Top Stories
|
Drive-by download attack compromises 500K websites13 May 2008 15:46 A funny thing happened on the way to the forumMore than half a million web pages have been compromised with malware as part of a new attack, Trend Micro warns. Badly configured PHP bulletin board applications are being used to plant malicious JavaScript on web forums. The JavaScript is used to push variants of the Zlob Trojan that come disguised as a video codec installer. The Trojans change DNS and browser settings on infected PCs leaving them open to further attack. Many of the compromised forums were already used to spamvertise knock-down drugs and smut sites. In the UK most of the infected websites belong to small- to medium-size firms whose weak security controls have left the door open to hackers. The malware is served up from systems based in the US and Russia. Trend reckons the latest attack bears the same hallmarks as previous attacks by a Russian and Ukrainian gang punting the Zlob Trojan. Trend has more on the attack in a blog posting here. Cybercrooks are increasingly looking toward planting malicious script onto regular sites rather than attempts to trick users into visiting obviously dodgy sites touting warez and porn. Fake media codecs are becoming a favourite vector for spreading spyware and Trojans. Last week McAfee warned that hundreds of thousands of samples of new Trojan that poses as a media file had flooded onto P2P networks. The booby-trapped files in that case and the Zlob-infected media codecs in the latest case both turn infected machines into zombie clients under the control of hackers. In both cases the scale of the attack rather than the technology in play, which has been around for months, is what's noteworthy. ® 14 comments posted — Comment period finished And remember, kids. Microsoft didn't develop PHP.Posted: 18:22 13th May 2008 Been going on for a whilePosted: 19:12 13th May 2008 Microsoft didn't develop PHP, but...Posted: 19:49 13th May 2008 And remember...Posted: 20:49 13th May 2008 Interoperability is usPosted: 20:56 13th May 2008
Track this type of story as a custom Atom/RSS feed or by email. Related storiesWeb browsers face crisis of security confidence (23 June 2008)
|
Breaking Hardware News
When Nvidia - allegedly - entered into an anti-Atom alliance with VIA, it was really preparing the ground to improve its negotiations with Intel. Allegedly. So say the latest rumours about rumours about rumours.
Newsletter |