The time now is Wed 19 Jun 2013, 21:32
All times are UTC - 4 |
| Author |
Message |
Flash
Official Dog Handler

Joined: 04 May 2005 Posts: 9911 Location: Arizona USA
|
Posted: Wed 09 Sep 2009, 00:11 Post subject:
ScanSafe raises alarm: thousands of compromised Web pages |
|
http://blogs.techrepublic.com.com/security/?p=2213&tag=nl.e036
| Quote: | ScanSafe’s Mary Landesman author of the ominous-sounding post somehow found a malicious iFrame embedded in upwards of 55, 000 Web sites. That didn’t mean much to me until I found out what an iFrame was. According to the Web Design Group an iFrame consists of:
“The IFRAME element defines an inline frame for the inclusion of external objects including other HTML documents. IFRAME provides similar functionality to OBJECT. One advantage of IFRAME is that it can act as a target for other links.”
The last sentence is the one to pay attention to. In this particular case, the iFrame includes of the following snippet of code:
“script src=http://a0v.org/x.js”
If I understand correctly, that simple phrase will redirect Web browsers to http://a0v.org/a.js without the user knowing it.
What happens then
The Web site a0v.org is where the heavy-duty malware is. Once the Web browser is talking to a0v.org, Landesman explains a slew of malicious code consisting of trojans, backdoors, password stealers, and possibly a downloader will try to install on the visiting computer. If the operating system is Windows-based and vulnerable, the malware will successfully install. |
He goes on to say that Windows users are the only ones who have to worry, but I think that's wishful thinking. This exploit redirects browsers to a malware site, where anything is possible.
|
|
Back to top
|
|
 |
Aitch

Joined: 04 Apr 2007 Posts: 6825 Location: Chatham, Kent, UK
|
Posted: Wed 09 Sep 2009, 12:53 Post subject:
|
|
more news
http://securitylabs.websense.com/content/Blogs/3465.aspx
http://topbuzznews.info/script-src-http-a0v.orgx.js/
hosted by.....godaddy!!
Check the Registrant name/street!! FFS!!
If you're with them....move!
Aitch
|
|
Back to top
|
|
 |
mikeb

Joined: 23 Nov 2006 Posts: 4378
|
Posted: Wed 09 Sep 2009, 22:04 Post subject:
|
|
| Quote: | | http://a0v.org/x.js |
tried that address but said server not found.
My partener had on site to do with parent stuff and quite often it would send the cpu 100% and memory would fill up until total seizure...my guess was something in an advert.
mike
|
|
Back to top
|
|
 |
|
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You cannot attach files in this forum You can download files in this forum
|
Powered by phpBB © 2001, 2005 phpBB Group
|
|
[ Time: 0.0400s ][ Queries: 12 (0.0054s) ][ GZIP on ] |