Internet Anthropologist Think Tank

  • Search our BLOG


  • HOME
    Terrorist Names SEARCH:
    Loading

    Tuesday, April 29, 2008

    Bot net counter


    4/29: Trojan.Asnoms!inf Detects Files Modified For Malicious Purposes
    April 29, 2008

    Trojan.Asnoms!inf is a detection for files that have been modified to load other malicious files during system start up.

    Technical details can be found at this Symantec page.

    xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

    This suggests the paradigm to counter bot nets.

    Gerald


    Labels: , , , , , , ,

    Terrorist Names SEARCH:
    Loading
    Internet Storm CenterImage via WikipediaExperts warn over SQL injection attacks
    Published: 2008-04-28

    Attackers are increasingly exploiting common database vulnerabilities to leave behind code on thousands of sites, redirecting visitors to servers that host malicious downloads, security experts warned last week.

    The attacks, which apparently started at the beginning of April, attempt to use any field on a Web site that accepts user input to execute commands on the database that stores the site's information. Since most databases use some variant of the structured query language (SQL), the attack is known as SQL injection.

    In the latest spate of compromises, unknown attackers used SQL injection techniques to create malicious iframe blocks on legitimate Web sites. Visitors to a compromised Web site could find their browser executing a Javascript file -- simply named 1.js or 1.htm -- embedded in the iframe, leading to another site that would attempt to install keylogging software by exploiting several different vulnerabilities.

    "The exploits target Microsoft applications, specifically browsers not patched against the VML exploit MS07-004 as well as other applications," security firm Websense stated in a research note last week. "Ominously files named McAfee.htm and Yahoo.php are also called by 1.htm but are no longer active at the time of writing."

    Estimates of the number of compromised Web pages varied between tens of thousands and just under 200,000 -- the latter tally based on the number of hits returned in a Yahoo! search.

    The most recent spate of SQL injection attacks resembles those that have occurred on and off over the past two years. In January 2007, the attacks gained notoriety when the Web site of Dolphin Stadium, the venue of that year's Superbowl, was compromised with a similar iframe attack. Earlier this year, the Internet Storm Center, a network-threat monitoring group, warned that such attacks had once again risen in prominence. The ISC issued a warning on Thursday about the latest rounds of attacks.

    In November 2007, a survey of Web site databases concluded that a half million were at risk of attack.

    In its analysis of the attacks, the Shadowserver group predicted that SQL injection will likely become more popular.

    "At the moment it appears that a small set of people are behind these attacks," the group said. "However, it most likely won't take too long for others to catch on and possibly conducting even more nefarious activities."

    If you have tips or insights on this topic, please contact SecurityFocus.

    Labels: , , , , , , ,

    Terrorist Names SEARCH:
    Loading

    Friday, April 25, 2008

    Half-Million IIS Servers Hit in Cyber Attack







    SEE WARNING AT END OF POST.

    Half-Million IIS Servers Hit in Cyber Attack
    April 25, 2008
    By Andy Patrizio

    A massive cyberattack is targeting vulnerable Internet Information Server-based Web pages by redirecting visitors to the site toward one hosting malicious code, and it's growing rapidly.

    When Panda Security first noted the infestation, it put the number of infected IIS servers at 282,000. Not even a day later and security firm F-Secure wrote its own blog entry, putting the infestation at over 500,000.

    The worst part of it all is that these infestations are not in seamy Web sites, they are taking place in legitimate Web pages. An IFRAME (define) redirects the user to another page, where identity-stealing malware is downloaded onto their computer. So even users who think they are staying clean are not safe.

    "In the old days, you used to think if you went to the dark side of the Internet you had a chance of being infected. Now you don't need to go to the bad neighborhoods to get attacked. You can be walking down the good side of the Internet and be infected," said Ryan Sherstobitoff, chief corporate evangelist at Panda Security.

    The vulnerability in IIS, developed by Microsoft (NASDAQ: MSFT), allows hackers to inject SQL code to manipulate legitimate Web pages. This code adds an IFRAME to redirect the user to a malicious Website that scans their computer for vulnerabilities and then downloads and installs malware that can get passed the user's defenses.

    The problem only affects IIS, not Apache or other Web servers. Microsoft reportedly knows of the issue, said Sherstobitoff. The company has not responded to a query InternetNews.com on when a fix can be expected as of press time.

    Sherstobitoff said the U.S. is being hardest hit, with government and public utility sites particularly popular. "They love anything that brings in victims," he said.

    Panda and F-Secure both identified a malicious piece of code being hidden in Web pages that does the redirect. Site admins should look for this hidden in their Web pages:
    >scCript src=http://www.nihaorr1.XXXcom/1.js<< href="http://forums.iis.net/t/1148917.aspx">"

    POSTING ( COPY/PASTE ) THE ABOVE CODE AS WRITTEN IN THE POST WILL INFECT YOUR BLOG. gOOGLES TEXT/CODE PROGRAMING WHEN POSTING CONVERTS THAT CODE TO "ACTIVE"......YOU WILL INFECT YOUR BLOG. g


    some people have noticed. Securing the server, updating all of the patches and proper configuration should help protect it until Microsoft comes out with a fix of its own, said Sherstobitoff.

    This article was first published on InternetNews.com.


    xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

    Be sure you are using "Google's block list"
    Some search pages have as many as 14,
    This blog had one for 15 min.?



    It will get worse if not this time NEXT TIME.

    What is ahead?

    Cyber Pearl Harbor.

    All the exercises the FEDs have and not one plans for
    the INTERNET GOING DOWN. days, weeks, months.
    The world could get its ASS kicked in months if the wrong people get together.
    Read cyber Pearl Harbor above.
    Its do able.

    Gerald
    WARNING POSTING THIS STORY FROM SOURCE WITH SCRIPT CODE INCLUDED IN STORY WILL INFECT YOUR BLOG. ETC...
    WARNING

    Labels: , , , , , , ,