BleepingComputer.com: Massive Surge In Website Iframe injections

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Massive Surge In Website Iframe injections blamed on a single, well organized group

#1 User is offline   Andrew 

  • Bleepin' Night Watchman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Moderator
  • Posts: 7,422
  • Joined: 05-December 05
  • Gender:Not Telling
  • Location:Right behind you

Posted 03 September 2009 - 01:22 AM

Quote

A mass compromise that has hit tens of thousands of English-language webpages is probably part of a much larger wave of attacks that's been under way since June by a sophisticated band of criminals, a security researcher said Wednesday.
Source: The Register

I know that I've noticed an upswing in the number of sites I surf to being flagged as unsafe by Google Safe Search or blocked by my antivirus (Avast) as containing either "HTML:Iframe-GZ" or "HTML:Iframe-EJ."

An Iframe, for those not familiar with HTML, is an "inline" frame, an HTML element which can display a webpage or other document within a "parent" page.

These malicious Iframes attempt to download and run a malicious javascript document which can infect a target computer with such nasties as the Gologger keylogger and various trojan horse programs.

According to Google, this exploit has resulted in a more than doubling of their Safe Browsing Malicious Sites list. since January.

The Iframes are inserted into websites which use MySQL databases as a backend by means of an SQL injection attack. Websites based on popular blogging platforms such as Wordpress and Drupal, and even forums such as those using Invision Power Board and PHPBB may be vulnerable.
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.
Posted Image
Boredom Software Stop Highlighting Things

#2 User is offline   scff249 

  • Indecisive Lurker
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 1,319
  • Joined: 14-February 08
  • Gender:Male
  • Location:A galaxy far, far away...

Posted 03 September 2009 - 06:57 AM

:thumbsup: .....scary......
"Ototo'i wa usagi o mita no...Kino wa shika...Kyo wa anata." -Kotomi Ichinose (Clannad) [see below for translation]
"Day before yesterday I saw a rabbit, and yesterday a deer, and today, you." -The Dandelion Girl
"You are not alone, and you are not strange. You are you, and everyone has damage. Be the better person." -Katawa Shoujo

#3 User is offline   QQQQ 

  • Forum Regular
  • PipPipPip
  • Find Topics
  • Group: Members
  • Posts: 165
  • Joined: 06-January 05

Posted 03 September 2009 - 09:54 AM

Just last week a customer of mine had this on their website, Google is still saying site may harm your computer. I wonder if it will reset itself somehow as it has been removed from the site.

#4 User is offline   Andrew 

  • Bleepin' Night Watchman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Moderator
  • Posts: 7,422
  • Joined: 05-December 05
  • Gender:Not Telling
  • Location:Right behind you

Posted 03 September 2009 - 12:19 PM

There should be a button on the warning page that says something like "This ain't no baddie, buddy! Look at 'er agin!"
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.
Posted Image
Boredom Software Stop Highlighting Things

#5 User is offline   tos226 

  • BleepIN--BleepOUT
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 1,423
  • Joined: 21-October 04
  • Gender:Female
  • Location:LocalHost

Posted 07 September 2009 - 09:33 PM

IFRAMES can and should be be blocked. All of them.
In IE in the miscellaneous settings.
In Opera they're calld Inline Frames.
Block and don't worry.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users