NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Incidents

Incidents


MSN Canada Website Compromised by Hackers

Malicious IFrame injected into redirect page

By Lucian Constantin, Web News Editor

12th of June 2009, 13:01 GMT

Adjust text size:


Malicious IFrame injected into Sympatico / MSN Canada website
Enlarge picture
Researchers from net security company Websense warn that a particular section of the MSN Canada website has fallen victim to hackers who injected rogue code into a page used for redirection. The code is obfuscated and loads content from a domain associated with malware distribution.

The msn.ca website redirects to sympatico.msn.ca, a portal operated by Bell Canada, known for its Internet service provider called Bell Internet, formerly Sympatico, and Microsoft. "Canada's most popular Internet destination," as the website claims of itself, offers all online services available on any MSN portal.

While surfing the website with a packet inspection program on, Jay Liew noticed some strange activity when trying to access cinema.sympatico.msn.ca. The index page on this subdomain is set to redirect users to divertissement.sympatico.msn.ca/Cinema/ via a Location HTTP header. This is also the place where the hackers chose to hide their payload.

Obfuscated JavaScript code injected into MSN Canada page
Enlarge picture
"The index page has been infected with obfuscated JavaScript code to redirect users to a known malware host," the Websense researcher explains. The escaped code actually reveals an injected IFrame, which loads content from a remote domain name that has been associated with malicious activities in the past.

The point of entry for this hack has not been revealed, but, according to the company, "Microsoft has since scrubbed the site clean, and we've confirmed that the malicious code is no longer there." The most common Web attacks resulting in code injection are called cross-site scripting (XSS).

XSS weaknesses are the result of poor input validation into web forms and can be persistent, non-persistent, or DOM-based. A persistent cross-site scripting weakness, also known as type 2 XSS, allows for permanent injection of arbitrary code into a page.

Another type of attack, which could have been used to compromise the msn.ca page, even if less likely, is the SQL injection. Such a flaw allows attackers to pass rogue SQL commands with the credentials used by the website via unsanitized parameters.

Fortunately, the hackers made a fatal mistake, which rendered their attack ineffective. According to the Websense analysts, "The Location HTTP header redirects [users] to another MSN Sympatico site before the browser has a chance to render the page and request the malicious content."

Watch Jay Liew explaining the attack on msn.ca:

TAGS:

MSN Canada | IFrame injection | website compromise | Sympatico | Websense
Read by 2,197 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Excellent (5.0/5) 1 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


The Embassy of Portugal in India Falls Victim to Hackers

The Embassy of India in Spain Pushes Malware via Website

Multiple Visa Websites XSSed

U.S. Bank and Bank of America Websites Vulnerable

Government Websites and Microsoft Help Push Scareware

New Mass Web Attack Makes 40,000 Victims

Gumblar Morphs, Becomes Martuz

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM