NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Security

Security


Microsoft Warns of Increase in Gamburl Attacks

A JavaScript redirector

By Marius Oiaga, Technology News Editor

28th of May 2009, 09:02 GMT

Adjust text size:


Security
Enlarge picture
Microsoft warned of an increase in web-based attacks related to a family of malicious code referred to as Gamburl, but also Gumblar or Redir. Gamburl is essentially a JavaScript redirector, and in this regard poses a high level of risk to end users because the code is used on legitimate websites that have been compromised by attackers.
Microsoft informed that it had confirmed the existence of legitimate webpages in the wild, modified in order to contain the malicious script. While victims think that they are safe by visiting trusted and familiar online destinations, the addition of Gamburl means that drive-by-attacks could be just “around” the next click.

Elda Dimakiling and Jireh Sanico from the Microsoft Malware Report Center explained that: “When a user visits a site containing a Gamburl script, the browser will be redirected to a specific Web site that contains a slew of exploits and other malware. As of this writing, Gamburl is known to redirect to the following Web sites: gumblar.cn; martuz.cn. Once connected to the above sites, Gamburl tries to download other malware into the system. From what we have observed, these malware are mostly backdoors, PDF and Shockwave exploits.”

At the same time, Microsoft informed that malformed webpages could lead to infections with malicious code from the Win32/Daonol family. Daonol Trojans are used to redirect searches to additional malicious websites. Removal is that more difficult since the malware blocks access to the websites of security companies.

“Daonol is also capable of stealing information, such as FTP credentials, and placing the information in a file in the Windows system folder called sqlsodbc.chm. Note that a file named sqlsodbc.chm exists by default when you install Windows, and so is overwritten if your system has been infected by Daonol. This may be a symptom of Gamburl/Daonol infection,” Dimakiling stated.


TAGS:

Gamburl | JavaScript redirector | Daonol
Read by 1,160 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
NOT RATED 0 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2010 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Comodo Software Removed from Softpedia [UPDATE 3]

Microsoft: Software as a Service Is a Must-Have for Businesses

Microsoft Zentity 1.0 RTM

ADMT 3.1 Doesn't Install on Windows Server 2008 R2

Access Free RampUp for Windows Mobile

Microsoft Online Customers in the Thousands

Office 2000 Support Ends in July, 2009

Windows 7 vs. Vista SP1 vs. XP SP3 – Feature Comparison

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM