Feeds

Mass compromise powers massive drive-by download attack

Invasion of the password snatchers

Top 5 reasons to deploy VMware with Tegile

More than 10,000 web pages have been booby trapped with malware in one of the largest attacks of its kind to date.

Compromised web pages include travel sites, government websites, and hobbyist sites that have been modified with JavaScript code that silently redirects visitors to a site in China under the control of hackers.

Miscreants likely reprogrammed the web pages after scanning the net for insecure servers.

The malware cocktail attempts to exploit vulnerabilities in Windows, RealPlayer, and other applications to break into insecure PCs, according to an analysis by net security firm McAfee.

Components of the malware attempt to steal passwords to online games while others leave a back door that allows the installation of additional malicious programs.

McAfee Avert Labs first spotted this attack on Wednesday, 12 March. Of the 10,000 pages that were compromised, a number have already been cleaned up.

A single organisation or small group is likely behind this attack, as the malicious code on all these pages is served up from the same server in China.

Craig Schmugar, threat researcher at McAfee Avert Labs, said the attack illustrated that the conventional wisdom that surfers are safe providing they stick to trusted sites (and away from warez and porn) no longer holds true.

"Often you hear warnings about not going to untrusted sites," said Schmugar. "That is good advice, but it is not enough. Even sites you know can become compromised. You went to a place before that you trust, but that trust was violated through a vulnerability that was exploited." ®

Intelligent flash storage arrays

More from The Register

next story
Knock Knock tool makes a joke of Mac AV
Yes, we know Macs 'don't get viruses', but when they do this code'll spot 'em
Shellshock over SMTP attacks mean you can now ignore your email
'But boss, the Internet Storm Centre says it's dangerous for me to reply to you'
Why weasel words might not work for Whisper
CEO suspends editor but privacy questions remain
Feds seek potential 'second Snowden' gov doc leaker – report
Hang on, Ed wasn't here when we compiled THIS document
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
China is ALREADY spying on Apple iCloud users, claims watchdog
Attack harvests users' info at iPhone 6 launch
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
New hybrid storage solutions
Tackling data challenges through emerging hybrid storage solutions that enable optimum database performance whilst managing costs and increasingly large data stores.
Website security in corporate America
Find out how you rank among other IT managers testing your website's vulnerabilities.