Slashdot Mirror


10,000-website Strong Malware Maze Created by Criminals

Stony Stevenson passed us an ITnews article about the newest scam in online crime. Some 10,000 web pages have been rigged by IT-minded criminals, with the aim of hijacking unsuspecting PCs. The site reports that the users are redirected through a maze of malware, all with the goal of gaining access to personal user information. "The reprogrammed web pages are probably victims of an automated attack that included scanning the internet for unsecured servers and planting a piece of JavaScript code that redirects to a site in China to serve up the malware. The malware cocktail attempts to exploit vulnerabilities in Windows, RealPlayer and other applications to break into the PC. A back door also allows the subsequent installation of additional malicious programs. McAfee Avert Labs first spotted the attack on 12 March. 'Of the 10,000 pages that were compromised a number have already been cleaned up,' the firm stated."

118 comments

  1. Oblig. by Damocles+the+Elder · · Score: 3, Funny

    It's over 9000!

    1. Re:Oblig. by Damocles+the+Elder · · Score: 0, Offtopic

      Oh, please. Over 9000 is modded redundant and It's a trap is modded up? Someone hasn't been keeping up with their web memes. I'm going to have to revoke your geek club membership.

    2. Re:Oblig. by Brian+Gordon · · Score: 0, Offtopic

      nice uid

    3. Re:Oblig. by fireman+sam · · Score: 3, Funny

      Every time someone posts to complain about a mod decision instead of leaving it to the meta-mods, God kills a kitten.

      --
      it is only after a long journey that you know the strength of the horse.
    4. Re:Oblig. by Anonymous Coward · · Score: 0

      Apparently, I'm not worthy of my geek club membership. WTF is "Over 9000"?

    5. Re:Oblig. by Thexare+Blademoon · · Score: 1

      So, complaining about mod decisions is the latest addition to the list, eh? If I didn't know any better, I'd say God doesn't like kittens. But he'd probably kill a kitten for that, too.

    6. Re:Oblig. by Anonymous Coward · · Score: 1, Informative

      IT'S OVER NINE THOUSAND! is a meme started from the annie may Dragon Ball Z, where characters would use scouters to detect power levels. It was cuntpasted many a time for the win. No topic goes without it. It's worth noting that in the original man gay, Vegeta noted Goku's power level as being "over 8000", "9000" is a product of Funimation Faggotry.

      From: http://www.encyclopediadramatica.com/9000

    7. Re:Oblig. by cheater512 · · Score: 2, Funny

      Oh nice work there. He just killed another one. :P

    8. Re:Oblig. by lantastik · · Score: 2, Funny

      IT'S OVER NINE THOUSAND! is a meme started from the annie may Dragon Ball Z, where characters would use scouters to detect power levels. It was cuntpasted many a time for the win. No topic goes without it. It's worth noting that in the original man gay, Vegeta noted Goku's power level as being "over 8000", "9000" is a product of Funimation Faggotry.

      From: http://www.encyclopediadramatica.com/9000 Cuntpasted? Is that what the kids are doing now-a-days?
    9. Re:Oblig. by Gideon+Fubar · · Score: 2, Funny

      I wish i could metamoderate this '+1 Funny'. Oh teh irony.

      --
      http://www.xkcd.com/354/
    10. Re:Oblig. by Anonymous Coward · · Score: 0
    11. Re:Oblig. by Anonymous Coward · · Score: 0

      Oh nice work there. He just killed another one. :P Sorry about that...

      Uh, I don't suppose you could hand me a tissue?
    12. Re:Oblig. by phexitol · · Score: 1

      Every time God kills a kitten, I kill two puppies, and kick an infant in the stomach.

  2. Another oblig by esocid · · Score: 4, Funny

    It's a trap!

    --
    Absolute power corrupts absolutely. indymedia
    1. Re:Another oblig by Anonymous Coward · · Score: 0

      All your websites are belong to us!

    2. Re:Another oblig by LMacG · · Score: 5, Funny

      Or for us older folk:

      You are in a maze of twisty little web pages, all alike.

      --
      Slightly disreputable, albeit gregarious
    3. Re:Another oblig by TaoPhoenix · · Score: 2, Funny

      Do we get eaten by a grue?

      --
      My first Journal Entry ever, in 8 years! http://slashdot.org/journal/365947/aphelion-scifi-fantasy-horror-poetry-webzine
    4. Re:Another oblig by bartosek · · Score: 1

      It's a trap! Get an axe!
    5. Re:Another oblig by LMacG · · Score: 2, Funny

      Only if it's pitch dark.

      --
      Slightly disreputable, albeit gregarious
    6. Re:Another oblig by newr00tic · · Score: 1

      It's bright, you insensitive clod!

