Search Perform an advanced search query SOFTPEDIA
 
SOFTPEDIA
Updated one minute ago
HomeSubmit a program for being reviewedAdvertise on our websiteGet help on surfing our websitesSend us your feedbackGet information about our XML/RSS backend and how to use itBrowse the news archiveVisit our discussion forumVizitati forumul in limba romana



KLIP
  1. HOME
  2. SCIENCE
  3. TECHNOLOGY
  4. WEBMASTER
  5. SECURITY
  6. MICROSOFT
  7. LINUX
  8. APPLE
  9. GAMES
  10. TELECOMS
  11. REVIEWS
  12. LIFE & STYLE
  13. EDITORIALS
  14. INTERVIEWS
  15. RSS
Welcome!
Hello, Guest

Login if you have a Softpedia.com account.

Otherwise, register for one.

SPYWARE THREATS

Thousands of Clean and Pirate Websites Affected by Massive Web Attack

- The IFrame attack continues

By: Bogdan Popa, Security and Search Engines Editor

A few days ago, security researchers around the world spotted a new avalanche of IFrame attacks that revealed a pretty new hack technique: the users are redirected to several pages until they reach a ‘deadly’ final one which attempts to deploy the infection.

Today, security researcher Dancho Danchev has published a blog post in order to disclose
a couple of new websites affected by the threats. "These are the high profile sites targeted by the same group within the past 48 hours, with number of locally cached and IFRAME injected pages within their search engines," Dancho Danchev mentioned in the blog post.

The IFrame injection affected both clean and malicious websites, so extra-care is obviously recommended when browsing suspicious pages. For instance, the US Administration of Aging, the University of Vermont and some BitTorrent websites are all targeted by the web attacks.

The exploit is started through newly-introduced domains, most of them hosted on .info domains, which attempt to redirect the users to infected pages. Just like past attempts, once the visitor reaches the final website, he is recommended to download an ActiveX control, actually a new variant of the Zlob Trojan horse. Downloading the malicious files obviously brings the infection in your computer, making it entirely vulnerable to other future attacks. However, there are even more changes, according to the folks at Computer Associates.

"This fake codec is actually a hijacker that will change your DNS settings whether you are aquire your IP settings through DHCP or set your IP information manually. This hijacker will attempt to re-route all your DNS queries through 85.255.x.29 or 85.255.x.121," it is mentioned on the CA page.

"If you use a static IP address, CA AntiSpyware will set your DNS server to 198.6.1.1 to prevent your DNS queries from continuing to go through the rogue DNS servers. Please change your DNS server to the DNS server provided by your IP or Network Administrator."

However, refusing the download and avoiding getting the files is probably the best solution that would keep your computer clean and unaffected by the threat.

MORE RELATED ARTICLES: Google Users Played for Fools by Cyber Criminals Googling at Microsoft Will Get You Shot! Hacked Antivirus Site Delivers Virus Kicking Internet Explorer Security Up a Notch God, These Google Hackers Are Smart!
 
Comments | Link here | Subscribe
Print | Send to friend
Today's News | Yesterday's News

Search:


14th March 2008, 15:39 GMT | Copyright (c) 2008 Softpedia | Contact:
Read by 1,065 user(s) | Rating: | 5 vote(s) so far | Cast your vote:
Thousands of Clean and Pirate Websites Affected by Massive Web Attack - USER OPINIONS




We are sorry, there are no opinions available for this article.






SHARE YOUR OPINION ABOUT Thousands of Clean and Pirate Websites Affected by Massive Web Attack

Since you are not logged on, your comments will have to be approved before being displayed.
Click here to login, or register.
Your Name:
Your Email:
Type in the result:
Your Opinion:
 


DO YOU WANT TO CONTACT US?  

If you have some comments or you want to send us some information you can send us an email directly to .
You can use the form below for the same purpose.
Your full name: (at least 3 characters)
Your email address: (at least 5 characters)
Message subject: (at least 5 characters)
Message text:
(at least 10 characters)
Type in the result:
 
 



© 2001 - 2008 Softpedia. All rights reserved.
Softpedia™ and Softpedia™ logo are registered trademarks of SoftNews NET SRL.
Copyright Information | Privacy Policy | Terms of Use | Contact Softpedia | Update your software | Archive