6 Music -> http://www.bbc.co.uk/6music/
1xtra -> http://www.bbc.co.uk/1xtra/
Na ovim sajtovima se nalazio maliciozni iFrame koji je dovodio, nezasticenog korisnika, do toga da se jednostavnim pretrazivanjem sajta mogao inficirati (drive-by download napad). Taj iFrame je automatski ucitavao malware sa sajta koji se nalazio na co.cc domenu. Payload je isporucivan samo pri prvoj poseti.
Za isporucivanje malicioznog koda koriscen je Phoenix exploit kit. Pominjan je u ovom clanku: informacija.rs
Malware je detektovalo samo 20-tak% svih anti-virusnih resenja sa Virus Total-a.
Citat:Using Virus Total scan to see which products picked up the injected iframe, Websense showed that anti-virus scans from some outfits like Kaspersky, Symantec, PC Tools and Trend Micro picked up the hack.
However, other top name insecurity vendors like Sophos, McAfee and even Microsoft's anti-virus tools didn't register the hack at all.
Citat:Posted: 15 Feb 2011 04:03 PM
Citat:At the time of writing this blog, the sites are still linking to an injected iframe.
Vise na:
http://community.websense.com/blogs/securitylabs/a.....-code.aspx
http://www.theinquirer.net/inquirer/news/2026766/bbc-music-websites-hacked
http://threatpost.com/en_us/blogs/bbc-sites-serving-malware-021611
http://www.net-security.org/malware_news.php?id=1631
|