Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Tags > drive-by download

Stories about: drive-by download


More: << previous 50

Source Code for JailbreakMe iOS Exploits Released

The author of the JailbreakMe service has released the source code of the entire website including the exploits for the two critical vulnerabilities patched by Apple, which were leveraged to unlock the device.The version of the JailbreakMe.com website launched at the end of last month was actually the second iteratio...

12 August 2010
02:41 GMT

New Windows Vulnerability Could Re-Enable Old Exploits

A newly discovered Windows vulnerability might allow hackers to re-enable any ActiveX exploit previously blocked by Microsoft. Vulnerability researchers from VUPEN Security have successfully crafted a proof-of-concept attack that leverages the flaw to bypass an active killbit.Setting killbits is the default method us...

7 August 2010
08:03 GMT

Mass Injection at Media Temple Leads to Potent Web Exploit Kit

Security researchers from Websense warn that over one hundred websites hosted at Media Temple (mt) have been injected with rogue code that lead visitors to a potent Web exploitation kit. The toolkit targets a dozen vulnerabilities in older versions of Flash Player, Adobe Reader, Internet Explorer or Java Runtime.The ...

6 August 2010
10:12 GMT

ShopNBC Fake Emails Lead to Malicious Website

A new email scam tricks users into opening malicious links by using a fake ShoNBC e-flyer as lure. The rogue links direct victims to a website trying to infect their computers with malware.The spam has been intercepted by email and Web security provider AppRiver, who notes that the scammers probably copied and modifi...

13 July 2010
05:56 GMT

Spam Emails Masquerade as ICANN Notifications

A spam campaign currently in circulation attempts to scare users into clicking on malicious links by claiming that their domain name has been suspended by ICANN. Victims are exploited and eventually end up on a Canadian Pharmacy site.ICANN's 38th Meeting took place last week in Brussels and has attracted a lot o...

2 July 2010
12:50 GMT

Attacks Targeting HCP Vulnerability Launched from Vodafone UK Website

AVAST Software reports that Vodafone's UK website has been infected with malicious scripts, which attempted to exploit their visitors. The attacked targeted the still unpatched remote code execution vulnerability in the Windows XP Help Center. According to the antivirus vendor, the malicious code injected b...

2 July 2010
11:05 GMT

Web Attackers Replace JavaScript Code with PDF Documents

Security researchers at Sophos have intercepted a Web attack where a PDF document is used to detect the version of Adobe Reader and serve the appropriate exploit. If exploitation is sucessful, a FAKEAV variant is downloaded and installed on the victim's computer. Web-based exploitation is one of the pr...

2 July 2010
06:33 GMT

Lenovo Support Website Infects Visitors with Trojan

The support site of leading Chinese PC manufacturer Lenovo has been compromised by unknown attackers who injected a rogue IFrame into the pages over the weekend. Security researchers warn that unwary visitors looking for drivers are exposed to several exploits that install the Bredolab trojan onto their computers. Ac...

21 June 2010
10:26 GMT

Unpatched Windows Vulnerability Actively Exploited in the Wild

A critical Windows remote code execution vulnerability disclosed last week is already being exploited in the wild. Security companies warn that attackers are luring unsuspecting users onto malicious Web pages that leverage the flaw to install malware on their computers. Last Thursday, Tavis Ormandy, an information s...

16 June 2010
11:05 GMT

Over 62,000 New URLs Serving Exploit Cocktail

Security researchers advise that a new mass compromise attack is underway and has affected over 62,000 URLs to date. A rogue IFrame injected into the compromised Web pages loads a cocktail of exploits and malware from other domains.Web security company ScanSafe has been monitoring this new threat and advises that the...

25 August 2009
05:52 GMT

Webalizer Bug Possibly Leading to Mass Web Compromise

Security researchers warn that a recently published exploit for a vulnerability in Webalizer might be used to inject malicious code into tens of thousands of legitimate websites. The compromised URLs are redirecting to other websites serving malware and attempting to exploit unwary visitors.The Threat Prevention Team...

25 August 2009
04:32 GMT

Web Exploit Kit Targets 0-Day Microsoft DirectShow Vulnerability

A 0-day remote code execution vulnerability in Microsoft Video ActiveX Control is actively being exploited as part of an attack that affected thousands of websites so far. The exploit has been incorporated into a drive-by attack kit, which attempts to install a cocktail of malware on visitors' machines. Securit...

7 July 2009
04:20 GMT

Torrentreactor Website Injected with Malicious Code

Torrentreactor, one of the largest torrent indexers, has been compromised by unknown attackers who injected a hidden IFrame into its pages. The IFrame loads malicious code from a remote server that attempts to exploit software on visitors' computers and infect them with malware. The incident has been reported b...

2 July 2009
06:04 GMT

Gumblar Morphs, Becomes Martuz

Security researchers warn that the currently most widespread web threat, technically known as JSRedir-R, but generally called Gumblar, has morphed in order to resist take-down attempts. The new iteration of this exploit features a new domain name and more complex obfuscation. Gumblar is a complex web exploit. Report...

20 May 2009
08:13 GMT


More: << previous 50

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM