Slashdot Mirror


Asus.com Compromised With Exploit Code

Juha-Matti Laurio writes in with news that the Web site of ASUSTeK Computer (asus.com) has been compromised to spread exploit code. The original report from Kaspersky Lab claimed that the compromise lead to code exploiting the recently patched Microsoft Windows Animated Cursor (.ANI) 0-day vulnerability, but sans.org found no evidence of this. Apparently a malicious iframe was added to one of the machines in asus.com's DNS round-robin.

4 of 117 comments (clear)

  1. jpeg or png? by MichaelSmith · · Score: 3, Insightful

    TFA:

    up to no good pointing to another obfuscated javascript and a executable cloaked as a jpg file

    Then:

    Name: next3.png

    So is next3.png the real exploit and are they using "jpeg" to mean an image file? Or is there a jpeg file involved here?

  2. Asus Site Is Always A Mess Anyway by chromozone · · Score: 3, Insightful

    Many people who like Asus products know the Asus website is awful. No problem on that site would come as any surprise to anyone who goes there for updates or information. I'm glad it's no big deal this specific problem but that is still one dodgey site that needs TLC quite desperately.

  3. Re:Just assume you're infected. by Aladrin · · Score: 3, Insightful

    As much as I hate to agree with a troll, he's partially right. It's best to assume you have been infected. Even if all the current anti-spyware doesn't find it, that doesn't mean it won't pop up soon. We don't know enough about this malware to identify what it is and if you have been affected, apparently.

    On the other hand, the troll is pretty much wrong about everything else, including "Furthermore, if you use WINE you can run virtually all of your existing Windows applications and games." I have been trying to get windows-based games to run for quite some time, and with the exception of a few favored games (WoW) and some old ones that were really simple, not much works at all, let alone with hours of tweaks. (Actually, I don't even own WoW, so I could be wrong about how well it works as well.)

    --
    "If you make people think they're thinking, they'll love you; But if you really make them think, they'll hate you." - DM
  4. I'm shocked... SHOCKED! by Excelcia · · Score: 5, Insightful

    How dare their web site go down when I need a driver? How dare anyone ever have a problem they don't know how to solve in sufficient time to deal with my selfish and entitled demands? Their tech support exists (solely, I might add) to tell me the bios version I need. So bye bye Asus, I consign you to the ash heap of history while I move along to a company that forces its developers to blog for me, whose support staff reads my every web site comment (including the ones on third party sites), and that spends every last dollar it has on server infrastucture. Of course, I don't particularly care that this company will be out of business in no time, because there are a constant influx of new companies who are willing to lose money for a year and fold.

    And to top it all off... BAH HUMBUG!