      --
      A horse can't be sick, you know, even if he wants to.
    7. Re:Another oblig by Bilbo · · Score: 1

      ... and you've turned off your flashlight (or let the batteries run out).

      --
      Your Servant, B. Baggins
  3. Including Slashdot? by davidwr · · Score: 4, Insightful

    Maybe not today, but tomorrow?

    Seriously, it's time to seriously sandbox web browsers and have "no extensions" by default with overrides on a per-page, per-session basis allowed.

    In addition to sandboxing, browsers should ship with NoScript or equivalent functionality built-in.

    --
    Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
    1. Re:Including Slashdot? by CRCulver · · Score: 5, Insightful

      In addition to sandboxing, browsers should ship with NoScript or equivalent functionality built-in.

      Most of the sites that most of the average public uses are heavy on Javascript. A web browser shipped without support for JS by default is not going to win many users.

    2. Re:Including Slashdot? by Anonymous Coward · · Score: 1, Interesting

      How about a pre-shipped white list. I know know there is whole bit of politics with who gets on the whitelist.

    3. Re:Including Slashdot? by Anonymous Coward · · Score: 2, Informative

      > In addition to sandboxing, browsers should ship with NoScript or equivalent functionality built-in.

      You mean like all the browsers of the Mozilla series do? NoScript is just a GUI exposing the Mozilla Security Policies, which have been available via prefs.js since ever. An older one is "Policy Manager" , and the lack of a GUI is even a long term Bugzilla entry.

      And yes, the NoScript guys intentionally create the impression that their work is something new.

    4. Re:Including Slashdot? by davidwr · · Score: 3, Interesting

      Far better is a mechanism where content from one server can be authenticated by another server.

      For example, if http://www.foo.bar/ served up index.html, and http://authenticator.foo.bar/ served up an md5 hash based on its copy of index.html, an attacker would have to compromise both servers to fool the checksum.

      This works well for static content. For dynamic content each piece would have to be checked independently. There are also other serious issues that would have to be worked out.

      Your web browser could treat unauthenticated content as untrustworthy even if the site was otherwise trusted by the user.

      --
      Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
    5. Re:Including Slashdot? by MttJocy · · Score: 2, Informative

      If you read TFA not very slashdot I know, but it does say that several of the sites were what would normally be considered trusted and thus could likely end up on such a whitelist so it would hardly protect you against situations like this where trusted websites have been owned by a malware attack themselves.

    6. Re:Including Slashdot? by element-o.p. · · Score: 1

      chroot firefox? Hmmm...I wonder how that would work. I might have to give it a shot :)

      --
      MCSE? No, sir...I don't do Windows. Yes, I am an idealist. What's your point?
    7. Re:Including Slashdot? by Yoshimetso · · Score: 1

      Firefox 3 has NoScript as a built-in feature ... ;)
      http://extremesecurity.blogspot.com/

    8. Re:Including Slashdot? by FLEB · · Score: 2, Insightful

      I suppose I'd give them credit, if nothing else but for the initiative. A commonly-desired behavior isn't much of a "feature" if you have to dig around raw un-user-documented prefs to activate it.

      --
      Information wants to be free.
      Entertainment wants to be paid.
      You just want to be cheap.
  4. We should make vbscript the standard... by syntaxeater · · Score: 5, Funny

    ...then we wouldn't be having these problems.

    1. Re:We should make vbscript the standard... by IBBoard · · Score: 2, Funny

      Yeah, because all of the sane webmasters would have quit or killed themselves and the insane ones would be creating pages that no-one would want to visit!

    2. Re:We should make vbscript the standard... by null.account · · Score: 1

      That must be how Angelfire was created.

  5. more informative article here by esocid · · Score: 3, Informative
    The name for the rootkit is random js toolkit which seems pretty uninventive to me.

    The random js attack is performed by dynamic embedding of scripts into a Web page. It provides a random filename that can only be accessed once.
    So does the infected computer then inject something into websites the user visits or is that done by whoever designed this little rootkit?
    --
    Absolute power corrupts absolutely. indymedia
  6. The Question Webmasters Have Is... by ausoleil · · Score: 5, Insightful

    ...how do we check our sites to ensure that this code has not been planted. The article gives no clue at all. It doesn't even identify if is platform or technology specific, etc. Just that someone else has set up a huge botnet.

    Even sysadmins and webmasters that use best practices and diligently patch, etc. can be gotten because there are always undisclosed holes that are utilized. In fact, were I in that game and I figured out something to defeat security, it would keep it under my ragged black hat and never share that info.

    1. Re:The Question Webmasters Have Is... by whitehatlurker · · Score: 3, Interesting
      See the posting immediately previous to yours.

      Yes, TFA is sparse on the details, but if this is the attack, it is detected by several anti-virus packages.

      That rootkit is very stealthy. It might most easily be detected by watching your httpd server logs for random javascript files being served. Some details here.

