Results 1 to 5 of 5

 

Thread: Web infection targeting website’s FTP details

  1. #1
    heartinternet's Avatar
    Registered User

    Status
    Offline
    Join Date
    Apr 2009
    Posts
    83
    Thanks
    7
    Thanked 8 Times in 5 Posts


    Just a heads up about a particularly aggressive compromise using FTP information stored on local machines to spread itself...

    ScanSafe STAT Blog - ScanSafe STAT Blog - GumblarQ&A
    ScanSafe STAT Blog - ScanSafe STAT Blog - Google SERPs Redirections Turn toBots

    Thanks

    Matt
    Heart Internet

  2. #2
    Dynamoo's Avatar
    Mooooo

    Status
    Offline
    Join Date
    Dec 2003
    Location
    Somewhere in Bedfordshire
    Posts
    1,908
    Thanks
    5
    Thanked 60 Times in 43 Posts
    Some more on it here: Gumblar .cn Exploit - 12 Facts About This Injected Script | Unmask Parasites. Blog.

    They seem to indicate that it is spreading through weak ftp passwords. It's a tricky bugger too.
    Never email donotemail@WeAreSpammers.com

  3. #3
    Registered User

    Status
    Offline
    Join Date
    May 2009
    Posts
    3
    Thanks
    0
    Thanked 0 Times in 0 Posts
    It's not so much that it's attacking weak passwords as much as the original virus infects the PC and actually sniffs the FTP traffic and either grabs the username and password through the FTP traffic stream or modifies your code as it's being sent to your website.

    You see, FTP sends username and password as plain text so it's easily "sniffable". So you might have a real strong password, but it will still grab them, send them to a remote server where that server will then copy your website, modify the files and then reload your site.

    We've seen everything from .htm, .html, .js and .php files all infected with malscripts. Some sites we've cleaned had over 2,500 files infected with malscripts.

    Luckily we've been able to use regex expressions to find and remove the infectious malscripts.

  4. #4
    Dynamoo's Avatar
    Mooooo

    Status
    Offline
    Join Date
    Dec 2003
    Location
    Somewhere in Bedfordshire
    Posts
    1,908
    Thanks
    5
    Thanked 60 Times in 43 Posts
    It morphed over the weekend to martuz.cn, more info here: Martuz .cn - New Incarnation of the Gumblar Exploit. So What’s New? | Unmask Parasites. Blog.

    Yes, it does seem to harvest FTP credentials. I'm not sure what the PC infection is.
    Never email donotemail@WeAreSpammers.com

  5. #5
    Technophobe Geek

    Status
    Offline
    Join Date
    Jan 2005
    Location
    Cumbria, UK
    Posts
    805
    Thanks
    11
    Thanked 21 Times in 21 Posts
    From what I can tell, the PC infection is partly looking for FTP details to exploit sites and partly so they can adjust the users Google search rankings. Seen various reports of it replacing Adwords, and other links with dodgy stuff.

    For some reason it targets Adobe Flash and Reader exploits rather than the browser itself which seems like a bit of a roundabout way, but maybe that gets around FF and Chrome being more secure (in theory).

    Best solution seems to be to keep AV upto date to prevent FTP bit, and make sure Adobe update has run to prevent SERP alterations. Sure they could start doing other things if they wanted to rather than simply changing links.

    Trev



Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. UK and US Targeting.
    By firespin in forum Affiliate Marketing Lounge
    Replies: 0
    Last Post: 20-03-07, 02:05 PM
  2. My targeting affiliates....
    By shecyvicky in forum Affiliate Marketing Lounge
    Replies: 5
    Last Post: 07-02-07, 09:37 AM
  3. Geo Targeting
    By mickn88 in forum Affiliate Marketing Lounge
    Replies: 0
    Last Post: 31-01-07, 02:09 PM
  4. Geo-Targeting
    By Qui Gon Jinn in forum Media Coverage & PR Strategy
    Replies: 0
    Last Post: 12-11-03, 05:10 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
To Top

Content Relevant URLs by vBSEO 3.5.0 RC2