Snooping on Chinese students?

Snooping on Chinese students?

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12279
  • Gde živiš: Höganäs, SE

Citat:Between the holidays I found a very simple but digitally signed malcode. It basically does one single thing: It overwrites the hosts file. The modification is as follows:

Citat:175.41.21.11 www.chsi.com.cn

The hosts file modification has the effect of overriding any DNS queries for chsi.com.cn so that it points to a different IP than the official one. The site chsi.com.cn seems to be a student information portal, “China Higher Education Student Information Network”.

By redirecting the address to a different IP, attackers are able to present users with altered web content or perform man-in-the-middle attacks. The purpose of this against a student site is up for speculation.

The digital signature attached to the file is quite recent, Dec. 28th, 2011. The certificate belongs to 北京火鸟网络科技有限责任公司 (Google translated to “Beijing Firebird Network Technology Co., Ltd.”). We’ve been in contact with Thawte and have gotten confirmation that this certificate is being revoked.


Source: http://blogs.norman.com/2012/malware-detection-tea.....e-students




Knjigu u šake, no bad western p0rn for you. Razz



Registruj se da bi učestvovao u diskusiji. Registrovanim korisnicima se NE prikazuju reklame unutar poruka.
Ko je trenutno na forumu
 

Ukupno su 468 korisnika na forumu :: 49 registrovanih, 8 sakrivenih i 411 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 1567 - dana 15 Jul 2016 19:18

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: _Petar, A.R.Chafee.Jr., Atomski čoban, bankulen, BSD2, crnitrn, danilopu, djordje92sm, dozorni, dragon986, duskovuk63, Filodendron, Georgius2, gzoki, ivance95, kolateralnasteta, Kos93, Kubovac, lelemud, Lep1na, louderick, ltcolonel, Mikulino, Milan Miscevic, milank1, milimoj, Mirage 2000N, NikolaGTR, novator, nuke92, Panonsky, plavii, riva, Rota 9, sasa.zoric, slonic_tonic, spooky-II, SsssssNOVI, stokanovicm, su27, theNedjeljko, vasa.93, vespa nikola, virked, vlad44, Vlada1389, vladom6, zlatkovuka, zodiac94