Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Incidents

June 12th, 2009, 13:01 GMT · By

MSN Canada Website Compromised by Hackers

SHARE:

Adjust text size:


Malicious IFrame injected into Sympatico / MSN Canada website
Enlarge picture
Researchers from net security company Websense warn that a particular section of the MSN Canada website has fallen victim to hackers who injected rogue code into a page used for redirection. The code is obfuscated and loads content from a domain associated with malware distribution.

The msn.ca website redirects to sympatico.msn.ca, a portal operated by Bell Canada, known for its Internet service provider called Bell Internet, formerly Sympatico, and Microsoft. "Canada's most popular Internet destination," as the website claims of itself, offers all online services available on any MSN portal.

While surfing the website with a packet inspection program on, Jay Liew noticed some strange activity when trying to access cinema.sympatico.msn.ca. The index page on this subdomain is set to redirect users to divertissement.sympatico.msn.ca/Cinema/ via a Location HTTP header. This is also the place where the hackers chose to hide their payload.

Obfuscated JavaScript code injected into MSN Canada page
Enlarge picture
"The index page has been infected with obfuscated JavaScript code to redirect users to a known malware host," the Websense researcher explains. The escaped code actually reveals an injected IFrame, which loads content from a remote domain name that has been associated with malicious activities in the past.

The point of entry for this hack has not been revealed, but, according to the company, "Microsoft has since scrubbed the site clean, and we've confirmed that the malicious code is no longer there." The most common Web attacks resulting in code injection are called cross-site scripting (XSS).

XSS weaknesses are the result of poor input validation into web forms and can be persistent, non-persistent, or DOM-based. A persistent cross-site scripting weakness, also known as type 2 XSS, allows for permanent injection of arbitrary code into a page.

Another type of attack, which could have been used to compromise the msn.ca page, even if less likely, is the SQL injection. Such a flaw allows attackers to pass rogue SQL commands with the credentials used by the website via unsanitized parameters.

Fortunately, the hackers made a fatal mistake, which rendered their attack ineffective. According to the Websense analysts, "The Location HTTP header redirects [users] to another MSN Sympatico site before the browser has a chance to render the page and request the malicious content."

Watch Jay Liew explaining the attack on msn.ca:


TELL US WHAT YOU THINK:

5,331 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


The Embassy of Portugal in India Falls Victim to Hackers

The Embassy of India in Spain Pushes Malware via Website

Multiple Visa Websites XSSed

U.S. Bank and Bank of America Websites Vulnerable

Government Websites and Microsoft Help Push Scareware

READER COMMENTS:


Comment #1 by: Grimalkin61 on 25 Nov 2010, 17:12 UTC reply to this comment

I still cannot figure out why perfectly smart people must waste their talents doing silly little games like this I have an excellent anti malware program and I'm sure it has saved me a number of times from having to worry about this crap.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM