BleepingComputer.com: Javascript Injection Attack

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Javascript Injection Attack

#1 User is offline   quietman7 

  • Bleepin' Janitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 25,511
  • Joined: 09-July 05
  • Gender:Male
  • Location:Virginia, USA

Posted 18 September 2008 - 01:43 PM

Quote

JavaScript injection attacks seem to be the in thing these days. Malware writers are increasingly utilizing such attacks as a better means to spread their work.

As little as a year ago, the bad guys were dependent on enticing people to follow links that pointed to malicious websites (via e-mail, search links, or IM worms). Today, they are using JavaScript injection attacks to simply "steal" a website's visitors, and it has become something of a Swiss Army Knife for underground hackers to spread their malware worldwide.

...The malicious site attempts two different methods to attack its visitors. The first is an attempt to exploit a Microsoft MDAC RDS.Dataspace ActiveX Control Remote Code Execution Vulnerability (MS06-014)...The second attack attempted is a drive-by download, which affects not only the IE browsers, but also Firefox 1.0 & 2.0 browsers. This attack uses JavaScript to detect the browser's type, then uses Adobe Flash exploits to download and execute a malicious binary file onto the system...

f-secure.com/weblog
Microsoft MVP - Consumer Security 2007-2012 Posted Image
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

#2 User is offline   iisjman07 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 94
  • Joined: 31-August 08

Posted 18 September 2008 - 01:44 PM

Oh great, more ways to get infected.....

#3 User is offline   norpacmiami 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 15
  • Joined: 16-September 08

Posted 19 September 2008 - 09:55 AM

Quietman7,

Any suggestions on programs that can and will stop such Java malware "injections" right at the front door ?

Or are we dependent right now on luck and constant suppervision ?

Andy

#4 User is offline   iisjman07 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 94
  • Joined: 31-August 08

Posted 21 September 2008 - 12:38 PM

I expect that running Firefox with NoScript would block the java attack

#5 User is offline   quietman7 

  • Bleepin' Janitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 25,511
  • Joined: 09-July 05
  • Gender:Male
  • Location:Virginia, USA

Posted 21 September 2008 - 12:54 PM

Protecting websites:
• "Microsoft Best Practices for preventing SQL Injection Attacks "
• "Stop SQL Injection Attacks Before They Stop You"
• "SQL Injection Attacks - Are You Safe?"
• "How To: Protect From SQL Injection in ASP.NET"

The Shadowserver Foundation provides an informative example of an SQL Injection attack, the malicious involved and tips on protection and detection for those who surf the web.

Malware Domain Block List
domains.txt is the complete list along with original reference.
Note: Blocking by IP address could potentially block other legitimate pages on the host and this technique is generally only helpful for a short duration as attackers frequently change domain names and IP addresses.

Strategies to help prevent infection:
* Disable, block active scripting/JavaScript in Internet Explorer or use the NoScript addon for Firefox.
* Be suspicious of links from unknown origin.
* Keep Windows up to date and apply all critical patches.
* Use real-time anti-spyware and anti-virus protection and a firewall.

Tools and Tips: Firefox security and safe surfing add-ons
How to Set Security Options in the Firefox Browser
50 Firefox Add-Ons to Achieve Private and Secure Web Surfing
Microsoft MVP - Consumer Security 2007-2012 Posted Image
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users