Feeds

Blackhole exploit posted on US Postal Service site

Return to sender of Spotify tainted ads pathogen

Intelligent flash storage arrays

The US Postal Service has pulled down a site hosting malicious code that was earlier used in a sophisticated multi-stage attack featuring the Blackhole Exploit kit.

The infected site - http://ribbs.usps.gov - which is involved in the delivery of USPS's business mail-focused barcode-based Intelligent Mail services - was infiltrated with malicious JavaScript. This malicious script redirected through a relay of other sites to an attack portal.

The attack portal displays a sneaky 404 Page Not Found error message while actually delivering live malicious code.

The drive-by download attack was ultimately aimed at using software vulnerabilities to install Trojans onto the machines of surfers visiting the particular USPS domain the miscreants managed to compromise.

Last week the same Blackhole Exploit kit infested the website of Worldfest, a Houston, Texas music festival, cloud security firm zscalar reports. The same Blackhole Exploit kit starred in the tainted ad compromise that affected ad-supported versions of Spotify late last month.

Although that attack ultimately punted scareware software, the exploit kit allows those with very little or no coding ability to deliver a hostile payload of their choice.

Zscalar has a good dissection of the latest attack, detected on Thursday, in a blog post here. ®

Top 5 reasons to deploy VMware with Tegile

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.