Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

December 12th, 2012, 12:31 GMT · By

BLOG

Compromised Joomla Sites Serve Scareware via Exploit Kits

SHARE:

Adjust text size:


Joomla sites hijacked and set up to serve malware Enlarge picture - Joomla sites hijacked and set up to serve malware
A large number of Joomla websites, and some WordPress sites, have been compromised and set up to serve malware to visitors, mainly fake AVs (scareware).

Germany’s CERT-Bund researchers have investigated this cybercriminal campaign and, according to The H, they found that the attackers have injected iFrames into the hijacked sites to redirect users to an exploit kit via the Sutra Traffic Distribution System.

The initial infections were most likely achieved with the use of automated scripts that exploited known vulnerabilities in the Joomla Content Editor.

In this case, the crooks are making a profit via two channels. First they earn some money from the internauts who pay for the registration fees asked by the fake antivirus applications.

They also make some money by using the traffic redistribution systems detailed around one year ago by experts from Symantec.

Webmasters are advised to make sure that their Joomla Content Editor is updated to the latest version. Those who believe that they might have fallen victims to this campaign are advised to check their JavaScript files for suspicious iFrames.

TELL US WHAT YOU THINK:

1,310 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Joomla 3.0.2 and 2.5.8 Available for Download, Security Fixes Included

Incapsula Releases Joomla Website Security and Acceleration Extension

Hackers Take Over Thousands of Tumblr Blogs with “Dearest ‘Tumblr’ users” Message

Cybercriminals Sell Apache-Based iFrame Injection Module for $1,000 (€800)

Piwik.org Hacked, Attacker Adds Malicious Code to Installation Files

READER COMMENTS:


Comment #1 by: ChrisT on 13 Dec 2012, 11:54 UTC reply to this comment

"Those who believe that they might have fallen victims to this campaign are advised to check their JavaScript files for suspicious iFrames."

You can do this quickly and for free using this online website scanner: http://www.websicherheit.at/en/website-security-check/

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM