Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Java script exploit |
|---|---|
| Date: | Sun, 19 Feb 2006 19:00:44 +0100 |
gandalf@digital.net wrote:
Greetings and Salutations: I just receieved this exploit,
It is none, as others already have mentioned. I suppose you got it from one of the various "you received a postcard" mailings going round. It is basically a trampoline that will lead to a series of webservers that have been compromised which will redirect to each other (typically 2 or 3 steps) using frames, iframes or similar javascripts (they use the same basic en-/decoder, as far as I have seen). The last step, however (which is probably what triggered a trap on your system) is a piece of HTML that is using 3 or 4 different exploits to try to download and execute a variant of Haxdoor. The first two are trying to use ActiveX together with .chm bugs (not sure, if I should count them as two), the next utilizes some JavaApplet called " SandBoxEscape.class", while the fourth tries to exploit http://www.securiteam.com/windowsntfocus/6B00L2KEKW.html The binary that should have been downloaded was identified by virusscan.jotti.org as being - Bitdefender BehavesLike:Trojan.WinlogonHook (probable variant), - NOD32 a variant of Win32/Haxdoor - VBA32 Trojan-Downloader.Agent.84 (probable variant). Note, that only three of about a dozen Scanners installed on jotti identify the malware, as it seems to be modified. I have given a short description of what I've seen there in the german newsgroup de.comp.security.virus with MID slrndv299i.sp1.becka-news-nospam-2006-02@xeon.mcs.acs.uni-duesseldorf.de
Subject: You have received a postcard! Id: 7963
Ah. Good guess. Kind regards, Andreas Beck -- Andreas Beck http://www.bedatec.de/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Vulnerabilites in new laws on computer hacking, Craig Wright |
|---|---|
| Next by Date: | Re: Vulnerabilites in new laws on computer hacking, FocusHacks |
| Previous by Thread: | Re: Java script exploit, Jose Nazario |
| Next by Thread: | [ MDKSA-2006:040 ] - Updated kernel packages fix multiple vulnerabilities, security |
| Indexes: | [Date] [Thread] [Top] [All Lists] |