DISCUSSION FORUMS
MAIN MENU
Home
Help
Advanced Search
Recent Posts
Site Statistics
Who's Online
Forum Rules
Bible Resources
• Bible Study Aids
• Bible Devotionals
• Audio Sermons
Community
• ChristiansUnite Blogs
• Christian Forums
• Facebook Apps
Web Search
• Christian Family Sites
• Top Christian Sites
• Christian RSS Feeds
Family Life
• Christian Finance
• ChristiansUnite KIDS
Shop
• Christian Magazines
• Christian Book Store
Read
• Christian News
• Christian Columns
• Christian Song Lyrics
• Christian Mailing Lists
Connect
• Christian Singles
• Christian Classifieds
Graphics
• Free Christian Clipart
• Christian Wallpaper
Fun Stuff
• Clean Christian Jokes
• Bible Trivia Quiz
• Online Video Games
• Bible Crosswords
Webmasters
• Christian Guestbooks
• Banner Exchange
• Dynamic Content

Subscribe to our Free Newsletter.
Enter your email address:

ChristiansUnite
Forums
Welcome, Guest. Please login or register.
April 26, 2024, 12:20:34 AM

Login with username, password and session length
Search:     Advanced search
Our Lord Jesus Christ loves you.
286805 Posts in 27568 Topics by 3790 Members
Latest Member: Goodwin
* Home Help Search Login Register
+  ChristiansUnite Forums
|-+  Entertainment
| |-+  Computer Hardware and Software (Moderator: admin)
| | |-+  IndiaTimes.com Visitors Risk High Exposure To Malware
« previous next »
Pages: [1] Go Down Print
Author Topic: IndiaTimes.com Visitors Risk High Exposure To Malware  (Read 8355 times)
Shammu
Global Moderator
Gold Member
*****
Offline Offline

Gender: Male
Posts: 34862


B(asic) I(nstructions) B(efore) L(eaving) E(arth)


View Profile WWW
« on: November 09, 2007, 09:20:44 PM »

IndiaTimes.com Visitors Risk High Exposure To Malware

The English-language version of the newspaper contains 434 malicious scripts, binaries, cookies, and images, according to a ScanSafe report.

By Thomas Claburn
InformationWeek
November 9, 2007 05:40 PM

Visitors to IndiaTimes.com, a major English-language Indian news site, risk infecting their computers with a deluge of malware, according to Mary Landesman, senior security researcher at ScanSafe.

"It's an entire cocktail of downloader Trojans and dropper Trojans," Landesman said Friday, putting the number of malicious files involved at 434. This includes scripts, binaries, cookies, and images.

Landesman characterized the size of the malicious payload as unusually large. She also noted that the attack involved a large number of Web sites. Analyzing just two of the binaries, she said that ScanSafe had identified at least 18 different IP addresses involved in the attack.

"Only certain pages of the IndiaTimes.com are infected," ScanSafe said in its Nov. 9 Threat Alert. "The impacted pages contain a script which points to a remote site containing iframes pointing to two additional sites. One of the sites included cookie scripts and an iframe pointing to a non-active site. The other iframe pointed to an encrypted script which exploits multiple vulnerabilities in an attempt to download malicious software onto susceptible systems of users visiting indiatimes.com."

"It appears that the Metasploit Framework was the framework used to facilitate these attacks," Landesman said. The Metasploit Framework is a security testing tool that can also be used maliciously.

Landesman decline to elaborate on the specifics of the exploit other than to say it involved cross-site scripting and that it could turn the victim's computer into a site for malware distribution. "We have reason to believe these are zero-day vulnerabilities," she said. "What we don't want to do is irresponsibly lead people to those exploit pages."

ScanSafe's Nov. 9 Threat Alert identifies one of the vulnerabilities as the MDAC vulnerability described in Microsoft Security Bulletin MS06-014.

Warning that much of current antivirus software misses this exploit, Landesman said that "a person even with up-to-date antivirus software is going to be susceptible to this. In the normal course of using this service, you'd arrive at this page and you'd be silently infected."

While Landesman would not say which operating systems or browsers could be affected, she acknowledged that ScanSafe had contactedMicrosoft (NSDQ: MSFT) about this particular attack. She also said that her company had reached out to IndiaTimes.com, but pointed out that Nov. 9 is a holiday in India.

"We're hoping they will cut their holiday short and take the appropriate actions," she said.

IndiaTimes.com Visitors Risk High Exposure To Malware
Logged

Pages: [1] Go Up Print 
« previous next »
Jump to:  



More From ChristiansUnite...    About Us | Privacy Policy | | ChristiansUnite.com Site Map | Statement of Beliefs



Copyright © 1999-2019 ChristiansUnite.com. All rights reserved.
Please send your questions, comments, or bug reports to the

Powered by SMF 1.1 RC2 | SMF © 2001-2005, Lewis Media