Feeds

Scareware tool dumps smut on Windows PCs

Rogue clean-up tool poses child abuse frame risk

Protecting against web application threats using SSL

Rogue anti-virus slingers are getting even sneakier. Instead of offering to clean up non-existent malware threats as per the traditional approach, one rogue scanner offers to clean up images of porn it claims to have found on a prospective mark's PC.

In reality, these images get downloaded by the purported clean-up package itself. Victims were exposed to the pitch on behalf of a especially malodorous scareware package called Win Spy Protect simply by visiting a hacked website.

Roger Thompson, chief of research at security firm AVG, ran across the threat months ago but held back on publishing details until Thursday. Heightened concerns about how malware infection could result in presence of image of child abuse on the PCs of non-paedophiles prompted Thompson into publishing a video of the threat (below).

The hacked website linked to the attack was a children's site and the content strictly adult porn. However, the tactic could result in child abuse images getting dropped onto the machines of surfers whose only mistake was to stray onto hacked websites, as Thompson explains.

Fortunately, LinkScanner detects the rogue-spyware aspects of this and blocks it just fine, but without LinkScanner, these images would now be in the browser cache, and it would sure look like the owner was guilty. Worse still, the images could just as easily be kiddy porn, and just being your cache would be regarded as possession, and therefore highly illegal by most law enforcement agencies.

Poisoned blogs

In related scareware news, hackers have set up 260,000 fake blog pages on compromised sites in preparation for a scareware distribution campaign that relies on manipulating search engine rankings so that booby-trapped sites appear prominently in the search indexes for topical terms.

Between the latest attack (detected this week) and an even larger assault along the same lines detected in September, there are now well over 800,000 fake blog pages. Few of these pages are detected by Google as malicious, net security firm eSoft warns.

A blog post by eSoft explains the mechanism of the scam.

"The key to this scheme is JavaScript uploaded to the compromised server and used in the fake blog pages. The file, css.js, contains obfuscated JavaScript which redirect users to Rogue AV [anti-virus] if the site is accessed through certain search engines," it said.

"Using this technique allows the attackers to quickly and easily change distribution points and payloads. The current payloads have low detection rates among AV [anti-virus] scanners." ®

Reducing the cost and complexity of web vulnerability management

More from The Register

next story
Infosec geniuses hack a Canon PRINTER and install DOOM
Internet of Stuff securo-cockups strike yet again
'Speargun' program is fantasy, says cable operator
We just might notice if you cut our cables
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
Greater dev access to iOS 8 will put us AT RISK from HACKERS
Knocking holes in Apple's walled garden could backfire, says securo-chap
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.