• On TechRepublic: Five super-secret features in Windows 7
June 18, 2007 1:31 PM PDT

Massive Web attack gains momentum

by Robert Vamosi
IFrame code

The IFrame code that leads to drive-by exploits.

(Credit: Trend Micro)

Over the weekend, thousands of legitimate English-language Italian Web sites fell victim to one line of code. Taking advantage of the trust the users have in the sites they visit, the malicious code silently redirects browsers via JavaScript to servers containing a variety of drive-by exploits. If the visiting computer is unpatched for a variety of operating system, browser, and specific application flaws, malicious code is downloaded. Once installed, the new software can then be used to steal personal information or enlist a compromised machine in attacks on other machines. According to security vendor Websense, the attack now affects over 10,000 Web sites worldwide, and that list continues to grow. According to Trend Micro, servers hosting some of the malicious code have been traced to Chicago, the San Francisco Bay Area, and Hong Kong.

Steps used by Mpack

Steps used by Mpack

(Credit: Trend Micro)
The attack, dubbed Mpack, uses cross-site scripting to place malicious IFrames on legitimate Web sites. IFrames are used by Web designers to open additional windows (often hosted on other sites) within a main Web page; IFrames can also be used by criminal hackers to redirect browsers to malicious-code sites. Trend Micro believes this latest attack was automated. Websense reports that the server where users are redirected includes a counter that shows large numbers of visitors from Italy, Spain, and the United States.

Fortunately, there are a number of variables here. First, you must accidentally happen upon a vulnerable site, then your computer must have one of several browser vulnerabilities present for the attack to take root. According to Trend Micro, the component that serves up the browser vulnerabilities is browser aware, able to infect your specific browser of choice. Assuming it can, the attack then downloads various Trojans designed to steal personal information.

To prevent such an attack, Trend Micro urges everyone to be aware of sites requiring software installation; do not allow software installation unless you trust the site and the provider of the software. Keep your PC software fully patched and be sure your antivirus protection is updating properly. And, of course, be wary of any unexpected e-mail and e-mail attachments.

For more on this specific attack, antivirus vendor Panda has prepared a 28-page PDF that provides granular detail.

Originally posted at News Blog
As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from Webware
Smartphone users, keep complaining
Two new remote Webcams: Mole and Vue
Google launches Maps tool for finding flu vaccine
Get a $10 Restaurant.com gift certificate for 80 cents
Hundreds of Facebook groups hijacked
Plan your wedding with these Web resources
Twitter, LinkedIn team up for self-promotion free-for-all
'Elf Yourself' returns with Facebook and Twitter power
Add a Comment (Log in or register) (9 Comments)
  • prev
  • 1
  • next
Haven't beat the record
by qwerty75 June 18, 2007 2:49 PM PDT
For most damage from one line.

That "honor" belongs to MS, with the sasser worm taking advantage of one line of code that took MS 188 days to fix.
Reply to this comment
Not on Macs
by MaLvaDo39 June 18, 2007 3:08 PM PDT
When will the Windows users finally wake up?

You have the Stockholm syndrome!
Reply to this comment
When will Mac users
by Lindy01 June 18, 2007 7:06 PM PDT
give up?

So if you have auto updates turned on your fine. You would not even need AV software....just auto updates.

Add in AV software that is up to date...throw in Vista with UAC and that is just another layer.

You have to be stupid....flat out stupid these days to get hit by this.

True is wont hurt a Mac....but that is because these A-holes want to get the most bang for the buck....and they did not want to waste their time on something that has less than 5% market share.
View reply
Children...Children!!!
by Kings X Rocks! June 19, 2007 4:51 AM PDT
We who use Windows to earn money to support our families (because our company mandates this OS) are very sorry that an interesting article about a clever, but dastardly, exploit struck such a nerve with OS-X users!!

Rather than starting up the old I-am-part-of-the-religion-of-Apple CRAP, why not talk about psycology of the exploit writers? Or the things that ISPs could possibly do the help trim out this stuff. Or, the theory of fuel-injection...

It'd be more interesting than your wanting so-o-o-o hard to be and I told you so!
(9 Comments)
  • prev
  • 1
  • next
advertisement

About Webware

Say No to boxed software! The future of applications is online delivery and access. Software is passé. Webware is the new way to get things done.

Add this feed to your online news reader

Webware topics

After 5 years, Firefox faces new challenges

Mozilla helped reshape the Web since releasing Firefox 1.0 five years ago. Now it's got a reawakened Microsoft and Google Chrome to reckon with.

There's a map for that: GPS or smartphone?

Almost every handset comes with mapping software these days, but standalone GPS devices are becoming more affordable than ever.

Inside CNET News

Scroll Left Scroll Right