<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: iframe]]></title>
    <link>http://securityratty.com/tag/iframe</link>
    <description></description>
    <pubDate>Mon, 26 May 2008 06:58:01 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Fake Security Software Domains Serving Exploits]]></title>
      <link>http://securityratty.com/article/a2ffa8d411dc417bdb5a774ee6ab5207</link>
      <guid>http://securityratty.com/article/a2ffa8d411dc417bdb5a774ee6ab5207</guid>
      <description><![CDATA[Psychological imagination, &quot;think cybercriminals&quot; mentality or scenario building intelligence, seem to always produce the results they are supposed to. On Monday, I pointed out that

Ironically, the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SLaDCa0a4yI/AAAAAAAACIU/V4NpXSLdBEA/s1600-h/fake_software_client_side_exploits.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SLaDCa0a4yI/AAAAAAAACIU/6N2G2L2h2-0/s200-R/fake_software_client_side_exploits.png" /></a>Psychological imagination, "think cybercriminals" mentality or scenario building intelligence, seem to always produce the results they are supposed to. On Monday, <a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">I pointed out that</a> :<br />
<br />
"<i>Ironically, the participant in the affiliate program whose original objective was to drive traffic to the fake security software's site, may in fact start receiving so much traffic due to the combination of traffic acquisition tactics, that <a href="http://ddanchev.blogspot.com/2008/02/serving-malware-through-advertising.html">introducing client-side exploits courtesy of a third-party affiliate network</a>, may in fact prove more profitable then the revenue sharing partnership with the rogue security software's vendor at the first place.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SLaJ9G1B_YI/AAAAAAAACIk/WVx1enYkT0E/s1600-h/fake_security_client_side.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SLaJ9G1B_YI/AAAAAAAACIk/XSe4BHhrt2w/s200-R/fake_security_client_side.JPG" /></a>The next day, <a href="http://sunbeltblog.blogspot.com/2008/08/xp-antivirus-2008-now-with-sploits.html">client-side exploits start getting introduced</a> "in between" the fake security software sites :<br />
<br />
"<i>I've blogged before about the problem of Google Adwords pushing Antivirus XP Antivirus 2008. The situation is still ongoing.&nbsp; However, it's taken a turn for the worse, as these XP Antivirus pages are pushing exploits to install malware on the users system. This will also affect the many syndicators of Google Adwords.</i>"<br />
<br />
The domain in question <b>bestantivirus2009.com</b> - (68.180.151.21) is hosting the binary at <b>bestantivirus2009 .com</b>/setup_1096_MTYwM3wzNXww_.exe and has an IFRAME pointing to <b>huytegygle .com</b>/index.php (200.46.83.246).<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SLaOX5IUu2I/AAAAAAAACIs/UmA8sFcQCIA/s1600-h/antivirus0003.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SLaOX5IUu2I/AAAAAAAACIs/YL8oDzvUAeY/s200-R/antivirus0003.png" /></a>Here's another example <b>antivirus0003.net</b> with an IFRAME pointing to a different location - <b>124.217.250.85 /~ave/etc/count.php?o=16</b>.<br />
<br />
Despite that these domains are part of the "International Virus Research Lab" fake domains portfolio, it remains to be seen whether others will start multitasking as well.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=yRDO0K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=yRDO0K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mEJFVK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mEJFVK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=74vKNk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=74vKNk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=FMF6wk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=FMF6wk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fnoShK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fnoShK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5q8hIK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5q8hIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GNqd3k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GNqd3k" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/377056323" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 02:41:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/exploits">exploits</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/client-side exploits courtesy">client-side exploits courtesy</category>
      <category domain="http://securityratty.com/tag/client-side exploits start">client-side exploits start</category>
      <category domain="http://securityratty.com/tag/start">start</category>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/antivirus">antivirus</category>
      <category domain="http://securityratty.com/tag/google adwords">google adwords</category>
      <category domain="http://securityratty.com/tag/fake domains portfolio">fake domains portfolio</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/377056323/fake-security-software-domains-serving.html">Fake Security Software Domains Serving Exploits</source>
    </item>
    <item>
      <title><![CDATA[Compromised Cpanel Accounts For Sale]]></title>
      <link>http://securityratty.com/article/6228ebb081126296ff70b5f6268fd2a3</link>
      <guid>http://securityratty.com/article/6228ebb081126296ff70b5f6268fd2a3</guid>
      <description><![CDATA[Is the once popular in the second quarter of 2007, embedded malware tactic on the verge of irrelevance, and if so, what has contributed to its decline? Have SQL injections executed through botnets...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SKlq1uSeDFI/AAAAAAAACDM/l4bxcru-BQk/s1600-h/cpanel_multiple_domains1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SKlq1uSeDFI/AAAAAAAACDM/ho301JgoMUs/s200-R/cpanel_multiple_domains1.png" /></a> Is the once popular in the second quarter of 2007, embedded malware tactic on the verge of irrelevance, and if so, what has contributed to its decline? Have SQL injections executed through botnets turned into the most efficient way to infect hundreds of thousands of legitimate web sites? Depends on who you're dealing with.<br />
<br />
A cyber criminal's position in the "underground food chain" can be easily tracked down on the basis of tools and tactics that he's taking advantage of, in fact, some would on purposely misinform on what their actual capabilities are in order not to attract too much attention to their real ones, consisting of high-profile compromises at hundreds of high-profile web sites.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SKmDVdDGnPI/AAAAAAAACDU/qNbLBUKlHp0/s1600-h/cpanel_multiple_domains3.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SKmDVdDGnPI/AAAAAAAACDU/ZsmcK9HMeUs/s200-R/cpanel_multiple_domains3.jpg" /></a>Embedded malware may not be as hot as it used to be in the last quarter of 2007, but thanks to the oversupply of stolen accounting data, certain individuals within the underground ecosystem seem to be abusing entire portfolios of domains on the basis of purchasing access to the compromised accounts. In fact, the oversupply of compromised Cpanel accounts is logically resulting in their decreasing price, with the sellers differentiating their propositions, and charging premium prices based on the site's page ranks and traffic, measured through publicly available services, or through the internal statistics.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SKmMyr4CWEI/AAAAAAAACDc/UafOTCKAb-0/s1600-h/cpanel_multiple_domains22.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SKmMyr4CWEI/AAAAAAAACDc/7IRBMNndy-w/s200-R/cpanel_multiple_domains22.JPG" /></a><br />
SQL injections may be the tactic of choice for the time being, but as long as stolen accounting data consisting of Cpanel logins, and web shells access to misconfigured web servers remain desired underground goods, goold old fashioned embedded malware will continue taking place.<br />
<br />
Interestingly, from an economic perspective, the way the seller markets his goods, can greatly influence the way they get abused given he continues offering after-sale services and support. It's blackhat search engine optimization I have in mind, sometimes the tactic of choice especially given its high liquidity in respect to monetizing the compromised access.<br />
<br />