      Note: I don't know that the above is the exploit described in TFA. I believe this subject was discussed earlier on slashdot. It was in The Reg as well.

      --
      .. paranoid crackpot leftover from the days of Amiga.
    2. Re:The Question Webmasters Have Is... by kesuki · · Score: 3, Interesting

      the funny thing is this isn't even the worst thing I've seen black hats use. There is this NASTY little exploit in windows that lets a CD-ROM be used to install automatic updates, when automatic updates ARE DISABLED.. think about this a little a cd-rom, CD-r, DVD-r, BD-R so what do you use to back up your data? blank dvds? did you ever notice that a disc left open 'gained' an extra session, somehow some where?
      BAM huge exploit.. it's the one that got me. i was tied up for weeks trying to figure ways around this nasty virus, and how to not loose all my data... i had no internet and the dang root-kit kept coming back (there were flaws in the root-kit, that caused 'bugs' the big 3 are, 1. a recurrent error in chkdsk where windows keeps complaining about the volume bitmap being corrupted. This is not as reported, a flaw in chkdsk, but something the Root-kit does constantly to 'make all it's infected files completely invisible to rootkit and virus scanners' the only way to scan for those files, is to put the hard drive into a linux machine and 'find' the missing files you can detect the problem in windows though, you navigate to your
      System Volume Information\_restore{(long number here)}\RP1 the RP1 folder is supposed to contain sequentially numbered temporary files, that are never deleted by normal means... so if you spot a 'numerical gap' in the files listed, you have the root-kit, to prove it pop the drive in a linux machine(or live cd) and the 'missing' numbered files are there, not deleted, not invisible, just 'not in the volume file bitmap' that's the easiest way to detect it, the second and third ways are less scientific, the second way I've detected it is by playing full screen games for many hours straight. if randomly over the course of 2-4 days the desktop shows in mid game for no reason... you have the root kit. sometimes it happens 3-5 times a day, but not always. the third indication doesn't always happen, but sometimes, the root-kit does something wrong, and autoplay gets disabled. usually this is related to frequent dvd movie usage. autoplay will still work on usb drives, but no longer on any optical drives... it's very wierd. in one case, it even screwed up the system so bad that '3 programs' installed on the system would 'set the default screen saver/power management settings back to their original windows defaults every 2 seconds' one of these programs was VLC media player, and frankly trying to watch a movie when the screen goes black every 20 minutes is ANNOYING...

      if you have any of the above mentioned symptoms i'd recommend grabbing a live cd linux disc, and mounting the hd and looking in your System volume information folders for signs of files that are only readable under linux.

    3. Re:The Question Webmasters Have Is... by Anonymous Coward · · Score: 1, Funny

      if you have any of the above mentioned symptoms i'd recommend grabbing a live cd linux disc...and install Linux

      Fixed that for you. ;)

    4. Re:The Question Webmasters Have Is... by kesuki · · Score: 1

      this is why i love slashdot lol

    5. Re:The Question Webmasters Have Is... by Uncle+Op · · Score: 2, Informative

      The Register offered one way to see the list:

            http://www.theregister.co.uk/2008/03/13/trend_micro_website_infected/

      The list is over 23,000 pages:

            http://www.l.google.com/search?hl=en&q=%22script+src%3Dhttp%3A%2F%2Fwww.2117966.net%2Ffuckjp.js%22&btnG=Google+Search&aq=f

      I haven't counted the Google-provided list. In theory some of those sites/pages have already been cleaned up, and they are reported 'cuz that was the last time Google spidered them.

  7. Time to Cut China Off of Our Internet by zibix · · Score: 0

    Isn't it about time to just isolate china for all this activity? Can't we just start banning whole ranges of IP addresses the way ISP's do?

    1. Re:Time to Cut China Off of Our Internet by billcopc · · Score: 3, Insightful

      I've been saying (and doing) this for years. China, South Korea, Malaysia, some parts of Russia... It sucks for them, but until their Governments/ISPs clean up the network, banning entire IP blocks is one of the better defenses against these malware floods. I figured it out while studying IDS logs a while ago, and noticed 98-99% of all exploit scans were coming from those countries. I do feel sorry for the good people who are getting blacklisted on behalf of their shit-flinging neighbours, but part of me wants them to get pissed off and do something about it, whether it's complaining to their ISP / political figure, or even just spontaneously beating the shit out of that sketchy kid selling burnt movies on the corner.

      Raising awareness is the first step toward solving a social problem like this. I used to drop packets at the router, but now I redirect them to an informational page explaining precisely why they're being blocked, with links to virus and spyware cleaners. That's if they weren't trying to find phpMyAdmin vulnerabilities, those guys I give a big colorful F.U. page, and if they ever invent the remote boxing glove, I'll add a trigger for that too!

