High ranking sites are still a target for malicious code injection. Last week, the site euroticketshop.com reselling tickets for the Euro 2008 soccer matches put visitors at risk of a drive-by infection.
The attacks are really ramping up the attacks and more sites are falling victim to it:
USAToday.com, ABCNews.com, News.com, Target.com, Packard Bell.com, Walmart.com, Rediff.com, MiamiHerald.com, Bloomingdales.com, PatentStorm.us, WebShots.com, Sears.com, Forbes.com, Ugo.com, Bartleby.com, Linkedwords.com, Circuitcity.com, Allwords.com, Blogdigger.com, Epinions.com, Buyersindex.com, Jcpenney.com, Nakido.com, Uvm.edu, hobbes.nmsu.edu, jurist.law.pitt.edu, boisestate.edu.
So how good are our virusscanners against the embedded malware?
Scanners Result: 12/32 (37.5%)
Suspicious:W32/Malware!Gemini; W32/BHO.BVW
File size: 107536 bytesMD5: e50f2c9874a128d4c15e72d26c78352c
SHA1: 91f8a0e2531ea63ce22d0c7f90e7366a78ebeb8aScanners Result: 2/32 (6.25%)
JS.Feebs.rv; JS/Feebs.gen2 @ MM
File size: 16098 bytes MD5: 64bbd8ba8a0c9ce009d19f5b8c9d426e
SHA1: 1b313198ef140d2c74f36aa84c13afe9497865b6Scanners Result : 11/32 (34.38%)
Trojan.Crypt.AN; FraudTool.Win32.UltimateDefender.cm
File size: 61440 bytes
MD5: 5d83515199803e1fbcd3d2d8e0cd4ce5SHA1: 4c1f0eba4be895cf3b018e41fa7f13523424874d
Hmmm..... a very gloomy picture but it doesn't surprise me.
Hmmm..... a very gloomy picture but it doesn't surprise me.
For the time being, Google is actively filtering the results, in fact removing the cached pages on number of domains when I last checked, the practice makes it both difficult to assess how many and which sites are actually affected, and of course, undermining the SEO poisoning, as without it the input validation and injecting the IFRAMEs would have never been able to attract traffic at the first place.Read the full analysis of Dancho Danchev with the IP blocks of the hosted malware and the juicy details.
The attack is now continuing, starting two weeks ago, the main IPs behind the IFRAMES are still active, new pieces of malware and rogue software is introduced hosting for which is still courtesy of the RBN, and we're definitely going to see many other sites with high page ranks targeted by a single massive SEO poisoning in a combination with IFRAME injections. Which site is next? Let's hope not yours, as if you don't take care of your web application vulnerabilities, someone else will.
So for the affected (infected) websites, upgrade your security and do input validation !!! End users, make sure your systems are patched and up-to-date. And I don't mean just Microsoft patches but your browser plugins. Check here.
Related articles:
Security4all Blog
Twitter
Slideshare
Facebook
Digg
Flickr



No comments:
Post a Comment