The bottom line - for the time being, there's a higher probability that your web properties will get SQL injected, than IFRAME-ed, as it used to be half a year ago, and that's because what used to be a situation where malicious parties would aim at launching a targeted attack at high profile site and abuse the huge traffic it receives, is today's pragmatic reality where a couple of hundred low profile web sites can in fact return more traffic to the cyber criminals, and greatly extend the lifecycle of their campaign taking advantage of the fact the the low profile site owners would remain infected and vulnerable for months to come.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/03/embedding-malicious-iframes-through.html">Embedding Malicious IFRAMEs Through Stolen FTP Accounts</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/injecting-iframes-by-abusing-input.html">Injecting IFRAMEs by Abusing Input Validation</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">Money Mule Recruiters use ASProx's Fast-flux Services</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/malware-domains-used-in-sql-injection.html">Malware Domains Used in the SQL Injection Attacks</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast-fluxed SQL Injected Domains</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/sql-injecting-malicious-doorways-to.html">SQL Injecting Malicious Doorways to Serve Malware </a><br />
<a href="http://ddanchev.blogspot.com/2008/05/yet-another-massive-sql-injection.html">Yet Another Massive SQL Injection Spotted in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/malware-domains-used-in-sql-injection.html">Malware Domains Used in the SQL Injection Attacks</a><br />
<a href="http://ddanchev.blogspot.com/2007/07/sql-injection-through-search-engines.html">SQL Injection Through Search Engines Reconnaissance</a><br />
<a href="http://ddanchev.blogspot.com/2007/05/google-hacking-for-vulnerabilities.html">Google Hacking for Vulnerabilities</a><br />
<a href="http://blogs.zdnet.com/security/?p=1122">Fast-Fluxing SQL injection attacks executed from the Asprox botnet</a><br />
<a href="http://blogs.zdnet.com/security/?p=1394">Sony PlayStation's site SQL injected, redirecting to rogue security software</a><br />
<a href="http://blogs.zdnet.com/security/?p=1118">Redmond Magazine Successfully SQL Injected by Chinese Hacktivists</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ExzKaK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ExzKaK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AgwoKK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AgwoKK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5JjO7k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5JjO7k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5Z85mk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5Z85mk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=s4xhGK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=s4xhGK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ReebmK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ReebmK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=T0yjTk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=T0yjTk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/368194376" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 06:42:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sql">sql</category>
      <category domain="http://securityratty.com/tag/sql injections">sql injections</category>
      <category domain="http://securityratty.com/tag/sql injection attacks">sql injection attacks</category>
      <category domain="http://securityratty.com/tag/massive sql injection">massive sql injection</category>
      <category domain="http://securityratty.com/tag/profile site">profile site</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/site sql">site sql</category>
      <category domain="http://securityratty.com/tag/sql injection">sql injection</category>
      <category domain="http://securityratty.com/tag/tactic">tactic</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/368194376/compromised-cpanel-accounts-for-sale.html">Compromised Cpanel Accounts For Sale</source>
    </item>
    <item>
      <title><![CDATA[Malicious Javascript Code In Another CNET Networks Website]]></title>
      <link>http://securityratty.com/article/c26d06f4a7b2d84f138987ddf691adf6</link>
      <guid>http://securityratty.com/article/c26d06f4a7b2d84f138987ddf691adf6</guid>
      <description><![CDATA[Websense has discovered that another CNET Networks site, CNET Clientside Developer Blog, has been compromised, just 5 months after previous incident. The main page of this website contains malicious...]]></description>
      <content:encoded><![CDATA[Websense has discovered that another CNET Networks site, CNET Clientside Developer Blog, has been compromised, just 5 months after previous incident. The main page of this website contains malicious JavaScript code that de-obfuscates into an iframe that loads its primary malicious payload from a different host. This malicious JavaScript code attempts to access the live [...]]]></content:encoded>
      <pubDate>Fri, 08 Aug 2008 06:14:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malicious javascript code">malicious javascript code</category>
      <category domain="http://securityratty.com/tag/cnet networks site">cnet networks site</category>
      <category domain="http://securityratty.com/tag/primary malicious payload">primary malicious payload</category>
      <category domain="http://securityratty.com/tag/website">website</category>
      <category domain="http://securityratty.com/tag/previous incident">previous incident</category>
      <category domain="http://securityratty.com/tag/main page">main page</category>
      <category domain="http://securityratty.com/tag/websense">websense</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/loads">loads</category>
      <source url="http://cyberinsecure.com/malicious-javascript-code-in-another-cnet-networks-website/">Malicious Javascript Code In Another CNET Networks Website</source>
    </item>
    <item>
      <title><![CDATA[Compromised Web Servers Serving Fake Flash Players]]></title>
      <link>http://securityratty.com/article/df22299b279b6326bc0fb82a62ea61b9</link>
      <guid>http://securityratty.com/article/df22299b279b6326bc0fb82a62ea61b9</guid>
      <description><![CDATA[The tactic of abusing web servers whose vulnerable web applications allow a malicious attacker to locally host a malicious campaign is nothing new. In fact, malicious attackers have been building so...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SJiClCFucVI/AAAAAAAAB_0/SSFpGnP3wvA/s1600-h/fake_flash1.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SJiClCFucVI/AAAAAAAAB_0/qKqvrWeAN3s/s200-R/fake_flash1.png" style="border: 0pt none ;" /></a>The tactic of abusing web servers whose vulnerable web applications allow a malicious attacker to locally host a malicious campaign is nothing new. In fact, malicious attackers have been building so much confidence in this risk-forwarding process of hosting their campaigns, that they would start actively spamming the links residing within low-profile legitimate sites across the web.<br />
<br />
This campaign serving fake flash players is getting so prevalent these days due to the multiple spamming approaches used, that it's hard not to notice it - and expose it. From a strategic perspective, having a legitimate low-profile site -- of course with the obvious exceptions being on purposely registered for malicious purposes within the participating sites -- hosting your malicious campaign is pretty creative in terms of forwarding the responsibility, and the eventual blocking of a legitimate site to the its owner. As far as the owner's are concerned, it appears that some of them are already seeing the malware page popping-up on the top of their daily traffic stats, and have taken measures to remove it.<br />
<br />
Moreover, <a href="http://blogs.adobe.com/psirt/2008/08/verifying_installers.html">Adobe's Product Security Incident Response Team (PSIRT) issued a warning notice about the attack yesterday</a>, which could come handy if the <a href="http://www.infoworld.com/article/08/08/05/Adobe_warns_of_bogus_Flash_Player_installers_1.html">attackers weren't taking advantage of client-side vulnerabilities</a>, putting the unware end user is a situation where he <a href="http://blogs.stopbadware.org/articles/2008/08/05/same-dogs-new-tricks">wouldn't even receive a download dialog</a> :<br />
<br />