      --
      -Billco, Fnarg.com
  8. Great Threat Research by metalman · · Score: 5, Insightful

    "Often you hear warnings about not going to untrusted sites," said Craig Schmugar, threat researcher at McAfee Avert Labs... That is good advice, but it is not enough. Even sites you know and trust can become compromised."

    In the old days it was easy to avoid malicious sites. Now even your neighbor could be the terrorist... err..I mean.. even sites you know and trust can become compromised.

    At least this threat researcher offered a calm analysis with plenty of advice about how to avoid such attacks without recoiling from the web in fear.

    MUST BUY MCAFEE...

    1. Re:Great Threat Research by myspace-cn · · Score: 0

      Nice analysis all the way up until the word terrorist.
      Just goes to show how brainwashed the American Citizens are by the corporate fascist media.

      Please stop spreading this fake fear to further erode our civil rights.

      If I setup a domain and website and keep my scripts updated and don't run a bunch of stupid ass modules, and I still get compromised, that does NOT make me a fucking terrorist.

      Also, your comment about "MUST BUY MCAFEE..." is wrong, you can get mcafee free, use the DOS version and manually update it, in fact it's easy to script a VB6 script up to control the whole show via a GUI without paying a cent.

  9. Wait, so we know the physical location... by Bryansix · · Score: 1

    of the server that is owned and run by the criminals. Isn't this what Tactical Nuclear Weapons were designed for?

    1. Re:Wait, so we know the physical location... by asuffield · · Score: 1

      Isn't this what Tactical Nuclear Weapons were designed for?


      No. Killing them that way is not slow and painful enough.
    2. Re:Wait, so we know the physical location... by mjwx · · Score: 2, Funny

      Isn't this what Tactical Nuclear Weapons were designed for?
      No. Killing them that way is not slow and painful enough.
      But nuking them from orbit is the only way to be sure.
      --
      Calling someone a "hater" only means you can not rationally rebut their argument.
    3. Re:Wait, so we know the physical location... by myowntrueself · · Score: 1

      Isn't this what Tactical Nuclear Weapons were designed for?

      Good point.

      Of course the only sane way to clear the entire internet of all malware of any kind...

      is to explode many nuclear weapons in orbit thus frying most of the electronics on the planet.

      Lets call that "Plan B".

      --
      In the free world the media isn't government run; the government is media run.
  10. It is pitch black. by circletimessquare · · Score: 5, Funny

    You are likely to be eaten by a script kiddie.

    --
    intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
    1. Re:It is pitch black. by irieiam · · Score: 1

      I not only actually lol'd but posted to boot!

      --
      hmmmm
  11. A number. by Hatta · · Score: 1

    What number? One? two? 17? 8000?

    --
    Give me Classic Slashdot or give me death!
    1. Re:A number. by Bryansix · · Score: 0, Offtopic

      Patriotism can be thinking that your form of government is better that anothers or that your implementation of it is better. This kind of patriotism has nothing in common with racism. This kind of patriotism is about ideas and ideologies.

    2. Re:A number. by d3ac0n · · Score: 1

      You do know that you are replying to his signature, right?

      That said, you are otherwise correct.

      --
      Official Heretic from the "Church of Global Warming". Proven right thanks to whistle blowers. AGW = Flat Earth Theory
    3. Re:A number. by Bryansix · · Score: 1

      Ya, I am aware. I just needed to respond to it.

    4. Re:A number. by Hatta · · Score: 1

      Racism can be thinking that your race or culture is better than another's. Believing that, for instance, american democracy is inherently better and more free than other democracies isn't really any different than believing that white people are inherently more civilized than others. I don't understand the distinction you're trying to make.

      --
      Give me Classic Slashdot or give me death!
    5. Re:A number. by Bryansix · · Score: 1

      One has to do with ideas which can change and be changed by either party. The other is state you are born into and can't be changed.

    6. Re:A number. by w0rd · · Score: 1

      Actually, you're incorrect. When you speak of believing that a particular culture is better than another, that's ethnocentrism. Racism is application of standards based only on race, not government.

    7. Re:A number. by Hatta · · Score: 1

      I don't understand, people are born racists?

      --
      Give me Classic Slashdot or give me death!
    8. Re:A number. by Bryansix · · Score: 1

      No, people are born with a race. Therefore arguing that one race is supierior to another is pointless because it's not like I can say "well being white sucks so I'll change to be asian instead". However with Patriotism if you talk to somebody who promotes the monarchy and they see democracy and like it then they can change what they are supporting based on the facts.

      Futhermore a government is just a group of people who make policy and rule a certain way. If yours does so honorably (for the most part) and you helped elect and be a part of the process then why not be proud?

    9. Re:A number. by Hatta · · Score: 1

      People are born American too. I'd argue that if you convince a patriotic american that the british government is superior, they're not really patriotic anymore. Similarly, if you convince a klan member that there's nothing fundamentally wrong with the african race, he's not really racist anymore.


