Affiliate Marketing
Forum Search

Reply
 
LinkBack Thread Tools Display Modes

  #1 (permalink)  
Old 26-04-08
Technophobe Geek
 
Join Date: Jan 2005
Location: Cumbria, UK
Posts: 482
Thanks: 0
Thanked 1 Time in 1 Post
trevHCS is an unknown quantity at this point
  nihaorr1.com ASP virus

Spotted a note about a forum being hacked from Granada in the travel section, but it looks like it's hitting rather wide and injecting itself into ASP sites with databases quite a lot.

There's a breakdown on this site (page 2+ is most useful):
Anyone know about nihaorr1

...but essentially if you're running IIS and ASP with MSSQL then this could be quite serious if you don't spot it coming in. According to Slashdot and F-Secure, there could be 500,000 servers affected, although I didn't think 500K people were daft enough to run Windows based servers.

There's a lot of confusing information on this currently as to exactly what it does, but in essence it seems that an encrypted query string or form input hits the site and tries to run an SQL type injection attack against the database. Due to the encryption and problems with ASP and MSSQL this isn't too easy to spot, so it effectively finds all the TEXT fields and adds some J/script code to those - presuambly on the assumption that some of them will be outputted to the screen.

The output is a series of J/script based iFrames which install a trojan on the users computer, which then tries to attack web sites with this virus. A bit like when that virus hit lots of PHPBB boards. Unfortunately like that one, it runs and pottentially hits very hard but doesn't seem to use Google to do the attacks. Presumably it only runs when it finds an ASP site to send it's injection by GET or POST.

It also seems it uses known problems with MSSQL and ASP to get in and do it's work so doesn't currently hit LAMP systems. I don't understand all the technical stuff about exactly how it gets in, but from what I can see it gets past quite a few security features so even having permissions on the tables might not always protect.

A few more bits on it:
Microsoft Security Advisory (951306): Vulnerability in Windows Could Allow Elevation of Privilege
Slashdot | 500 Thousand MS Web Servers Hacked


Final aim of this seems to be something to do with the Olympics in China, but it could easily be altered to destroy things with a DROP or TERMINATE, or of course just fill the tables with all kinds of illegal stuff. Just depends who gets hold of it.

Trev - running everything on LAMP
__________________
UK Hotel :: UK Cottage :: UK Attraction :: Mad Theories
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 26-04-08
John Jupp's Avatar
The New 'Arfur Daley
 
Join Date: Mar 2004
Location: Kent UK
Posts: 2,352
Thanks: 34
Thanked 40 Times in 30 Posts
John Jupp is an unknown quantity at this point
  Re: nihaorr1.com ASP virus

Virus Threat

I have answered it here. It's a SQL injection. No cure. Attacking booking, reservation and retail sites, attack emanating from Russia. Warning about this has been removed from the BBC news site. Obviously amassing customer payment details.
__________________
Read Our Blog, London/New York/San Francisco Affiliate Program Management - Contact Us
My Contact Details: Terrasip: 21100004227 @ terrasip.net Skype: john_jupp
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 26-04-08
Technophobe Geek
 
Join Date: Jan 2005
Location: Cumbria, UK
Posts: 482
Thanks: 0
Thanked 1 Time in 1 Post
trevHCS is an unknown quantity at this point
  Re: nihaorr1.com ASP virus

Looking further into this it appears the code at least one some versions is more related to getting exploits on peoples machines and server exploits as there are ones for AJAX through to Yahoo IM.

A bit worrying when large sites such as these are affected:

http://www.faststream.gov.uk [UK Civil Service]
http://www.n-somerset.gov.uk [UK Local Government]
http://www.umc.org [United Methodist Church]
http://www.oddbins.co.uk [Major UK wine retailer]

...and the classic http://www.safecanada.ca [Canadian National Security].

Most of those won't get too much, but Oddbins could be a real killer. There are quite a few listed on this site:
http://www.dynamoo.com/blog/index.htm

Trev

Edit: Meant to add this to the travel site thread, oh well.
__________________
UK Hotel :: UK Cottage :: UK Attraction :: Mad Theories

Last edited by trevHCS; 26-04-08 at 08:18 PM.. Reason: Stopping it doing annoying URL auto editing
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 26-04-08
tbp tbp is offline
Registered User
 
Join Date: Dec 2006
Posts: 1,999
Thanks: 0
Thanked 18 Times in 18 Posts
tbp is an unknown quantity at this point
  Re: nihaorr1.com ASP virus

Very interesting post about this below, which explains how it works and what it does:

Anyone know about www.nihaorr1.com/1.js? - IIS.net
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #5 (permalink)  
Old 27-04-08
Barry's Avatar
Typing with both fingers.
 
Join Date: Aug 2003
Location: In Fishguard with my lovely coracle.
Posts: 2,981
Thanks: 114
Thanked 26 Times in 19 Posts
Barry seems to know their stuff
  Re: nihaorr1.com ASP virus

Thanks for the heads up.



ta
__________________
Mirror Ten Ltd :: Free Codes :: HTC Touch HD
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
ZoneAlarm launches with zanox! Zanox Zanox 0 28-08-07 09:50 AM
Kama Sutra Virus Alert LeylaPCSS Merchant Promotions & Incentives 0 01-02-06 08:47 PM
ASP IPS Generator Barry Widgets, Coding, AJAX, PHP - Technology & Affiliate Marketing 1 26-09-03 08:27 AM


Affiliate Marketing RSS Feeds - Contact Us - Affiliate Marketing - Archive - Privacy Statement - Top

Content Relevant URLs by vBSEO 3.2.0 RC7