1
   

Strange new attacks on the internet

 
 
Reply Fri 25 Jun, 2004 05:07 pm
It seems that some attacks on IIS servers are compromising web servers and including a global footer that contains a javascript exploit to download a trojan.

The attack seems to be very broad but not much else is known about it.

http://www.cnn.com/2004/TECH/internet/06/24/internet.attack.ap/index.html

Note: Able2Know does not use IIS servers.
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 1,519 • Replies: 11
No top replies

 
Mr Stillwater
 
  1  
Reply Fri 25 Jun, 2004 06:47 pm
What happens if one of the hamsters gets mange or breaks a whisker or something?
0 Replies
 
Craven de Kere
 
  1  
Reply Fri 25 Jun, 2004 06:51 pm
That particlar exploit isn't one that affects the platform A2K runs on.
0 Replies
 
ehBeth
 
  1  
Reply Fri 25 Jun, 2004 07:07 pm
Is that the popular chicken in every pot platform?
I'm quite fond of that one.




sorry.

I actually take this sort of thing seriously, but it's hard to figure out how to bookmark this kind of thread without being silly (and i'm trying to not just type bookmark or flyspeck or . )
0 Replies
 
Craven de Kere
 
  1  
Reply Sat 26 Jun, 2004 05:28 pm
The Russian server hosting the trojan has been shut down. So the exploit download goes to a 404 now.
0 Replies
 
dlowan
 
  1  
Reply Sat 26 Jun, 2004 08:03 pm
Washington Post article on what I assume is the same thing:

http://www.washingtonpost.com/wp-dyn/articles/A6746-2004Jun25.html?referrer=email for full article - free registration required.

Don't know if you agree with the advice here, Craven????

Virus Designed to Steal Windows Users' Data
Hundreds of Web Sites Targeted

By Brian Krebs
Special to The Washington Post
Saturday, June 26, 2004; Page A01


A new Internet virus has surfaced that allows hackers to steal passwords, credit card numbers and other personal information when someone merely visits an infected Web site, government computer security experts warned this week.

Hundreds of Web sites have been targeted by the virus, which exploits flaws in Microsoft Corp.'s Windows Internet software, according to an alert issued Thursday by the U.S. Computer Emergency Readiness Team (US-CERT), a division of the Department of Homeland Security.

Infected sites were programmed to connect people using the Microsoft Internet Explorer browser to a Web site that contains code allowing hackers to record what users type, such as passwords and credit card and Social Security numbers. The code then e-mails that information to the anonymous attackers.

Government officials would not identify the infected sites; computer security vendors said many have taken steps to fix the problem. In addition, most large Internet service providers have stopped forwarding Web traffic to the Russian Web site that apparently hosts the software that records what is typed, minimizing the theft of data, officials said.

Among the several Web sites hit by the virus, dubbed "js.scob.trojan" by one antivirus vendor, were the Web sites of the Kelley Blue Book automobile pricing guide and MinervaHealth Inc., a Jackson, Wyo., company that provides online financial services for hospitals and health care businesses.

Robyn Eckard, a spokeswoman for the Irvine, Calif.-based Kelley Blue Book, said the company learned about the problem late Wednesday after Web site visitors said their antivirus software tipped them off to the code. Eckard said Kelly Blue Book removed the malicious code from its site by late Thursday afternoon.

Jennifer Scharff, vice president of marketing for MinervaHealth, said some of the company's clients reported the problem on Thursday. The company has since fixed its site, she said. Scharff said no more than 50 visitors browsed the Web site during the time it was serving up the hostile code.

Stephen Toulouse, a security program manager at Microsoft, said the company does not believe the attack is widespread. "Nonetheless, we view this as a very real threat, with serious significance in terms of the potential impact on our customers," he said.

Toulouse said the company is gathering information on the attack and will hand it over to the FBI.

FBI spokesman Joe Parris declined to say whether the FBI is investigating the attack. "These types of Trojan horse attacks are not that uncommon, and we work closely with Microsoft in investigating matters of this type and always follow up on any information provided by industry," he said.

Security experts said the attack represents the latest variation on "phishing" scams, a form of fraud designed to trick people into giving personal data to criminals who have designed Web sites to look like those of respectable companies.

Ken Dunham, malicious code manager for iDefense Inc., a Reston-based computer security company, said he expects this kind of attack to become more widespread in coming weeks and months.
0 Replies
 
ossobuco
 
  1  
Reply Sat 26 Jun, 2004 09:43 pm
I read this earlier, Dlowan, and forwarded the article to work. As I remember at the end of it the expert suggested one option for computer users (pc's) was to switch to netscape, mozilla, or opera as a browser instead of internet explorer.
0 Replies
 
dlowan
 
  1  
Reply Sat 26 Jun, 2004 09:45 pm
Yes - that is why I was wondering if Craven agreed. It is quite a big thing to advise.
0 Replies
 
Craven de Kere
 
  1  
Reply Sat 26 Jun, 2004 09:57 pm
No, I do not advise it at all. It's one of the more idiotic things people advise.

Those other programs are not usually more secure. When a Linux or Mozilla exploit is found nobody advocates a move to Microsoft.

The call to those alternative programs is just a cultish following. Their answer to everything is "stop using Microsoft". It's a stupid way to think sourced nearly entirely in their personal feelings about Microsoft.

When their programs are found with holes you will never hear them advocate a move to Microsoft. It only works one way for them.

This exploit was dealt with and MS should release a patch shortly to prevent a new one.
0 Replies
 
Mr Stillwater
 
  1  
Reply Sun 27 Jun, 2004 06:16 pm
Well bugger that! I sold off my computer and bought an abacus! And I didn't need to?
0 Replies
 
PDiddie
 
  1  
Reply Tue 29 Jun, 2004 09:40 am
Craven de Kere wrote:
No, I do not advise it at all. It's one of the more idiotic things people advise.

Those other programs are not usually more secure. When a Linux or Mozilla exploit is found nobody advocates a move to Microsoft.

The call to those alternative programs is just a cultish following. Their answer to everything is "stop using Microsoft". It's a stupid way to think sourced nearly entirely in their personal feelings about Microsoft.

When their programs are found with holes you will never hear them advocate a move to Microsoft. It only works one way for them.

This exploit was dealt with and MS should release a patch shortly to prevent a new one.


This answers a question I posed to you on another thread. Thanks.
0 Replies
 
Craven de Kere
 
  1  
Reply Fri 2 Jul, 2004 06:41 pm
The patch was released today. Update your windows.
0 Replies
 
 

Related Topics

YouTube Is Doomed - Discussion by Shapeless
So I just joined Facebook.... - Discussion by DrewDad
Internet disinformation overload - Discussion by rosborne979
Participatory Democracy Online - Discussion by wandeljw
OpenDNS and net neutrality - Question by Butrflynet
Internet Explorer 8? - Question by Pitter
 
  1. Forums
  2. » Strange new attacks on the internet
Copyright © 2024 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.05 seconds on 04/19/2024 at 03:53:09