      Futhermore a government is just a group of people who make policy and rule a certain way. If yours does so honorably (for the most part) and you helped elect and be a part of the process then why not be proud?


      Races are just a group of people who look and act a certain way. If yours does so honorably for the most part, why not be proud?

      By your reasoning there's nothing wrong with white pride, because white people do less time in jail than black people.

      --
      Give me Classic Slashdot or give me death!
    10. Re:A number. by Bryansix · · Score: 1

      You are confusing race and culture.

    11. Re:A number. by Hatta · · Score: 1

      I'd say racists do the same thing, so my comparison stands.

      --
      Give me Classic Slashdot or give me death!
  12. It's called a hosts file by Bryansix · · Score: 1

    You can just have anything that tries these IP addresses go to a blackhole.

    1. Re:It's called a hosts file by Se7enLC · · Score: 1

      WHAT ip addresses? This article gives NO information about the attack, doesn't mention any of the sites that were compromised, doesn't say what information is being sent or anything.

      It may as well have been just the headline.

    2. Re:It's called a hosts file by Se7enLC · · Score: 3, Informative

      This was the information that should have been included in the article. A link to the McAfee Avert Labs Blog:

      http://www.avertlabs.com/research/blog/index.php/2008/03/12/another-mass-attack-underway/

    3. Re:It's called a hosts file by RayMarron · · Score: 1

      Hosts files don't work on IP addresses, only hostnames, and they don't accept wildcards. The drawing board patiently awaits your return. ;)

      --
      ON DELETE CASCADE
  13. NoScript is a no-go by ivan256 · · Score: 5, Insightful

    Why not just disallow redirection and loading of off-domain/off-host data from scripts?

    Disabling scripts entirely disables dangerous behavior, sure... But is also disables lots of desirable functionality that most people want.

    1. Re:NoScript is a no-go by Hatta · · Score: 1

      That would strongly encourage web designers to run their code on their own machines where it belongs. That's very much a desired effect in my book.

      --
      Give me Classic Slashdot or give me death!
    2. Re:NoScript is a no-go by v(*_*)vvvv · · Score: 1

      This is a good step, but wouldn't hackers just be able to work around this too? eg. just put the bad stuff on the same host, etc.

      This precaution is currently not enforced, and hence current attacks don't consider it, but if it were enforced, then I have a feeling hackers would just find another way, just as they have done to create the current exploitations.

      It is disturbing that plugins such as real player and acrobat can be exploited, since often times an old plugin that is no longer in use will never get updated, and a lot of "smart" users will still have backdoors available on their system just for not updating something they no longer use or want.

    3. Re:NoScript is a no-go by ivan256 · · Score: 4, Insightful

      Interactive code can't be run on the server and still be responsive enough for a good user experience.

      Web pages aren't just static content anymore. And other than stuffy people who don't want to let go of the paper document, or paper document + hyperlink models, nobody really thinks they *should* be static content either.

    4. Re:NoScript is a no-go by The+End+Of+Days · · Score: 1

      Once again, I'm amazed at the tendency towards Ludditism on what is ostensibly a tech site.

    5. Re:NoScript is a no-go by sabt-pestnu · · Score: 1

      You seem to be blithely disregarding issues of trust. And bandwidth. And disability. (Just how well do those interactive pages work with page readers?)

      For me, when a company puts up a page that is utterly useless unless you run flash, or javascript, that's a company I turn away from.

      Maybe I'm just one of those "stuffy people" you mention. But even if I am, it doesn't mean I don't have legitimate grievances.

    6. Re:NoScript is a no-go by ivan256 · · Score: 1

      I don't think I'm ignoring the issues of trust... I think you just didn't read the whole thread.

      I think the bandwidth issue was pretty core to my argument. Dynamic content can, and should, use less bandwidth than static content to obtain the same level of interactivity.

      I'm also not ignoring disability. I just don't think we should say "the web is text" and be stuck with that model forever in order to cater to a lowest common denominator. The fact of the matter is that the web has grown into an application platform. The "screen reader" mentality needs to evolve, because what's broken there is the assumption that the web provides consumable content and not interactive applications. The web doesn't need to be held back because of that.\

      Lastly, I think you're limiting your view of the situation severely when you say "when a company puts up a page that is utterly useless unless you run flash, or javascript, that's a company I turn away from". Corporate home pages are among the least valuable content on the internet, both in terms of usefulness to end users, and in terms of revenue creation. They should be ignored entirely in discussions about the future of web technology.

    7. Re:NoScript is a no-go by FLEB · · Score: 1

      Well, if it was absolutely locked down, about the worst an attacker could do would be to create a lookalike phishing site on the same host. Unfortunately, properly locking that sort of thing down may need to go as far as disallowing off-site IMG tag references, as well as JavaScript and the like.