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SJiP_0v81lI/AAAAAAAACAM/LuFjz3rFLAc/s1600-h/fake_flash3_exploit.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SJiP_0v81lI/AAAAAAAACAM/GXwA3Ai1LLY/s200-R/fake_flash3_exploit.jpg" style="border: 0pt none ;" /></a>"<i>We have seen coverage from the security community of a worm on popular social networking sites that is using social engineering lures to get users to install a piece of malware. According to the reports, the worm posts comments on these sites that include links to a fake site. If the link is followed, users are told they need to update their Flash Player. The installer, posted on a malicious site, of course installs malware instead of Flash Player.We’d like to take this opportunity to reiterate the importance of validating installers and updates before installing them. First off, do not download Flash Player from a site other than adobe.com – you can find the link for downloading Flash Player here. This goes for any piece of software (Reader, Windows Media Player, Quicktime, etc.) – if you get a notice to update, it’s not a bad idea to go directly to the site of the software vendor and download the update directly from the source. If the download is from an unfamiliar URL or an IP address, you should be suspicious.</i>"<br />
<br />
<a href="http://bp2.blogger.com/_wICHhTiQmrA/SJiGkBrMqII/AAAAAAAAB_8/6PfKZxTNQao/s1600-h/fake_flash2.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SJiGkBrMqII/AAAAAAAAB_8/ADBheDs2hkk/s200-R/fake_flash2.png" style="border: 0pt none ;" /></a>The structure of the malware campaign is pretty static, with several exceptions where they also take advange of client-side vulnerabilities (Real player exploit) attempting to automatically deliver the fake flash update or player depending on the campaign. On each and every site, there are <b>dnd.js</b> and <b>master.js</b> scripts shich serve the rogue download window, and another .html file, where an IFRAME attempts to access the traffic management command and control, in a random URL it was <b>207.10.234.217/cgi-bin/index.cgi?user200</b>. A sample list of participating URLs, most of which are still active and running :<br />
<br />
<div style="text-align: left;"><b>joseantoniobaltanas .com</b></div><b>automoviliaria .es/hotnews.html<br />
risasnc .it/fresh.html<br />
carpe-diem .com.mx/fresh.html<br />
kotilogullari .com.tr/hotnews.html<br />
ferrariclubpesaro .it/hotnews.html<br />
imobiliariacom .com.br/default.html<br />
misoares .com<br />
osniehus .de/fresh.html<br />
mydirecttube .com/1/5098/<br />
madosma .com/default.html<br />
tutotic .com/checkit.html<br />
veit-team .si/default.html<br />
antigewaltkurse .de/stream.html<br />
kwhgs .ca/topnews.html<br />
vorgo .com/stream.html<br />
ankaraspor .com.tr/default.html<br />
xxxdnn0314 .locaweb.com.br/watchit.html<br />
ossuzio .com/watchit.html<br />
cit-inc .net/default.html<br />
negocioindependiente .biz/default.html<br />
ambermarketing .com/topnews.html<br />
web27 .login-7.loginserver.ch/stream.html<br />
moretewebdesign .br-web.com/stream.html<br />
omdconsulting .es/topnews.html<br />
parapendiolestreghe .it/hotnews.html<br />
campodifiori .it/topnews.html<br />
212.50.55.81 /stream.html<br />
logisigns .net/fresh.html<br />
intimaescorts .com/default.html<br />
ghioautotre .it/live.html<br />
geckert .de/stream.html<br />
yuricardinali .com/watchit.html<br />
retder .com/fresh.html<br />
valdaran .es/default.html<br />
getadultaccess .com/movie/?aff=5274<br />
bauelemente-giering .de/stream.html<br />
newyork-hebergement .com/watchit.html<br />
allevatoritrotto .it/live.html<br />
exoss2 .com/hotnews.html<br />
soundandlightkaraoke .com/stream.html<br />
land-kan .com/stream.html<br />
grimaldi.nexenservices .com/watchit.html<br />
inconstancia .com.br/watchit.html <br />
gretelstudio .com/stream.html<br />
sumacyl .com/watchit.html<br />
mysna .net/fresh.html<br />
gimnasioyx .com.ar/watchit.html<br />
lagalbana .com/watchit.html<br />
bielizna.tgory .pl/topnews.html<br />
bcs92.imingo .net/stream.html<br />
lapiramidecoslada .es/topnews.html<br />
raulortega .com/stream.html<br />
go-art-morelli .de/hotnews.html<br />
wowhard.baewha .ac.kr/watchit.html<br />
dianagraf .es/default.html<br />
komma10-thueringen .de/hotnews.html<br />
miavassilev .com/stream.html<br />
swampgiants .com/watchit.html<br />
compagniedephalsbourg .com/fresh.html<br />
arla-rc .net/hotnews.html<br />
salacopernico .es/watchit.html<br />
drfinster .de/checkit.html<br />
healthylifehypnotherapy .com/stream.html<br />
ecotrike-bg .com/fresh.html<br />
paoepalavra .org/watchit.html<br />
jureplaninc-sp .com/topnews.html<br />
fichte-lintfort .de/default.html<br />
hergert-band .de/checkit.html<br />
izliyorum .org/topnews.html<br />
lideka .com/stream.html<br />
athena-digitaldesign .com.tw/hotnews.html<br />
e-paso .pl/stream.html<br />
colombeblanche .org/stream.html<br />
teatromalasa .es/watchit.html<br />
mesporte.digiweb.com .br/stream.html<br />
bistrodavila.com .br/watchit.html<br />
hausfeld-solar .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
csr.imb .br/stream.html<br />
herion-architekten .de/default.html<br />
jbhumet .com/default.html<br />
gruppouni .com/hotnews.html<br />
francex .net/fresh.html<br />
galvatoledo .com/topnews.html<br />
cmeedilizia .eu/topnews.html<br />
kroenert .name/default.html<br />
textilhogarnovadecor .com/topnews.html<br />
keithcrook .com/stream.html<br />
elpatiodejesusmaria .com/checkit.html<br />
neticon .pl/hotnews.html<br />
malerbetrieb-pelzer .de/hotnews.html<br />
easterstreet .de/fresh.html<br />
piogiovannini .com.ar/watchit.html<br />
ser-all .com/topnews.html<br />
petzold-dieter .de/checkit.html<br />
beatmung-brandenburg .de/checkit.html<br />
ossuzio .com/watchit.html<br />
teatromalasa .es/watchit.html<br />
vuelosultimahora .com/topnews.html<br />
zelenaratolest .cz/pornotube/index1.htm<br />
ambulatoriovirtuale .it/topnews.html<br />
10a3 .ru/index1.php<br />
izliyorum .org/topnews.html<br />
collectedthoughts .co.uk/index12.html<br />
afg .es/topnews.html<br />
albertruiz .net/topnews.html<br />
bielizna.tgory .pl/topnews.html<br />
blueseven.com .br/topnews.html<br />
bollettinogiuridicosanitario .it/topnews.html<br />
caprilchamonix.com .br/topnews.html<br />
carlolongarini .it/topnews.html<br />
champimousse .com/topnews.html<br />
cheviot.org .nz/topnews.html<br />
contrapie .com/topnews.html<br />
gruppouni .com/topnews.html<br />
hausfeld-solar .de/topnews.html<br />
herbatele .com/topnews.html<br />
houseincostaricaforsale .com/topnews.html<br />
alim.co .il/topnews.html<br />
allevatoritrotto .it/topnews.html<br />
amafe .org/topnews.html<br />
ambulatoriovirtuale .it/topnews.html<br />
atelier-de-loulou .fr/topnews.html<br />
automoviliaria .es/topnews.html<br />
autoreserve .fr/topnews.html<br />
izliyorum .org/topnews.html<br />
jureplaninc-sp .com/topnews.html<br />
kwhgs .ca/topnews.html<br />
lapiramidecoslada .es/topnews.html<br />
last-minute-reisen-4u .de/topnews.html<br />
marcadina .fr/topnews.html<br />
maremax .it/topnews.html<br />
corradiproject .info/topnews.html<br />
dantealighieriasturias .es/topnews.html<br />
deliriuslaspalmas .com/topnews.html<br />
ecchoppers .co.za/topnews.html<br />
elianacaminada .net/topnews.html<br />
fonavistas .com/topnews.html<br />
fraemma .com/topnews.html<br />
fundmyira .com/topnews.html<br />
galvatoledo .com/topnews.html<br />
grafisch-ontwerpburo .nl/topnews.html<br />
markmaverick .com/topnews.html<br />
micela .info/topnews.html<br />
motoclubnosvamos .com/topnews.html<br />
nebottorrella .com/topnews.html<br />
negozistore .it/topnews.html<br />
neticon .pl/topnews.html<br />
norbert-leifheit.gmxhome .de/topnews.html<br />
segelclub-honau .de/topnews.html<br />
snmobilya .com/topnews.html<br />
splashcor .com.br/topnews.html<br />
stephanmager .gmxhome.de/topnews.html<br />
svcanvas .com/topnews.html<br />
tautau.web .simplesnet.pt/topnews.html<br />
textilhogarnovadecor .com/topnews.html<br />
theflorist4u .com/topnews.html<br />
thewindsorhotel .it/topnews.html<br />
vuelosultimahora .com/topnews.html<br />
aliarzani .de/topnews.html<br />
ambermarketing .com/topnews.html<br />
arnold82.gmxhome .de/topnews.html<br />
ocoartefatos.com .br/topnews.html<br />
omdconsulting .es/topnews.html<br />
parapendiolestreghe .it/topnews.html<br />
positive-begegnungen .de/topnews.html<br />
projetsoft .net/topnews.html<br />
rbc.gmxhome .de/topnews.html<br />
beatmung-sachsen .eu/topnews.html<br />
campodifiori .it/topnews.html<br />
clickjava .net/topnews.html<br />
cmeedilizia .eu/topnews.html<br />
dammer .info/topnews.html<br />
embedded-silicon .de/topnews.html<br />
ferrariclubpesaro .it/topnews.html<br />
fgwiese .de/topnews.html<br />
fswash.site .br.com/topnews.html<br />
fytema .es/topnews.html<br />
gildas-saliou. com/topnews.html<br />
go-art-morelli .de/topnews.html<br />
go-siegmund .de/topnews.html<br />
guerrero-tuning .com/topnews.html<br />
gut-barbarastein .de/topnews.html<br />
japansec .com/topnews.html<br />
komma10-thueringen .de/topnews.html<br />
koon-design .de/topnews.html<br />
lanz-volldiesel .de/topnews.html<br />
