewhere?…"

- http://preview.tinyurl.com/6zoezg
April 22, 2008 (Symantec Security Response Weblog) - "We have recently received a new Web exploit pack called Tornado that contains exploits for 14 vulnerabilities by default. The pack also contains the usual stats and admin pages; however, the greatest success of this pack appears to be how well it has stayed under the radar… It shows the number of visitors to the exploit pack and how many of those visitors were successfully exploited, which includes a breakdown by OS and by browser type… It appears that traffic is directed to the pack via “hacked” Web pages. There were ftp logs included with the pack that show this. The method for generating traffic for the exploit site was via logging into legitimate ftp accounts using stolen credentials and searching for all .html files. Whenever an html file was found, an iframe was inserted into the page, which pointed to the Tornado pack. This is a common technique used by many packs… Some people have confused this pack with the Neosploit exploit pack; however, the packs are significantly different. The most obvious difference is the fact that Tornado is written in php… Another interesting point about this pack is that although the pack is Russian owned/written, many of the servers hosting Tornado are in China. Could this be due to RBN moving to China, as has been reported elsewhere?…"