Feeds

Hackers turn Cleveland into malware server

And Computer Associates too

Providing a secure and efficient Helpdesk

Tens of thousands of websites belonging to Fortune 500 corporations, state government agencies and schools have been infected with malicious code that attempts to engage in click fraud and steal online game credentials from people who visit the destinations, security researches say.

At time of writing, more than 94,000 URLs had been infected by the fast-moving exploit, which redirects users to the uc8010-dot-com domain, according to this search. Security company Computer Associates was infected at one point, as were sites belonging to the state of Virginia, the city of Cleveland and Boston University.

"This is a wide variety of sites that have been impacted," said Mary Landesman, a researcher for ScanSafe, a company that provides real-time information to clients about malicious sites. "It's a real in-your-face example of what we see everyday. It's really time for companies that have a vested interest in a web presence to take a hard look at what their security posture is."

Malicious hackers were able to breach the sites by exploiting un-patched SQL injection vulnerabilities that resided on the servers, according to Johannes Ullrich, CTO for the SANS Internet Storm Center. The injections included javascript that redirected end users to the rogue site, which then attempted to exploit multiple vulnerabilities to install key-logging software that stole passwords for various online games, he and other researchers said.

In many respects, the attack resembles one that took place early last year on websites belonging to the Miami Dolphins football team just in time for the Super Bowl. Miscreants behind that attack exploited a bug in a content creation tool called DreamWeaver, which left much of the code on the website vulnerable to SQL injections. The attackers, which over the past year have struck other sites, were able to exploit the vulnerabilities using scripts that scour servers for the buggy code.

Ullrich said he was unsure where the vulnerability lies in the latest round of attacks.

Visiting uc8010-dot-com set off a chain of redirections that tried to use patched vulnerabilities to install key-logging software. Ullrich said he observed the sites using an old RealPlayer vulnerability. Roger Thompson of Exploit Prevention Labs, said here end users were also treated to a Windows vulnerability Microsoft patched in late 2006.

According to Landesman, the exploits forced end users to visit sites that pay third parties a fee in exchange for sending them traffic. She speculates the attackers signed up as affiliates of the sites and then profited each time an end user was infected. The malware also installed keyloggers on end user machines that stole passwords to various online games, Ullrich said.

He said the uc8010-dot-com domain (we don't recommend readers visit the site) was registered in late December using a Chinese-based registrar, indicating the attackers were fluent in Chinese.

As we've said before, end users should make sure browsers, browser plug-ins, media software and other applications are updated. Secunia's Software Inspector is one good way to do this. Also helpful is the use of the Firefox browser with the NoScript plug-in, which helps fortify users from many javascript attacks. ®

New hybrid storage solutions

More from The Register

next story
Google recommends pronounceable passwords
Super Chrome goes into battle with Mr Mxyzptlk
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Reddit wipes clean leaked celeb nudie pics, tells users to zip it
Now we've had all THAT TRAFFIC, we 'deplore' this theft
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
TorrentLocker unpicked: Crypto coding shocker defeats extortionists
Lousy XOR opens door into which victims can shove a foot
Greater dev access to iOS 8 will put us AT RISK from HACKERS
Knocking holes in Apple's walled garden could backfire, says securo-chap
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Top 5 reasons to deploy VMware with Tegile
Data demand and the rise of virtualization is challenging IT teams to deliver storage performance, scalability and capacity that can keep up, while maximizing efficiency.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.