lauscher-staat .de/topnews.html<br />
losnaranjos.com .es/topnews.html<br />
medical-service-krause .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
nepi.si/topnews .html<br />
radieschenhein. de/topnews.html<br />
residenceflora .it/topnews.html<br />
sabuha .de/topnews.html<br />
ser-all .com/topnews.html<br />
siemieniewicz .de/topnews.html<br />
viajesk .es/topnews.html<br />
allevatoritrotto .it/live.html<br />
bollettinogiuridicosanitario .it/live.html<br />
carlolongarini .it/topnews.html<br />
maremax .it/topnews.html<br />
negozistore .it/topnews.html<br />
parapendiolestreghe .it/live.html<br />
www.donlisander .it/stream.html<br />
aerogenesis .net/watchit.html<br />
allevatoritrotto .it/live.html<br />
atelier-de-loulou .fr/topnews.html<br />
bistrodavila.com .br/watchit.html<br />
bollettinogiuridicosanitario .it/live.html<br />
caprilchamonix.com .br/topnews.html<br />
cheviot.org .nz/live.html<br />
condorautocenter .com.br/watchit.html<br />
dantealighieriasturias .es/live.html<br />
ecchoppers .co.za/topnews.html<br />
elianacaminada .net/live.html<br />
fonavistas .com/topnews.html<br />
fundmyira .com/topnews.html<br />
g6esporte .com.br/stream.html<br />
grafisch-ontwerpburo .nl/topnews.html<br />
gretelstudio .com/stream.html<br />
gutierrezymoralo .com/watchit.html<br />
healthylifehypnotherapy .com/stream.html<br />
herbatele .com/live.html<br />
jureplaninc-sp .com/topnews.html<br />
lacomercialsrl .com.ar/stream.html<br />
lagalbana .com/watchit.html<br />
lapuertaestrecha .com.es/watchit.html<br />
marcadina .fr/topnews.html<br />
maremax .it/topnews.html<br />
myadultcube .com/flash//aff=5176<br />
myadultcube .com/flash//aff=5810<br />
myadultcube .com/movie//aff=5155<br />
newyork-hebergement .com/watchit.html<br />
norbert-leifheit.gmxhome .de/topnews.html<br />
omdconsulting .es/topnews.html<br />
oyakatakent46537 .com/stream.html<br />
parapendiolestreghe .it/live.html<br />
regesh. co.il/watchit.html<br />
rikkeroenneberg .dk/watchit.html<br />
s215847279 .onlinehome.fr/stream.html<br />
salacopernico .es/watchit.html<br />
seekzones .com/watchit.html<br />
seicomsl .es/watchit.html<br />
sigma-lux .ro/watchit.html<br />
soundandlightkaraoke .com/stream.html<br />
stephanmager.gmxhome .de/topnews.html<br />
tartuinstituut .ca/watchit.html<br />
teatromalasa .es/watchit.html<br />
vuelosultimahora .com/topnews.html<br />
wowhard.baewha .ac.kr/watchit.html<br />
aliarzani .de/topnews.html<br />
ambermarketing. com/live.html<br />
bilbondo .com/watchit.html<br />
bollettinogiuridicosanitario .it/live.html<br />
colombeblanche .org/stream.html<br />
donlisander .it/stream.html<br />
fgwiese .de/topnews.html<br />
geckert .de/stream.html<br />
helene-taucher .de/watchit.html<br />
lanz-volldiesel .de/topnews.html<br />
mairie-margnylescompiegne .fr/watchit.html<br />
medical-service-krause .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
ossuzio .com/watchit.html<br />
piogiovannini .com.ar/watchit.html<br />
sabuha .de/topnews.html<br />
sumacyl .com/watchit.html<br />
swampgiants .com/watchit.html<br />
xn--glland-3ya .de/stream.html<br />
yuricardinali .com/watchit.html</b><br />
<b>nepi .si/topnews.html<br />
dammer .info/topnews.html<br />
atelier-de-loulou .fr/topnews.html<br />
galvatoledo .com/topnews.html<br />
allevatoritrotto .it/topnews.html<br />
hausfeld-solar .de/topnews.html<br />
micela .info/topnews.html<br />
bistrodavila .com.br/watchit.html<br />
hausfeld-solar .de/topnews.html<br />
csr.imb .br/stream.html<br />
herion-architekten .de/default.html<br />
gruppouni .com/hotnews.html<br />
galvatoledo .com/topnews.html<br />
kroenert .name/default.html<br />
keithcrook .com/stream.html<br />
elpatiodejesusmaria .com/checkit.html<br />
malerbetrieb-pelzer .de/hotnews.html<br />
dantealighieriasturias .es/topnews.html<br />
oyakatakent46537 .com/stream.html<br />
89.19.29 .13/stream.html<br />
slobodandjakovic .com/fresh.html<br />
cqcs.com .br/stream.html<br />
seekzones .com/watchit.html<br />
pascosa .it/stream.html<br />
caprilchamonix .com.br/topnews.html<br />
positive-begegnungen .de/topnews.html<br />
ferien-urlaub-lastminute .de/default.html<br />
mueggelpark .info/watchit.html<br />
hillner-online .de/fresh.html<br />
guiasaojose .net/default.html<br />
deliriuslaspalmas .com/topnews.html<br />
fraemma .com/topnews.html<br />
morsbaby .net/default.html<br />
vickywhite .com/fresh.html<br />
micela .info/topnews.html<br />
corradiproject .info/topnews.html<br />
liguehavraise .com/live.html<br />
capacitacaoemlideranca .com.br/fresh.html<br />
materialesyacabados .com.mx/stream.html<br />
208.112.7.68 /checkit.html<br />
152.10.1.37 /1.html<br />
carlolongarini .it/topnews.html<br />
splashcor.com .br/topnews.html<br />
lobpreisstrasse .org/1.html<br />
motoclubnosvamos .com/hotnews.html<br />
hk-rc.com /1.html<br />
taaf.re /stream.html<br />
dulceysalao .com/default.html<br />
amafe .org/topnews.html <br />
</b><br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SJiNeb1AJDI/AAAAAAAACAE/MTxnF1XLDCw/s1600-h/fake_flash3_rogue_software.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SJiNeb1AJDI/AAAAAAAACAE/3Dgh4x23dRs/s200-R/fake_flash3_rogue_software.png" style="border: 0pt none ;" /></a>Sample detection rate : <span id="status_nombre">flashupdate.exe</span><br />
<span id="status_nombre"><b>Scanners Result</b>: 35/36 (97.23%)</span><br />
<span id="status_nombre">Trojan-Downloader.Win32.Exchanger.hk; Troj/Cbeplay-A</span><br />
<b>File size</b>: 78848 bytes<br />
<b>MD5</b>...: c81b29a3662b6083e3590939b6793bb8<br />
<b>SHA1</b>..: d513275c276840cb528ce11dd228eae46a74b4b4<br />
<br />
The downloader then "phones back home" at <b>72.9.98.234 port 443 </b>which is responding to the rogue security software AntiSpy Spider (<b>antispyspider.net</b>) :<br />
<br />
"<i>AntiSpy Spider is a cutting-edge anti-spyware solution.This revolutionary anti-spyware program was created by the industry's top spyware experts in order to protect your computer and your privacy.html, while ensuring optimal system performance.With the ability to locate, eliminate and prevent the widest range of spyware threats, AntispyStorm is able to offer its users a safe, spyware-free computing experience; and with it's convenient automatic update feature, AntispyStorm ensures continuous up-to-date protection.</i>" <br />
<br />
Sample detection rate : antispyspider.msi<br />
<b>Scanners Result</b>: 11/35 (31.43%)<br />
FraudTool.Win32.AntiSpySpider.b;&nbsp; <br />
<b>File size</b>: 1851904 bytes<br />
<b>MD5</b>...: 2f1389e445f65e8a9c1a648b42a23827<br />
<b>SHA1</b>..: e32aa6aa791e98fe6fdef451bd3b8a45bad0acd8<br />
<br />
The bottom line - over a thousand domains are participating, with many other apparently joining the party proportionally with the web site owner's actions to get rid of the malware campaign hosted on their servers.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">Underground Multitasking in Action</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">Blackhat SEO Redirects to Malware and Rogue Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/malicious-doorways-redirecting-to.html">Malicious Doorways Redirecting to Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">A Portfolio of Fake Video Codecs</a><b> <br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BvcTqK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BvcTqK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=onawHK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=onawHK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4fa1ek"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4fa1ek" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5nQAgk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5nQAgk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sqdHIK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sqdHIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mq3LKK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mq3LKK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8zplkk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8zplkk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/356677080" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 10:50:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/file">file</category>
      <category domain="http://securityratty.com/tag/html file">html file</category>
      <category domain="http://securityratty.com/tag/html">html</category>
      <category domain="http://securityratty.com/tag/comtopnews">comtopnews</category>
      <category domain="http://securityratty.com/tag/detopnews">detopnews</category>
      <category domain="http://securityratty.com/tag/windows media player">windows media player</category>
      <category domain="http://securityratty.com/tag/player">player</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/real player exploit">real player exploit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/356677080/compromised-web-servers-serving-fake.html">Compromised Web Servers Serving Fake Flash Players</source>
    </item>
    <item>
      <title><![CDATA[McAfee's Site Advisor Blocking n.runs AG - "for starters"]]></title>
      <link>http://securityratty.com/article/980eb4d1bd34b658bcb6d139b3d762f1</link>
      <guid>http://securityratty.com/article/980eb4d1bd34b658bcb6d139b3d762f1</guid>
      <description><![CDATA[Following the recent, and now fixed false positive blocking sans.org due to the already considered malicious dshield.org and giac.org it's also interesting to note that n.runs AG ( nruns.com ), whose...]]></description>
      <content:encoded><![CDATA[<div class="" style="text-align: left; clear: both;"><a href="http://bp2.blogger.com/_wICHhTiQmrA/SJHp1ZiyMHI/AAAAAAAAB-8/ALBebqDtrl0/s1600-h/nruns_siteadvisor_false.bmp" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SJHp1ZiyMHI/AAAAAAAAB-8/1_qCXyFB8b8/s200-R/nruns_siteadvisor_false.bmp" style="border: 0pt none ;" /></a>Following the recent, and now fixed <a href="http://isc.sans.org/diary.html?storyid=4799">false positive blocking sans.org</a> due to the already considered malicious <b>dshield.org</b> and <b>giac.org</b> it's also interesting to note that n.runs AG (<b>nruns.com</b>), whose <a href="http://ddanchev.blogspot.com/2008/07/vulnerabilities-in-antivirus-software.html">research into vulnerabilities in antivirus products</a> received a lot of attention lately, is also flagged as <a href="http://www.siteadvisor.com/sites/nruns.com/downloads/15713425/">a dangerous site</a>.</div><div class="" style="text-align: left; clear: both;"></div><div class="" style="text-align: left; clear: both;"><br />
Excluding the conspiracy theories, a false positive when your solution is integrated in the second most popular search engine is bad, especially when other <a href="http://www.google.com/safebrowsing/diagnostic?site=nruns.com">automated crawling approaches</a> are successfully detecting the site as a non-malicious one. How come? It's all a matter of how you define malicious activity, and what exactly are you trying to protect your users from.<br />
<br />
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SJMiqmiaOxI/AAAAAAAAB_M/T74a9Ztjt8U/s1600-h/invisiblethings_siteadvisor.bmp" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SJMiqmiaOxI/AAAAAAAAB_M/JtWk3WVLlug/s200-R/invisiblethings_siteadvisor.bmp" style="border: 0pt none ;" /></a>In this case, Site Advisor seems to be trying to protect the end user from herself, but flagging sites hosting some sort of hacking/pen-testing tool in a clear directory structure, since SiteAdvisor isn't capable of automatically flagging a SQL injected site as a malicious one, the approach it takes for assessing whether or not a specific site is malicious is flawed, namely integrating McAfee's signatures based malware database and flagging a site hosting anything detected as malware as a badware site itself. <a href="http://www.theregister.co.uk/2008/08/01/siteadvisor_sans_snafu/page2.html">McAfee's comments</a>:</div><div class="" style="text-align: left; clear: both;"><br />
"<i>Our tests are very accurate," Dowling said. "The frequency of false positives is fewer than one a month. Changes in classifications we make are almost always because sites have changed their behaviour. "The email tests are the ones than have the most false positives. Users can have confidence in our ratings.</i>"<br />
<br />
</div><div class="" style="text-align: left; clear: both;"></div><div class="" style="text-align: left; clear: both;"></div><div class="" style="text-align: left; clear: both;"></div><div class="" style="text-align: left; clear: both;"><a href="http://bp1.blogger.com/_wICHhTiQmrA/SJMjH58t8FI/AAAAAAAAB_U/jFxueEROzkM/s1600-h/hackinthebox_siteadvisor.bmp" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SJMjH58t8FI/AAAAAAAAB_U/Wj65aLQMO3M/s200-R/hackinthebox_siteadvisor.bmp" style="border: 0pt none ;" /></a>There are even more surprising false positives, such as, <b>Hack in the Box security conference, Defcon.org, Zone-H France, Invisiblethings.org, AME Info - Middle East business and financial news</b> and more :</div><div class="" style="text-align: left; clear: both;"><a href="http://www.siteadvisor.com/sites/milw0rm.com"><b>milw0rm.com</b></a></div><div class="" style="text-align: left; clear: both;"><a href="http://www.siteadvisor.com/sites/hackinthebox.org/summary/"><b>hackinthebox.org</b></a></div><div class="" style="text-align: left; clear: both;"><b><a href="http://www.siteadvisor.com/sites/defcon.org">defcon.org</a> <br />
<a href="http://www.siteadvisor.com/sites/hitb.org"><b>hitb.org</b></a></b></div><div class="" style="text-align: left; clear: both;"><b><a href="http://www.siteadvisor.com/sites/invisiblethings.org/summary/"><b>invisiblethings.org</b></a></b></div><div class="" style="text-align: left; clear: both;"><b><a href="http://www.siteadvisor.com/sites/zone-h.fr/summary/"><b>zone-h.fr</b></a></b></div><div class="" style="text-align: left; clear: both;"><b><a href="http://www.siteadvisor.com/sites/ussrback.com/summary/"><b>ussrback.com</b></a></b></div><div class="" style="text-align: left; clear: both;"><b><b><a href="http://www.siteadvisor.com/sites/ameinfo.com">ameinfo.com</a></b><br />
<br />
</b>Take for instance the Hack in the Box security conference, which is considered as the <a href="http://www.siteadvisor.com/sites/hitb.org/downloads/11950271/">download publisher of a file hosted at packetstormsecurity.org</a>. What's interesting to point out is that just like a huge percentage of already flagged as potentially harmful sites that haven't been re-checked in months, with Hack in the Box's case the link was last checked in February, 2008. And since <b>hitb.org</b> is now distributing spyware, any site that it links to is also flagged as badware, like <b>hackinthebox.org</b> itself :<br />
<br />
"<i>When we tested this site we found links to hitb.org, which we found to be a distributor of downloads some people consider adware, spyware or other potentially unwanted programs.</i>'<br />
<br />
These sites aren't SQL injected, IFRAME-ed or embedded with malware whatsoever, so it's like flagging a gun store as a malicious store because of the inventory there - wrong generalization aiming to bring order into the underground chaos at the first place is prone to result in lots of false positives, <a href="http://ddanchev.blogspot.com/2007/07/insecure-bureaucracy-in-germany.html">a wrong mentality that certain countries are starting to embrace</a>.</div><br />
The bottom line - is the "<i>do not visit unknown or potentially harmful sites</i>" security tip on the verge of extinction? Probably, as these days, exploited legitimate sites are hosting or redirecting to more malware than potentially harmful sites are.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6BU3YK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6BU3YK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WYGGVK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WYGGVK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=osuqWk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=osuqWk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ysc5ak"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ysc5ak" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=S0nWuK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=S0nWuK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=x7tmHK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=x7tmHK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZdrCPk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZdrCPk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/355386532" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 04 Aug 2008 05:42:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/site advisor">site advisor</category>
      <category domain="http://securityratty.com/tag/org due">org due</category>
      <category domain="http://securityratty.com/tag/org">org</category>
      <category domain="http://securityratty.com/tag/dangerous site">dangerous site</category>
      <category domain="http://securityratty.com/tag/specific site">specific site</category>
      <category domain="http://securityratty.com/tag/malicious">malicious</category>
      <category domain="http://securityratty.com/tag/harmful sites">harmful sites</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/355386532/mcafees-site-advisor-blocking-nruns-ag.html">McAfee's Site Advisor Blocking n.runs AG - "for starters"</source>
