Reposted from The Sophos Naked Security Blog.
Troj/PHPShll-B: Malware injects itself into WordPress installations
On Friday, a colleague in our IT department asked about a Mal/Badsrc-C malware detection that had been found by Sophos products on one of their friends' websites.
When I initially downloaded the website it looked clean. However, the automated systems inside SophosLabs were detecting the webpage as being infected with Mal/Badsrc-C.
So, I investigated a little more deeply - repeating the download after setting the User-Agent in my browser to pretend to be Internet Explorer.
This time I saw:
>>> Virus 'Mal/Badsrc-C' found in file index.html
Continue reading at The Sophos Naked Security Blog
Anatomy of a Wordpress Hack at the Loudmouthman Blog
I am a malware researcher and security analyst for a mid-sized global manufacturer. These are some of the incidents I come across frequently.
Monday, September 19, 2011
Thursday, August 18, 2011
The Low Hanging Fruit
Once again the "hackers" as they call themselves have come across some low-hanging fruit and have exploited it to inject iFrame into a low-traffic site.
I came across this one when investigating a root-cause for a malware infection on one of the machines I administer. Luckily the site had just been hit a couple days ago, and with the low traffic they have, it shouldn't infect many people.
I have informed the business owners and the site designer, but as of 3 hours later, the site is still online and the index.html file still has the iFrame code perched at the bottom of it. *update: the html files have been updated, but apparently by the bad guys*
It's a PDF exploit that takes advantage of CVE-2010-1885, which is a help and support center whitelist vulnerability. Another fine reminder that if you don't keep your software up to date, you become low-hanging fruit as well.
Hopefully more to come as I tear this thing apart a bit.
I came across this one when investigating a root-cause for a malware infection on one of the machines I administer. Luckily the site had just been hit a couple days ago, and with the low traffic they have, it shouldn't infect many people.
I have informed the business owners and the site designer, but as of 3 hours later, the site is still online and the index.html file still has the iFrame code perched at the bottom of it. *update: the html files have been updated, but apparently by the bad guys*
It's a PDF exploit that takes advantage of CVE-2010-1885, which is a help and support center whitelist vulnerability. Another fine reminder that if you don't keep your software up to date, you become low-hanging fruit as well.
Hopefully more to come as I tear this thing apart a bit.
Subscribe to:
Posts (Atom)