• On MovieTome: See the villain of IRON MAN 2!
March 14, 2007 2:56 PM PDT

Blogger.com targeted by online criminals

by Robert Vamosi
  • Font size
  • Print
  • Post a comment

A few weeks ago, casual surfers to the official Super Bowl XLI site were exposed to malicious exploits, not by design but rather because vandals attempted to poison a legitimate Web experience. The process is called cross-site scripting, where vandals add a snippet of malicious code to a site's URL. If the site is vulnerable to such an attack (and many sites are), the code is accepted by the Web server and added to the display page. Future visitors to the site will then download the malicious code along with the page they intended to view.

Now, security vendor Fortinet reports that Google-owned Blogger.com sites are also vulnerable. Using Exploit Prevention Labs Linkscanner Pro, CNET confirmed one of the example blog sites provided by Fortinet does currently contain a malicious iframe insertion. Iframes are used by Web designers to open additional windows (often hosted on other sites) within a main Web page; iframes can also be used by criminal hackers to redirect browsers to malicious-code sites. In the example provided by Fortinet, the iframe instruction appears as URL Escape Code characters, two-character hexadecimal (8-bit) values usually starting with a "%" character, such as "%3C," making it hard to read what the code intends to do.

Chances are the owner of the blog did not include this code on his page, and has not checked the page since posting his original blog. Using Linkscanner Pro on the page, we found the malicious code uses an unspecified vulnerability within the RDS.Dataspace ActiveX control (CVE-2006-0003). Visitors to this particular infected blog site who have not installed the patches within Microsoft Security Bulletin MS06-014 might be vulnerable to remote code execution on their desktops. Fortinet says it has found other examples of Blogger.com content targeted with cross-site scripting malicious code, including sites on topics as diverse as Star Wars, school, furniture, and girlfriends.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
advertisement

About Webware

Say No to boxed software! The future of applications is online delivery and access. Software is passé. Webware is the new way to get things done.

Add this feed to your online news reader

Webware topics

13 games for newer iPhones

So you've got an old iPhone or iPod and want to see what some of the latest games are doing with the newer hardware? We've checked out 11 titles to show you the differences.
• Images: Old vs. new

Intel to pay AMD $1.25B in settlement

Antitrust and intellectual property fights come to an end for now. AMD will drop pending litigation, and Intel will "abide by" a long list of prohibitions.
• AMD: Our claims are 'ratified'

Inside CNET News

Scroll Left Scroll Right