|
|
Rubrik: Virenwarnung/Aktuelle Meldungen Massenhafte Verseuchung von Webseiten mit bösartigem JavaScript-Code Die Zahl der infizierten Webseiten geht in die Hunderttausende (07.05.08) - Die Websense Security Labs wiesen in einer Eilmeldung auf die massenhafte Verseuchung von Webseiten mit bösartigem JavaScript-Code hin. Bereits Anfang April konnten die Websense Security Labs einen großangelegten Angriff auf tausende von Domains feststellen. Jetzt folgt offensichtlich eine zweite Welle. Die Zahl der infizierten Webseiten geht in die Hunderttau-sende. Besucht ein Surfer eine derart verseuchte Webseite wird eine Datei namens 1.js herunter-geladen und der Benutzer zu 1.htm umgeleitet. Hier geht es dann gezielt um die Ausnutzung der VML-Schwachstelle MS07-004.
Anzeige
In seinen Security Labs beobachtet Websense pro Stunde mehr als 40 Millionen Websites und analysiert, wie sich neue Bedrohungen aus dem Internet verhalten und auswirken. Die gesamte E-Mail-Nachricht der Websense Security Labs im
Wortlaut: Websense
Security Labs has been tracking a recent development of the malicious
JavaScript injection that compromised thousands of domains at the start of
this month, just 2-3 weeks ago. The attackers have now switched over to a new
domain as their hub for hosting the malicious payload in this attack. We have
no doubt that the two attacks are related as our brief analysis in our blog
will detail. In the last few hours we have seen the number of compromised
sites increase by a factor of ten. This mass
injection is remarkably similar to the attack we saw earlier this month. When
a user browses to a compromised site, the injected JavaScript loads a file
named 1.js which is hosted on http://www.nihao[removed].com The JavaScript
code then redirects the user to 1.htm (also hosted on the same server). Once
loaded, the file attempts 8 different exploits (the attack last April
utilised 12). The exploits target Microsoft applications, specifically browsers
not patched against the VML exploit MS07-004
<http://www.microsoft.com/technet/security/Bulletin/MS07-004.mspx> as well as
other applications. Ominously files named McAfee.htm and Yahoo.php are also
called by 1.htm but are no longer active at the time of writing. There are
further similarities too between the two mass attacks. Resident on the latest
malicious domain is a tool used in the execution of the attack. An analysis
of that tool can be found in the ISC diary entry here
<http://isc.sans.org/diary.html?n&storyid=4294> .
Mentioned in that diary entry is http://www.2117[removed].net. Our blog on
that attack can be found here
<http://securitylabs.websense.com/content/Blogs/3053.aspx> . It appears that same tool was used to orchestrate
this attack too. The
number of sites affected is in the hundreds of thousands. Casualties of the
previous attack include various |
||
|