Security [CENTRAL] Forum - SCforum.info
31. July 2010., 07:11:48 *
Welcome, Guest. Please login or register.

Login with username, password and session length

SCforum.info - Security [CENTRAL] Forum

↑ Grab this Headline Animator

Custom Search
News: # Win 3 licenses of BitDefender Total Security 2010 ! ! !
 
  Home   Forum   Help Chess Links Login Register   *

SCforum.info




SCF Recent Posts
[30. July 2010., 21:34:58]

[30. July 2010., 04:46:02]

[29. July 2010., 18:08:07]

[29. July 2010., 10:48:03]

[29. July 2010., 06:49:07]

[28. July 2010., 18:43:20]

[28. July 2010., 09:39:19]

[28. July 2010., 08:25:57]

[27. July 2010., 20:10:00]

[26. July 2010., 09:48:23]
SCF Translate


Members
Total Members: 4608
Latest: bufuNk
Stats
Total Posts: 10662
Total Topics: 3314
Online Today: 957
Online Ever: 51419
(01. January 2010., 12:27:49)
Users Online
Users: 13
Guests: 1107
Total: 1120

@MEMBER OF PROJECT HONEY POT
Spam Harvester Protection Network
provided by Unspam

Friend of WOT

Creative Commons License

SCF Feedburner

SCF Facebook

SCF Twitter

Welcome to SCforum.info - Security [CENTRAL] Forum, a home of the SCF Community devoted to provide Computer related News, Alerts, Downloads and FREE Help in such a way that even the novice computer user can understand.

Getting started using our community is extremely easy, check the two steps below:

Step 1: Create an account by clicking here. It's completely free with no hidden strings attached.

Step 2: If you have a computer problem and need some help, or just want to take part in opened discussions, simply visit scForum. Once you *Register an account, you can quickly post your questions and comments.

(*Registered Members get: free support, also, they can communicate privately with other members via PM, removal of this message, see fewer ads and much more...)






Pages: 1
  Print  
Author Topic: Thousands snared by malware warning from big-name websites  (Read 752 times)
0 Members and 1 Guest are viewing this topic.
Amker
SCF Global Moderator
*****

KARMA: 17
Gender: Male
Age: 30
Location: EU
Posts: 1314


Google Talk
WWW
« on: 08. November 2007., 06:32:59 »

Thousands of PC users have been duped into surrendering sensitive information and installing malicious software after falling victim to a complex scam that continues to plague well-known websites, a researcher warns.

The scam is the latest to piggyback on banner ads that are fed to high-traffic destinations. Malicious code hardwired into the ads prompts a pop-up that warns of a bogus security threat on the visitor's machine. It offers to fix the problem in exchange for a fee and for credit card information. The ad then attempts to install a back door on the victim's machine.

"These are pretty well-respected, high-traffic websites," said Don Jackson, a researcher with security provider SecureWorks. "The point is to compromise [the user's machine] and basically have it on demand."

Jackson estimates the rogue ads have appeared on anywhere from "several hundred to 1,000" sites, which tend to be related to television and entertainment. Based on unique signatures of the javascript used in the attack, which researchers have seen passing over the net, he estimates thousands of people have fallen for the ruse.

Jackson has managed to shut down at least two servers serving the bad ads, but warns at least two more are still operational. He declined to identify the servers or the websites by name.

Those behind the scam make some money from the sale of the bogus software, but the real profit comes from selling the victim's credit card information and access to the infected computer.

The tainted ads are being sold by outfits posing as small online advertising agencies. They then purchase ad space from the large websites. It's hard to spot anything fishy about the ads. They look legitimate are are programmed to only occasionally serve up malicious code, thwarting attempts by security personnel to filter out harmful ads.

As is so frequently the case, those using the NoScript extension for the Firefox browser are afforded some level of protection against the ads, but not always. The ads are frequently served up by the same server hosting the trusted content. Users who allow the site to run javascript so, for example, it can provide local weather forecasts, will not be protected, Jackson said.

When a person views a page that contains a malicious ad, a threat warning will appear if the victim clicks anywhere on the page or take most other actions. The bogus anti-spyware programs bear names including Spy-shredder, AntiVirGear and MalwareAlarm. ®

The Register
Logged

-> Is your PC free of viruses, trojans, worms, spyware...?! Check here: http://scforum.info/index.php/topic,734.0.html
Security [CENTRAL] Forum - SCforum.info
« on: 08. November 2007., 06:32:59 »



 Logged
Pages: 1
  Print  
 
Jump to:  

Enter your email address to receive daily email with 'SCforum.info - Security CENTRAL Forum' newest content:

Terms of Use | Privacy Policy
Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC
TinyPortal v0.9.8 © Bloc
Valid XHTML 1.0! Valid CSS!


Google visited last this page 28. July 2010., 18:51:11