    </item>
    <item>
      <title><![CDATA[Monetizing Compromised Web Sites]]></title>
      <link>http://securityratty.com/article/9f7b106457f7cdcbfb11dd8b0b3dd971</link>
      <guid>http://securityratty.com/article/9f7b106457f7cdcbfb11dd8b0b3dd971</guid>
      <description><![CDATA[Despite that pure patriotic hacktivism is still alive and kicking, compromised sites are largely getting monetized these days, starting from hosting blackhat SEO junk pages, to redirecting to live...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SHsAOtYiisI/AAAAAAAAB58/CA2dvGI0DL0/s1600-h/Municipal_de_Amparo.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SHsAOtYiisI/AAAAAAAAB58/k2bP_iz48tA/s200-R/Municipal_de_Amparo.png" style="border: 0pt none ;" /></a>Despite that pure patriotic hacktivism is still alive and kicking, <a href="http://ddanchev.blogspot.com/2008/06/monetizing-web-site-defacements.html">compromised sites are largely getting monetized</a> these days, starting from hosting blackhat SEO junk pages, to redirecting to live exploit URLs and fake codecs where revenue is earned through their participation in an affiliate business model.<br />
<br />
With The Africa Middle Market Fund's site monetized by web site defacers who defaced it "in between" the blackhat SEO infrastructure they were hosting internally, in this I'll comment on the currently compromised and redirection to a fake porn sites, Camara Municipal de Amparo (<b>camaraamparo.sp.gov.br/r.html</b>). Basically, it's homepage is heavily linking to the Zlob variant (<b>camaraamparo.sp.gov.br/ video.exe</b>) in between loading an IFRAME to <b>61.162.230.12/ index.php</b>. As always, upon uploading their redirector, they've build enough confidence into their new hosting provider that the link to the redirector was instantly spammed across the web. The site is so heavily linking to the internal redirector itself, that upon clicking on the majority of links the user will inevitably come across it.<br />
<br />
Speaking of fake porn sites redirecting to Zlob variants, here are the very latest additions spammed across the web through blackhat SEO practices :<br />
<br />
<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp0.blogger.com/_wICHhTiQmrA/SHsLbgFp7NI/AAAAAAAAB6E/ZDNLECdRM1U/s1600-h/fake_porn_sites_zlob.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SHsLbgFp7NI/AAAAAAAAB6E/TIqQ0wE9bQM/s200-R/fake_porn_sites_zlob.JPG" style="border: 0pt none ;" /></a><b>just-tube .com<br />
mypornmovies .net<br />
moms-galls .net<br />
porntubefilms .com<br />
porntubedot .com<br />
hot-porntube .com<br />
landmovieblog .com<br />
sexvidtube .com<br />
freelifevideo .com<br />
getyourfreemovie .com<br />
iubat .com<br />
sweetyjoly .com<br />
hardbizarre .com<br />
freeworldvideo .net<br />
hot-porntube .net<br />
qualitymovies .net<br />
porntube1con .net<br />
video-info .net<br />
videocityblog .com<br />
fuckedolder&nbsp; .com<br />
highpro1 .com<br />
max-graf.com .pl<br />
grandsupertds .info<br />
hot-porn-tube .net<br />
hot-porntube .com<br />
terryschulz .com<br />
show-sextube .com<br />
qualitymovies .net<br />
clubvideos .net</b><br />
<br />
No matter the high profile site that's been exploited in order to participate in such malicious operations, for the time being, crunching out new domain names and using the hosting services of the well known ISPs neglecting their removal, seems to be the tactic of choice. The long tail of SQL injected sites is however, clearly replacing the plain simple blackhat SEO web spamming, so that traffic to these rogue sites is driven through redirection of the the traffic from legitimate sites.<b><br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=cEyKTJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=cEyKTJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=qsdYjJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=qsdYjJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BVongj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BVongj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4DJmRj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4DJmRj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=al8bCJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=al8bCJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nrE7PJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nrE7PJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TCjewj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TCjewj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/334911319" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 13 Jul 2008 23:26:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/rogue sites">rogue sites</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/web site defacers">web site defacers</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/fake porn sites">fake porn sites</category>
      <category domain="http://securityratty.com/tag/profile site">profile site</category>
      <category domain="http://securityratty.com/tag/redirector">redirector</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/334911319/monetizing-compromised-web-sites.html">Monetizing Compromised Web Sites</source>
    </item>
    <item>
      <title><![CDATA[Monetizing Web Site Defacements]]></title>
      <link>http://securityratty.com/article/9c0b522d99880bbb79d7258c5f16975f</link>
      <guid>http://securityratty.com/article/9c0b522d99880bbb79d7258c5f16975f</guid>
      <description><![CDATA[What used to be a harmless web site defacements back in the old school days, is today's ongoing monetization of defaced web sites, a logical development given the consolidation between different...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SFKBgjBBwkI/AAAAAAAAByo/TVBWvnlCxq8/s1600-h/africa_fund_defaced.png"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SFKBgjBBwkI/AAAAAAAAByo/TVBWvnlCxq8/s200/africa_fund_defaced.png" alt="" id="BLOGGER_PHOTO_ID_5211370114976432706" border="0" /></a>What used to be a harmless web site defacements back in the old school days, is today's ongoing monetization of defaced web sites, a logical development given the consolidation between different underground parties, evidence of which can be seen in the majority of incidents I've been analyzing recently.<br /><br /><a href="http://africammfund.com">The Africa Middle Market Fund</a>' site is the latest example of a web site defacer is abusing the access to the web server to generate and locally host blackhat SEO pages, which when once access only by searching for the keywords and consequently returning 404 if traffic isn't coming from a search engine, redirect to known rogue security software, in this case, the <a href="http://ddanchev.blogspot.com/2008/05/got-your-xpshield-up-and-running.html">XP antivirus protection</a> (<span style="font-weight: bold;">securityscannersite.com</span>) which you must be familiar with if you were following the <a href="http://ddanchev.blogspot.com/2008/03/massive-iframe-seo-poisoning-attack.html">assessments</a> of the <a href="http://ddanchev.blogspot.com/2008/03/rogue-rbn-software-pushed-through.html">massive IFRAME</a> SEO <a href="http://ddanchev.blogspot.com/2008/03/more-cnet-sites-under-iframe-attack.html">poisoning attacks</a> that took place during March this year. More about the found :<br /><br />"<span style="font-style: italic;">The Africa Middle Market Fund is a private capital fund that invests in small and medium sized African businesses who need from $500,000 up to $2 million to grow and succeed to their full potential. We are a "double bottom-line" or "impact investment" fund, meaning that we care equally about financial performance and social benefit. We are for-profit and insist on our investees employing world standards of financial and business management to maximize their chances of success</span>"<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/SFKLPBOgSkI/AAAAAAAAByw/N8jiOnSohiw/s1600-h/africa_fund_blackhat_seo.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_wICHhTiQmrA/SFKLPBOgSkI/AAAAAAAAByw/N8jiOnSohiw/s200/africa_fund_blackhat_seo.JPG" alt="" id="BLOGGER_PHOTO_ID_5211380808964655682" border="0" /></a>Most of the outgoing links from a sample of over 50 blackhat SEO pages at the site point to <span style="font-weight: bold;">23search.org</span>, which is an invitation-only affiliate based network for traffic exchange, connecting different malicious parties together :<br /><br />"<span style="font-style: italic;">What is this site? This site helps webmasters to earn money with their sites. How it works? Our program generate traffic from search engines and display advertising. What shell I do to start with you? Signup, get php file from member area, put file into your website directory, modify or create .htaccess in the same directory, and receive money!