Custom Search
Search more than 150 trusted Websites for related information.

Hacking: Legitimate sites serving up stealthy attacks

January 22, 2008 by Shanmuga  
Filed under Hacking

malware-help0005-12-jan-08.jpg "Thousands of legitimate Web sites are hosting an infection kit that evades detection by attempting to compromise each visitor only once and using a different file name each time, Web security firm Finjan warned last Monday. The attack, dubbed the "Random JS toolkit" by the security firm, currently uses dozens of hosting servers and more than 10,000 legitimate domains to attempt to exploit the systems of visitors to the sites, the company said in an analysis posted to its Web site.

The compromised sites host the malicious code — foregoing the iframe redirect that has increasingly been used by attackers — and serves up the attack to each visitor only once using a random file name each time. The two techniques, along with more traditional code obfuscation, makes the attack difficult to find, said Yuval Ben-Itzhak, chief technology officer for Finjan. "This attack uses three different methods to go undetected by signature-based or URL-based defenses," Ben-Itzhak said. "If you realize that you’ve been infected, and you go and search sites, you will not be able to find the site that infected you."" - Content courtesy of Legitimate sites serving up stealthy attacks

  • StumbleUpon
  • Digg
  • Reddit
  • del.icio.us
  • Facebook
  • MySpace
  • TwitThis
  • Google
  • Yahoo! Buzz
  • Live
  • YahooMyWeb
  • E-mail this story to a friend!

If you enjoyed this post, make sure you subscribe to my RSS feed!

You may also like to read

Comments

Everyone has an Opinion...why don't you share yours and oh, if you want a pic to show with your comment, go get a gravatar! or you can even subscribe to our comments feed.

    Note:
  • All fields except the comments field are optional.
  • Real names aren't required, but please give us something to call you. Conversations among several people called "Anonymous" get too confusing.
  • All comments are pre-moderated, and will not appear on this site until approved by the site owner.





Tags

More News, Articles from elsewhere