Feeds

Malware authors play Mario on Daily Mail website

Cue the outrage

Combat fraud and increase customer satisfaction

Updated Tainted banner ads are being served up onto the Daily Mail's website.

We passed on a reader tip about a possible infection on DailyMail.co.uk to anti-virus firm Sophos, which confirmed that script served up through the site was redirecting surfers to a server linked to the spread of the strain of the Mario family of worms.

The tainted ads are the work of malicious hackers who somehow succeeded in injecting redirection scripts into banner ads. These malicious scripts generated an iFrame which pulls its content from a malicious server, located in Russia. The site attempts to exploit browser flaws to download malicious code onto unpatched Windows PCs, as part of a classic drive-by-download attack.

Analysis of the attack is ongoing.

We emailed the Daily Mail's website techies, which bounced with a no-such-user error message, but followed up with a call. An advertising sales rep confirmed he'd being informed of the attack, because of the potential impact on ads being served via site. It's unclear how far Associated Newspaper technicians have gone in blocking the attack but at least we know they are on the case. ®

Update

The first version of this story said that the tainted ads were been served up through an ad serving network, as in commonplace in such cases. Actually the malware came from the servers of the publisher of the Mail.

SANS - Survey on application security programs

Whitepapers

Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.