|
|
Yesterday we uncovered a newer mass hack affecting over 10,000 web pages. That number has since doubled. Today, I took a look at another recent mass attack, which was similar to those reported by Dancho Danchev, but reference a JS file rather than an IFRAME. Â
The attack seems to have started more than a week ago, and nearly 200,000 web pages have been found to be compromised, most of which are running phpBB. This contrasts yesterday’s attack in that the vast majority of those were active server pages (.ASP). The ASP attacks are different than the phpBB ones in that the payload and method are quite different. Various exploits are used in the ASP attacks, where the phpBB ones rely on social engineering. phpBB mass hacks have occurred in the past, including those done by the Perl/Santy.worm back in 2004.
Here’s a brief video demonstrating how the phpBB attack looks from the end user’s perspective.
|
|
I had never thought the obviously simple ways Google works. The truth of the issue is that even though it crawls your page multiple times, it takes a tonne of work on your part to get a site to become “relevent” to the spiders. I guess this lends to my understanding of search engines.
Even if it is an ad, they are apparently very good at what they do. I mean, infecting this many machines this quickly just so their product is needed… they are hella smart.
PJ – I can tell the target of the attacks by looking at the pages that were hit.
Very interesting to have come across this article and video. It was possibly last Thursday/Friday that I was using the internet for general use. I like to read the news. During the evening, my browser would open, but would not close. This issue was quickly resolved but I still wonder what might have caused it.
I’ve responded to Henry S offline.
For those looking for more about how they can tell if they have been impacted. Compromised sites have script injected on pages.
script src="http://... .js
Submit your own comments / message for this post