      --
      Information wants to be free.
      Entertainment wants to be paid.
      You just want to be cheap.
  14. Pages != Sites by mythosaz · · Score: 2, Interesting

    10,000 pages != 10,000 sites. ...unless the sites each only have one page.

  15. What's vulnerable? by Badbone · · Score: 1

    The article doesn't make it clear. This is a vulnerability in Windows, or in IE?

    --
    It can be go tiem now plees?
    1. Re:What's vulnerable? by symbolset · · Score: 3, Funny

      The article doesn't make it clear. This is a vulnerability in Windows, or in IE?

      Yes.

      --
      Help stamp out iliturcy.
  16. Obligatory criticism of the use of 'obligatory' by spun · · Score: 4, Funny

    From now on, whenever someone posts something they claim is 'obligatory,' we should point out, "You keep using that word. I do not think it means what you think it means." Dueling memes, what fun!

    --
    - None can love freedom heartily, but good men; the rest love not freedom, but license. -- John Milton
  17. Impressive! by jgarra23 · · Score: 2, Funny

    It reminds me of that Eddie Izzard bit in "Dress To Kill" where he talks about how we as a society abhor serial killers but when we start to get even into the hundreds or thousands or millions we're like, "well done!" that's impressive! In an odd morbid sort of way... I mean, you hear about worms and crap like that or the oddball who hacked A system... but to create a "maze" of over 10k sites?? Well, uh... impressive!

    1. Re:Impressive! by IBBoard · · Score: 4, Funny
      And for anyone who is unfortunate enough not to know Eddie Izzard or who hasn't seen "Dress to Kill", the section is:

      And Hitler ended up in a ditch, covered in petrol, on fire, so, that's fun! I think that's funny, 'cause he was a mass-murdering fuckhead. And that was his honeymoon as well! Double trouble!

      "Eva, let's marry."

      "Where should our honeymoon be?"

      "Well, in a ditch, covered in petrol, on fire. I've already arranged it upstairs."

      "Oh, how romantic, Adolf."

      "Yes, I thought!"

      Fun! What a bastard! And he was a vegetarian, and a painter, so he must have been going, "I can't get the fucking trees... Damn! I will kill everyone in the world!"

      And he was a mass-murdering fuckhead, as many important historians have said. But there were other mass murderers that got away with it! Stalin killed many millions, died in his bed, well done there; Pol Pot killed 1.7 million Cambodians, died under house arrest at age 72, well done indeed! And the reason we let them get away with it is because they killed their own people, and we're sort of fine with that. "Ah, help yourself," you know? "We've been trying to kill you for ages!" So kill your own people, right on there. Seems to be... Hitler killed people next door... "Oh... stupid man!" After a couple of years, we won't stand for that, will we?
      Pol Pot killed 1.7 million people. We can't even deal with that! You know, we think if somebody kills someone, that's murder, you go to prison. You kill 10 people, you go to Texas, they hit you with a brick, that's what they do. 20 people, you go to a hospital, they look through a small window at you forever. And over that, we can't deal with it, you know? Someone's killed 100,000 people. We're almost going, "Well done! You killed 100,000 people? You must get up very early in the morning. I can't even get down the gym! Your diary must look odd: "Get up in the morning, death, death, death, death, death, death, death - lunch- death, death, death - afternoon tea - death, death, death - quick shower..."

      So I suppose we're glad that Pol Pot's under house arrest... you know, 1.7 million people. At least he - we know where he is - under house arrest! Just don't go in that fucking house, you know? I know a lot of people who'd love to be under house arrest! They bring you your food... "Just stay here? Oh, all right. (singing laconically ) Have you got any videos?" You know, you just sit there all day... And Pol Pot was a history teacher. And Hitler was a vegetarian painter. So... mass-murderers come from the areas you least expect it. I don't know how the flip comes over, but it happens.


      http://www.auntiemomo.com/cakeordeath/d2ktranscription.html#history
  18. Mod parent informative by davidwr · · Score: 1

    At least, it's news to me.

    --
    Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
  19. Isn't this the obvious result .... ? by King_TJ · · Score: 4, Insightful

    First, people figured out that in order to hijack people's PCs for "bot net" purposes, they could try to trick them into installing a program that would slip it in, along with the desired program being loaded. But along came all the "spyware cleaner" packages, that could identify and remove the malware, leaving the originally desired software installed and running.

    So the next trick was to try to make removal difficult or impossible by infecting a PC with a "downloader virus". That way, the virus itself would try to avoid detection, but silently download and install spyware from various sites around the world. The user might figure out he/she was infected with the spyware and try to clean it with a remover, but it would keep coming right back, as the original virus kept re-downloading the stuff.

