eWeek Security Watch
Advertisement
Advertisement
April 3, 2007 11:26 AM

Widespread ANI Attack Coming Out of Asia/Pacific



A large clump of sites in the Asia Pacific region are sporting embedded IFrames pointing to a site that's spreading ANI exploit code, Websense reported yesterday. An IFrame is an HTML element that makes it possible to embed an HTML document inside a main document.

The security firm's ThreatSeeker technology is tracking more than 450 unique compromised sites, most with all pages infected. The total of infected pages with exploit code links is tens of thousands. Websense is working with groups to get them taken down. Besides those sites, the 50-plus sites in this particular cluster all connect to the same host.

Websense's alert said the sites appear to be running blogs or message boards. Most of the sites contain embedded IFrames on all pages that lead to the set of sites hosting the ANI exploit, the alert said. The total number of pages is more than 500.

Were a user to connect to one of these feeder sites, that user would be redirected to two hosts of the exploit code. The hosts download and install a file called "ad.exe" which contains a password stealer that Websense says is not being detected by most antivirus companies.

Websense has screenshots of the sites here.

Microsoft has promised a patch for the animated cursor flaw today, jumping its normal Patch Tuesday cycle by a week in order to address the rising tide of exploit and customer concern. Meanwhile, eEye has updated its workaround in order to address the exploit's newfound ability to bypass its temporary patch.

TrackBack

TrackBack

http://securitywatch.eweek.com/cgi-bin/mte/mt-tb.cgi/10712

Post a Comment

 
 


RSS Syndication
Advertisement
Advertisement
Security Watch     Contact Us | Advertise | Site Map
Ziff Davis Enterprise

Ziff Davis Enterprise Home | Contact Us | Advertise | Link to Us | Reprints | Magazine Subscriptions | Newsletters
RSS Feeds | White Papers | ROI Calculators | Tech Podcasts | Tech Video |

Baseline | Careers | Channel Insider | CIO Insight | DesktopLinux | DeviceForge | DevSource | eSeminars |
eWEEK | LinuxDevices | Linux Watch | Microsoft Watch | Mid-market | Networking | PDF Zone |
Publish | eWeek Security | Strategic Partner | Web Buyer's Guide | Windows for Devices

Developer Shed | Dev Shed | ASP Free | Dev Articles | Dev Hardware | SEO Chat | Tutorialized | Scripts |
Code Walkers | Web Hosters | Dev Mechanic | Dev Archives | IT Marketplace | igrep

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2007 Ziff Davis Enterprise, Inc. All Rights Reserved. Security Watch is a trademark of Ziff Davis Enterprise, Inc. Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.

Ziff Davis Enterprise