Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

Halloween Hack Haunts Web Searches

Legitimate Halloween costume sites infected with rogue antivirus program

Oct 23, 2008 | 03:35 AM

By Kelly Jackson Higgins
DarkReading

All it takes for a good scare this Halloween season is a search for "Halloween costumes": That query turns up legitimate Web pages that have been infected by the attackers, according to researchers at Trend Micro.

Trickster attackers have inserted Web pages on the legit Halloween costume sites that come up in a search and used rogue JavaScript that invisibly redirects the user to a malicious page. It's a new twist on an old trick of manipulating search-engine optimization, according to the researchers.

"Usually in SEO Poisoning Attacks, malware authors compromise websites that are already top ranked in search engines, which may not be related to one another. Once compromised, they insert a specially crafted webpage on the compromised website so as upon using search engines or site searches, they can easily be visited or referred to," says Lennard Galang, a threat researcher with Trend Micro in a blog entry.

But with this Halloween costume attack, the rogue Web pages inserted into the compromised legitimate Websites contains the keyword "Halloween costumes" so they will come up a search. Once the user visits the page, he or she unknowingly gets redirected to the attacker's page, which displays a convincing-looking browser pop-up message offering a free scan for adware or spyware. The message says that your computer "is running slower than normal" and may be infected, so download the free Antivirus 2009 scanner to clean it up.

But clicking "okay" downloads the now-notorious rogue AV program/Trojan, which has been spreading rapidly via infected Websites. Trend Micro says this attack is similar to one last Christmas that targeted Christmas gift-shoppers.

— Kelly Jackson Higgins, Senior Editor, Dark Reading

  • Trend Micro Inc.


  • Subscribe to RSS










    Bugs
    ENTERPRISE VULNERABILITIES
    Vulnerability:suse linux
    Published:2010-01-22
    Severity:High
    Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
    Vulnerability:bind
    Published:2010-01-22
    Severity:Medium
    Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


    Briefing Centers
    POWERFUL INFORMATION
    AT YOUR FINGERTIPS
    (SPONSORED LINKS)