    This led to popular anti-virus packages starting to blur the lines between spyware and virii (in cases where the company in question didn't have a specific anti-spyware product ready to sell you). They'd just attempt to clean ALL of the stuff up. Others wanted you to run 2 distinct programs together to protect against both types of threats. In any case, all of this confused a lot of people -- but also made them catch on that a lot of this stuff appeared to be impossible to clean ONLY because of that "downloader trojan horse" trick.

    After they started "wising up" and unplugged their Inet connections while doing all the virus and spyware removal ... the "evil doers" had to escalate things further.

    The current ploy of injecting the stuff from normally benign web sites is pretty much the "next logical step" for them. Doesn't surprise me a bit. I think we'll continue to see more and more of this, too. After all, this attack has several vectors. DNS server entries could be spoofed, redirecting people to fake sites. Web servers with security flaws could be compromised, and modified code loaded directly onto them. Or maybe, legitimate sites will unwittingly host infected ad banners down their pages, paid for by "advertisers" with motives other than really caring if you view the ad's visible content?

  20. can anyone tell me the checksum of the code? by 3seas · · Score: 5, Informative

    I discovered my site had a directory and just under 2500 pages added to it. The directory and file dates are January 9th 08 and every one of the html files has the same script code in it. My research turned up indication of two mass site hacks in January.

    A google search for threeseas.net/blogger/log/cache/ (cache being the directory that contained the files [past tense]) shows up about 4500 site pointing to one of the files in that directory. Some of the findings are even sourceforge sites and you can tell they have been hacked as well. In other words there are a lot of hacked sites besides mine.

    I notified google this morning and my host has already removed the files from my site as the owner and group were set that I couldn't do this myself.

    anyways rather that posting the code, a check sum would be better of the code starting with teh word "function" to the end of the code.

    1. Re:can anyone tell me the checksum of the code? by element-o.p. · · Score: 3, Informative
      From TFA:

      Signaturing a dynamic script is not effective. Signaturing the exploiting code itself is also not effective, since these exploits are changing continually to stay ahead of current zero-day threats and available patches.

      Sounds like it would be rather difficult to get a checksum for you, sorry.
      --
      MCSE? No, sir...I don't do Windows. Yes, I am an idealist. What's your point?
    2. Re:can anyone tell me the checksum of the code? by hesaigo999ca · · Score: 1

      Actually , i think he meant a checksum for his site and all its content, not to end up one day with diff. pages online without knowing about it. Of course the checksum verificator could obvisously not be hosted on the same server....and it could send you an email if any content on your wesite has changed. I guess a reverse google cache of sorts...

  21. Re:Win A_Week_With_A_Hooker by Anonymous Coward · · Score: 0

    What are you trying to highlight in the word patriot? If it's the word 'riot,' I suggest that you stop capitalizing the initial P, because it just comes out as PRIOT, which isn't... you know... anything.

    Just a heads up, there, Dingus.

  22. Re:Isn't this the obvious result .... ? by d3ac0n · · Score: 2, Insightful

    It makes you wonder what the next logical step after this one is, doesn't it?

    Personally, I suspect that we will start seeing DNS cache and Route poisoning attempts become much more commonplace. Particularly after the whole "YouTube gets 'knocked offline' because of an improper route broadcast by a piss-ant totalitarian country" issue we had in recent weeks.

    I would bet good money that there were criminals rubbing their hands together with glee over the idea of dumping MILLIONS of users to a malware server simultaneously. Or using that type of exploit as a blackmail tool.

    What do you think the next logical step is?

    --
    Official Heretic from the "Church of Global Warming". Proven right thanks to whistle blowers. AGW = Flat Earth Theory
  23. Save us by DiscoLizard · · Score: 5, Funny

    McAfee Avert Labs described the assault as "one of the largest attacks to date of this kind".

    The attack serves as a reminder that even trusted websites can be malicious, McAfee warned.

    "Often you hear warnings about not going to untrusted sites," said Craig Schmugar, threat researcher at McAfee Avert Labs."That is good advice, but it is not enough."

    McAfee Avert Labs first spotted the attack on 12 March.



    I wonder who can sell us some sort of software to guide us out of this maze of evil webpages?

  24. series of tubes by overcaffein8d · · Score: 1

    series of twisted, tangled, and altogether screwed up tubes

    --
    Those of us who think they know everything annoy those of us who do.
  25. If this is true... by JudgeFurious · · Score: 1

    Then it would be like 911 times a thousand!

    That's right. 911,000!

    --
    Appended to the end of comments you post. 120 chars.
  26. Re:Dueling memes.. by Gideon+Fubar · · Score: 3, Funny

    You're doing it wrong; the internet is for porn.

    --
    http://www.xkcd.com/354/
  27. Oh No! My Pwecious Mac! by CheeseburgerBrown · · Score: 0

    Oh...wait.