</span>"<br /><br />The session is then redirected to <span style="font-weight: bold;">drivemedirect.com/soft.php?aid=0195&amp;d=3&amp;product=XPA,</span> as well as to<span style="font-weight: bold;"> drivemedirect.com/soft.php?aid=0263&amp;d=2&amp;product=XPC </span>to ultimately redirect the user to<span style="font-weight: bold;"> online-xpcleaner.com/2/freescan.php?aid=880263<br /><br /></span>Moreover, the majority of blackhat SEO campaigns are also starting to apply evasive techniques to make it harder to analyze them. In this particular campaign for instance, only traffic comming from search engines would get the chance to see the SEO page due to the use of document.referrer tags. Here are some sample monitization practices from what I've seen between the lines of recently defaced sites :<br /><br />- installing web backdoors and reselling the access to phishers, spammers and malware authors who would have full control over the content, and can therefore do whatever they to with the web server<br /><br />- installing web based spamming tools that later on will be either used directly by the defacers, or access to the tools sold to those interested in using them<br /><br />- participating in an affiliate based blackhat SEO networks, where revenue coming of the victims w<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SFKcYCaWu9I/AAAAAAAABy4/X2y_2cplAoE/s1600-h/africa_fund_blackhat_visualized.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SFKcYCaWu9I/AAAAAAAABy4/X2y_2cplAoE/s200/africa_fund_blackhat_visualized.JPG" alt="" id="BLOGGER_PHOTO_ID_5211399655599291346" border="0" /></a>ho installed the rogue software is shared among the defacer and the affiliate based network, which doesn't really care how and where is all the traffic coming from<br /><br />- forwarding the responsibility of hosting phishing pages to the legitimate site by hosting them locally in between sending the phishing emails again using the same host<br /><br />- selling the access by promoting it based on its page rank<br /><br />Web site defacements in times when <a href="http://blogs.zdnet.com/security/?p=1200">traffic suppliers are efficiently coordinating campaigns with traffic seekers</a>, will mature into a tool for providing malicious infrastructure on demand, just like botnets did. Then again, the endless possibilities provided by insecure web applications are already blurring the lines between web site defacements and SQL injections.<br /><br /><span style="font-weight: bold;">Related posts:</span><br /><a href="http://ddanchev.blogspot.com/2008/05/pro-serbian-hacktivists-attacking.html">Pro-Serbian Hacktivists Attacking Albanian Web Sites</a><br /><a href="http://ddanchev.blogspot.com/2008/04/rise-of-kosovo-defacement-groups.html">The Rise of Kosovo Defacement Groups</a><br /><a href="http://ddanchev.blogspot.com/2008/04/commercial-web-site-defacement-tool.html">A Commercial Web Site Defacement Tool</a><br /><a href="http://ddanchev.blogspot.com/2008/04/phishing-tactics-evolving.html">Phishing Tactics Evolving</a><br /><a href="http://ddanchev.blogspot.com/2008/04/web-site-defacement-groups-going.html">Web Site Defacement Groups Going Phishing</a><br /><div><a href="http://ddanchev.blogspot.com/2006/02/hacktivism-tensions.html">Hacktivism Tensions</a></div> <div><a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Hacktivism Tensions - Israel vs Palestine Cyberwars</a></div> <div><a href="http://ddanchev.blogspot.com/2007/11/mass-defacement-by-turkish-hacktivists.html">Mass Defacement by Turkish Hacktivists</a></div> <a href="http://ddanchev.blogspot.com/2007/11/overperforming-turkish-hacktivists.html">Overperforming Turkish Hacktivists</a><br /><a href="http://ddanchev.blogspot.com/2008/05/blackhat-seo-campaign-at-millennium.html">Blackhat SEO Campaign at The Millennium Challenge Corporation</a><br /><a href="http://ddanchev.blogspot.com/2008/03/massive-iframe-seo-poisoning-attack.html">Massive IFRAME SEO Poisoning Attack Continuing</a><br /><a href="http://ddanchev.blogspot.com/2008/02/massive-blackhat-seo-targeting-blogspot.html">Massive  Blackhat SEO Targeting Blogspot</a><br /><a href="http://ddanchev.blogspot.com/2008/01/invisible-blackhat-seo-campaign.html">The  Invisible Blackhat SEO Campaign</a><br /><a href="http://ddanchev.blogspot.com/2007/01/attack-of-seo-bots-on-edu-domain.html">Attack  of the SEO Bots on the .EDU Domain</a><br /><a href="http://ddanchev.blogspot.com/2007/11/p0rngov-ongoing-blackhat-seo-operation.html">p0rn.gov  - The Ongoing Blackhat SEO Operation</a><br /><a href="http://ddanchev.blogspot.com/2008/02/continuing-gov-blackat-seo-campaign.html">The Continuing .Gov Blackat SEO Campaign</a><br /><a href="http://ddanchev.blogspot.com/2008/02/continuing-gov-blackat-seo-campaign_25.html">The Continuing .Gov Blackhat SEO Campaign - Part Two</a><br /><a href="http://ddanchev.blogspot.com/2007/10/compromised-sites-serving-malware-and.html">Compromised Sites Serving Malware and Spam</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NKDexI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NKDexI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hZINeI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hZINeI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3PrFbi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3PrFbi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nDo4mi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nDo4mi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jT9iqI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jT9iqI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YLiNQI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YLiNQI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sAhmSi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sAhmSi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/311270173" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 13 Jun 2008 07:54:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/web site defacements">web site defacements</category>
      <category domain="http://securityratty.com/tag/site helps webmasters">site helps webmasters</category>
      <category domain="http://securityratty.com/tag/web site defacement">web site defacement</category>
      <category domain="http://securityratty.com/tag/web sites">web sites</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/traffic exchange">traffic exchange</category>
      <category domain="http://securityratty.com/tag/traffic">traffic</category>
      <category domain="http://securityratty.com/tag/traffic suppliers">traffic suppliers</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/311270173/monetizing-web-site-defacements.html">Monetizing Web Site Defacements</source>
    </item>
    <item>
      <title><![CDATA[Stealing Password Hashes with Java and IE]]></title>
      <link>http://securityratty.com/article/8194d6ab09a249e970bed5125521056a</link>
      <guid>http://securityratty.com/article/8194d6ab09a249e970bed5125521056a</guid>
      <description><![CDATA[OK, I read a lot, I mean a lot on a regular basis. There is a lot of tripe floating about the tubes of the internet and Im always pleased to read a new posting from several folks who buck that trend....]]></description>
      <content:encoded><![CDATA[<p>OK, I read a lot, I mean <b>a lot</b> on a regular basis. There is a lot of tripe floating about the tubes of the internet and I&#8217;m always pleased to read a new posting from several folks who buck that trend. Among which I count John Heasman. He has a great new post on his site about stealing password hashes with Java and Internet Exploder.</p>
<p>From Aut Disce, Aut Discede:</p>
<blockquote><p>Consider for a moment the state of client-side bugs 5 or 6 years ago. Attacks such as this, a multi-stage miscellany of IE and Mediaplayer bugs that resulted in the &#8220;silent delivery and installation of an executable on the target computer, no client input other than viewing a web page&#8221; were reported with regularity. Gradually these type of attack gave way to exploitation of direct browser implementation flaws such as the IFRAME overflow and DHTML memory corruption flaws. So what has become of the multi-stage attacks - have they become redundant? The answer to this, which I&#8217;m sure you can guess, is a resounding &#8220;no&#8221; and will be emphatically demonstrated in my upcoming Black Hat talk &#8220;The Internet is Broken: Beyond Document.Cookie - Extreme Client Side Exploitation&#8221;, a joint double session presentation co-presented by Billy Rios, Nate McFeters and Rob Carter.</p>