    Nevermind.

    Good luck, lads.

  28. Comment removed by account_deleted · · Score: 1

    Comment removed based on user account deletion

  29. Meme? Absolutely i for internet savvy by Whiteox · · Score: 1

    Would someone please identify the person(s) who are trying to make 'meme' another buzzword?
    I would appreciate their email addy if you can manage that as well.
    I've had to put up with 'Absolutely' in the 90's and now 'meme' for the next decade, as well as iAddyourwordhere.... for just too long.

    --
    Don't be apathetic. Procrastinate!
  30. New (?) redirect attack blogs??? by siglercm · · Score: 1

    Hey,

    I've noticed through some search terms found on Google Trends that there are bunches of apparently fake "blogs" on blogspot. Here's an example:

    http://forniagill.blogspot.com/2008/03/what-time-is-it.html

    Clicking on the "what time is it scandal" "video" redirects toward a site Firefox flags for malware downloading (even though I'm on Linux -- thank you 'Fox :).

    There seem to be hundreds of these random malware blogs out there. Is this an old phenomenon? Thx.

    --
    sigfault (core dumped)
    1. Re:New (?) redirect attack blogs??? by cswiger · · Score: 1

      Good find. That site tries to persuade you to run this "WebVideoSetup.exe" program, which is a Win32 GUI PE according to file, and a quick check of strings suggests it creates a remote shell and contacts IP 78.129.166.25. Virus scanners identify it as "DR/Delphi.Gen" or "Mal/Heuri-E, Mal/DelpDldr-E".

      --
      "The human race's favorite method for being in control of the facts is to ignore them." -Celia Green
  31. THANKS A LOT, "SECURITY"! FOR NOTHING! by Jane+Q.+Public · · Score: 3, Insightful

    If McAfee (and others) really wanted to solve this "problem", then they would have to do little more than TELL US what the domain name, IP address, etc. of the offending server was!

    If we knew that, we could reject any requests from there at the application OR server level, or even both.

    And when they move to a new server, same thing. Of course, it would be helpful to have signature(s) of the code as well, but let's STAMP OUT the immediate problem, then worry about potential problems.

    I know the "security" companies are commercial interests. But there are times when responsibility toward your community trumps making an enormous profit.

    1. Re:THANKS A LOT, "SECURITY"! FOR NOTHING! by Yoshimetso · · Score: 1

      Hi, You can visit http://malwaredomains.com/ and get the DNS/HOSTFILE blacklists and use them to prevent local machines from accessing these domains. Check my post here about this technique: http://extremesecurity.blogspot.com/2008/03/dns-redirection-techniques.html
      Good Luck
      extremeSecurity.blogspot.com

    2. Re:THANKS A LOT, "SECURITY"! FOR NOTHING! by Yoshimetso · · Score: 1

      System admins should be ready to prevent their clients from getting exploited and redirected to those malicious domains. check here: http://extremesecurity.blogspot.com/2008/03/iframe-attacks-actions-to-be-taken.html

    3. Re:THANKS A LOT, "SECURITY"! FOR NOTHING! by Yoshimetso · · Score: 1

      System admins should be ready to prevent their clients from getting exploited and redirected to those malicious domains. check here: http://extremesecurity.blogspot.com/2008/03/iframe-attacks-actions-to-be-taken.html

  32. ok, so how do I block China by speculatrix · · Score: 1

    so, given I rarely if ever need to see Chinese servers, is there a list which I can use to generate a firewall access list and block all outbound access to Chinese servers?

  33. Re:Isn't this the obvious result .... ? by MrMacman2u · · Score: 1

    I think the next step should be; EVERYONE Install Linux or Buy a Mac. At once. Problem Temporarily solved and time that will be needed in order to implement the NEXT next logical step will be bought. Of course, the NEXT next logical step is to kill every last one of these bottom feeding scum suckers in the face.

    --
    This signature is lame.
  34. But... by Tastecicles · · Score: 1

    ...do any of these exploits specifically target Linux? If not, then this is a nonevent for me.

    --
    Operation Guillotine is in effect.
    1. Re:But... by riondluz · · Score: 1

      If you checked out any of the above links, then you would see that it definitely affects linux hosts. From what i was able to glean, the problem stems from infected PC's that contain usernames and password info for their ftp account on a linux box From there a payload is delivered to the linux box that inserts a small httpd into the kernel and covers its tracks. So yes, its a linux rootkit, but only doable if the linux host is running ftpd (pro/pure?) as a means for letting remote users access the filesystem.
      At least, that's my take.

      --
      resist propaganda
  35. Re:Oh No! My Pwecious Mac! by Yvan256 · · Score: 1

    Because, of course, as OS X marketshare increase, its security will weaken... Oh wait that doesn't make any sense.