<p>As a teaser for that, I&#8217;m going to revisit an old attack - pre-computed dictionary attacks on NTLM - and discuss how we can steal domain credentials from the Internet with a bit of help from Java. I&#8217;m going to split it into two posts. In this post we&#8217;ll apply the attack to Windows XP (a fully patched SP3 with IE7). In my next post we&#8217;ll consider its impact on Windows Vista.</p></blockquote>
<p>For the full article read on.</p>
<p>Why are you still here? Go read it. </p>
<p> <img src='http://www.liquidmatrix.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><a href="http://heasman.blogspot.com/2008/06/stealing-password-hashes-with-java-and.html">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=kFHS3D"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=kFHS3D" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=jii6HI"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=jii6HI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=fcDSai"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=fcDSai" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=h9BNei"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=h9BNei" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=zcteYi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=zcteYi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=1UYjFi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=1UYjFi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/307957636" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 09 Jun 2008 07:34:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/internet exploder">internet exploder</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/dictionary attacks">dictionary attacks</category>
      <category domain="http://securityratty.com/tag/password hashes">password hashes</category>
      <category domain="http://securityratty.com/tag/java">java</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/article link">article link</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/307957636/">Stealing Password Hashes with Java and IE</source>
    </item>
    <item>
      <title><![CDATA[Flash Player + Windows = Threat of SQL Injection]]></title>
      <link>http://securityratty.com/article/bcc3f89d776010d41693715b0461d5bf</link>
      <guid>http://securityratty.com/article/bcc3f89d776010d41693715b0461d5bf</guid>
      <description><![CDATA[Apparently Adobe Flash players that arent patched and up to date on Windows might be vulnerable to a new SQL injectionthere are apparently 18 variants of the new exploit. SecureWorks has the details...]]></description>
      <content:encoded><![CDATA[<p>Apparently Adobe Flash players that aren&#8217;t patched and up to date on Windows might be vulnerable to a new SQL injection&#8211;there are apparently 18 variants of the new exploit. <a rel="nofollow" target="_blank" href="http://www.secureworks.com/research/threats/adobeflashflaw/?threat=adobeflashflaw"> SecureWorks </a>has the details:</p>
<blockquote><p>
Attackers insert SCRIPT and IFRAME tags into the content of trusted, legitimate web sites via a known SQL injection attack. Those tags redirect the user to the attacker&#8217;s server which hosts the Flash exploit. Tens of thousands of web sites are vulnerable to the SQL injection attack, meaning the distribution potential is high.</p>
<p>The vulnerability is not &#8220;zero-day&#8221;; however, these are the first known public exploits targeting it. The SecureWorks Counter Threat Unit (CTU) has analyzed 18 variants of the exploit, and all attempt to leverage the integer overflow vulnerability originally discovered by Mark Dowd (CVE-2007-0071), which was patched by Adobe with release of version 9.0.124.0 of the Flash Player. While some have reported that the latest version is vulnerable, the CTU was unable to duplicate these results with samples taken from known exploit sites. The only confirmed vulnerable version is (pre-patch) 9.0.115.0.
</p></blockquote>]]></content:encoded>
      <pubDate>Thu, 29 May 2008 11:59:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vulnerable version">vulnerable version</category>
      <category domain="http://securityratty.com/tag/vulnerable">vulnerable</category>
      <category domain="http://securityratty.com/tag/exploit">exploit</category>
      <category domain="http://securityratty.com/tag/flash exploit">flash exploit</category>
      <category domain="http://securityratty.com/tag/sql injection attack">sql injection attack</category>
      <category domain="http://securityratty.com/tag/integer overflow vulnerability">integer overflow vulnerability</category>
      <category domain="http://securityratty.com/tag/exploit sites">exploit sites</category>
      <category domain="http://securityratty.com/tag/flash player">flash player</category>
      <category domain="http://securityratty.com/tag/vulnerability">vulnerability</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/300861445/">Flash Player + Windows = Threat of SQL Injection</source>
    </item>
    <item>
      <title><![CDATA[Yet Another Massive SQL Injection Spotted in the Wild]]></title>
      <link>http://securityratty.com/article/12b8db5bd43df2b62e54ac712ae9b35b</link>
      <guid>http://securityratty.com/article/12b8db5bd43df2b62e54ac712ae9b35b</guid>
      <description><![CDATA[Another SQL injection attack was spotted in the wild during the last couple of hours, and while it continues remaining active, surprisingly, the malicious domain is not in a fast-flux. As I've already...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SDqaq-zK7XI/AAAAAAAABvg/nRL6KdGrZzI/s1600-h/SQL_latest.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SDqaq-zK7XI/AAAAAAAABvg/nRL6KdGrZzI/s200/SQL_latest.JPG" alt="" id="BLOGGER_PHOTO_ID_5204642382582836594" border="0" /></a>Another <a href="http://ddanchev.blogspot.com/2008/05/malware-domains-used-in-sql-injection.html">SQL injection attack</a> was spotted in the wild during the last couple of hours, and while it continues remaining active, surprisingly, the malicious domain is not in a fast-flux. As I've already pointed out, the upcoming SQL injection attacks for the next couple of months, will be primarily executed by copycats, where among the few differentiation factors left is <a href="http://blogs.zdnet.com/security/?p=1122">increasing the survivability of the domain</a>.<br /><br />In the particular attack, the injected domain <span style="font-weight: bold;">chliyi.com /reg.js</span> loads an iFrame to <span style="font-weight: bold;">chliyi.com /img/info.htm</span> where a VBS script attempts to execute by exploiting MDAC ActiveX code execution (CVE-2006-0003), whose detection rate is 1/32 (3.13%)  and is detected as Mal/Psyme-A. Approximately, 8,900 sites have been affected.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2lbQHH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2lbQHH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sNMLDH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sNMLDH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jW8r5h"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jW8r5h" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4QlCUh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4QlCUh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UYtzTH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UYtzTH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TrIIlH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TrIIlH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HRviah"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HRviah" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/298464633" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 26 May 2008 06:58:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/domain">domain</category>
      <category domain="http://securityratty.com/tag/domain chliyi">domain chliyi</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/sql injection attack">sql injection attack</category>
      <category domain="http://securityratty.com/tag/vbs script attempts">vbs script attempts</category>
      <category domain="http://securityratty.com/tag/chliyi">chliyi</category>
      <category domain="http://securityratty.com/tag/malicious domain">malicious domain</category>
      <category domain="http://securityratty.com/tag/sql injection attacks">sql injection attacks</category>
      <category domain="http://securityratty.com/tag/differentiation factors">differentiation factors</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/298464633/yet-another-massive-sql-injection.html">Yet Another Massive SQL Injection Spotted in the Wild</source>
    </item>
  </channel>
</rss>
