Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Hackers, Scammers Hide Malicious JavaScript On Web Sites
TechWeb News ^ | October 20, 2005 | Gregg Keizer

Posted on 10/21/2005 2:23:35 AM PDT by Eagle9

click here to read article


Navigation: use the links below to view more comments.
first 1-2021-31 next last
The Websense PDF, referenced in the last paragraph, can be downloaded at the following link. On page 7 is an in-depth analysis of JS/Wonka.

http://www.websensesecuritylabs.com/resource/pdf/wslabs_wonka_analysis_oct05.pdf

1 posted on 10/21/2005 2:23:36 AM PDT by Eagle9
[ Post Reply | Private Reply | View Replies]

To: Eagle9

Organized Spam


2 posted on 10/21/2005 2:26:42 AM PDT by DannyTN
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9

Organized Spam


3 posted on 10/21/2005 2:26:42 AM PDT by DannyTN
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9

Thanks!
You know, an Iframe exploit can work completely invisibly.

It can be done to display a graphic without scroll bars, or even better, just stick an iframe in a page with a size of 1 pixel by 1 pixel. Then through this invisible window, one may sneak all kinds of nasty code!

There are also exploits using the embed command, flash could be used embedded with a payload delivered unseen.

The base command could also be used for mischief.


4 posted on 10/21/2005 2:40:06 AM PDT by Bon mots
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9

I just checked the example website used in the article and the nasty javascript code is still there. With javascript turned off I chased the tail all the way to the end (redirecting 4 to 5 times) and its all still there. You'd think that the webmaster for that site would have cleaned things up after having his site mentioned in this article.


5 posted on 10/21/2005 3:22:11 AM PDT by Avenger
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9
Three out of four of the sites found using JS/Wonka are hosted in the U.S.,

Once again, the USA leads in technical innovation! ;-)

But seriously, this is just another reason not to use IE. The ecommerce website that I run has seen IE usage drop off to under 50%.

6 posted on 10/21/2005 4:14:37 AM PDT by glorgau
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9

Thanks, good stuff.


7 posted on 10/21/2005 4:37:27 AM PDT by newsgatherer
[ Post Reply | Private Reply | To 1 | View Replies]

To: glorgau
But seriously, this is just another reason not to use IE. The ecommerce website that I run has seen IE usage drop off to under 50%.

Are you selling Apple hardware or some other self-selecting product?

This is from my commercial site, as of this minute:


Top 15 of 325 Total User Agents # Hits User Agent

1 5456 17.52% Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET

2 4628 14.86% Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)

3 1591 5.11% Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1

4 1239 3.98% Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)

5 1086 3.49% Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.10) Ge

6 892 2.87% Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1 7 791 2.54% Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)

8 631 2.03% Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.12) Ge

9 591 1.90% Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)

10 555 1.78% Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; MSN 9

11 519 1.67% Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.11) Ge

12 387 1.24% Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.8) Gec

13 374 1.20% Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; Hotba

14 356 1.14% Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/

15 353 1.13% Mozilla/5.0 (Windows; U; Windows NT 5.1; fr-FR; rv:1.7.12) Ge



8 posted on 10/21/2005 4:42:09 AM PDT by Gorzaloon
[ Post Reply | Private Reply | To 6 | View Replies]

To: glorgau

It doesn't matter what browser or operating system you use. JavaScript is standard, and all browsers are supposed to render it. This is all a browser exploit, and doesn't affect your machine at the OS level.


9 posted on 10/21/2005 4:46:34 AM PDT by proxy_user
[ Post Reply | Private Reply | To 6 | View Replies]

To: Eagle9

Warez sites are bad about having those trojans in their script ---- errrr, uhhh, so I've heard.....


10 posted on 10/21/2005 4:47:48 AM PDT by TomGuy
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9
bump :)
11 posted on 10/21/2005 5:15:52 AM PDT by clyde asbury ("You're out there in the whole world, regulating. Are washing machines next?")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Gorzaloon

I just ran some stats, and last month the hits broke down to 75% for all versions of IE - so far this month it's at 71%, but it's never been below 70% for any month over the last year.


12 posted on 10/21/2005 5:45:47 AM PDT by Senator Bedfellow
[ Post Reply | Private Reply | To 8 | View Replies]

To: Gorzaloon

Hits for the website *I* administer, not yours, I should make clear ;)


13 posted on 10/21/2005 5:46:20 AM PDT by Senator Bedfellow
[ Post Reply | Private Reply | To 8 | View Replies]

To: Senator Bedfellow
Hits for the website *I* administer, not yours, I should make clear ;)

Whew..that's a relief! :-)

14 posted on 10/21/2005 5:55:18 AM PDT by Gorzaloon
[ Post Reply | Private Reply | To 13 | View Replies]

To: proxy_user
It doesn't matter what browser or operating system you use. JavaScript is standard, and all browsers are supposed to render it. This is all a browser exploit, and doesn't affect your machine at the OS level.

The exploit described in the paper boiled down to:

... attempt to exploit a Microsoft HTML URL Processing Vulnerability 
(vulnerability resolved by Microsoft Security Bulletin MS04-013). 
Vulnerable computers will retrieve a CHM file (disguised as a style sheet 
named “style.css”) which in turn drops a Trojan Horse called open.exe. 
Open.exe is a Trojan Downloader which uses HTTP to download yet 
another file which is a Trojan Backdoor (executable file girl.bmp)
so, it's yet another reason not to use IE on Windows. It can evidently be avoided by using the product advertised in the paper that described the vunerability, but as always caveat emptor.
15 posted on 10/21/2005 6:19:05 AM PDT by glorgau
[ Post Reply | Private Reply | To 9 | View Replies]

To: rdb3; chance33_98; Calvinist_Dark_Lord; Bush2000; PenguinWry; GodGunsandGuts; CyberCowboy777; ...

16 posted on 10/21/2005 6:34:55 AM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Gorzaloon
Made you nervous, eh? Although, now that you mention it, I notice some things in your logs....

:^)

17 posted on 10/21/2005 6:38:35 AM PDT by Senator Bedfellow
[ Post Reply | Private Reply | To 14 | View Replies]

To: ShadowAce

Thanks! I wish the browser providers would allow for per site jscript like they do cookies. For example, in Firefox I can specify to ask me each time a cookie is being set, and either allow/disallow the cookie. Browser providers should allow that for jscript as well.


18 posted on 10/21/2005 6:57:08 AM PDT by rit
[ Post Reply | Private Reply | To 16 | View Replies]

To: ShadowAce

Thanks! I wish the browser providers would allow for per site jscript like they do cookies. For example, in Firefox I can specify to ask me each time a cookie is being set, and either allow/disallow the cookie. Browser providers should allow that for jscript as well.


19 posted on 10/21/2005 6:59:11 AM PDT by rit
[ Post Reply | Private Reply | To 16 | View Replies]

To: glorgau

I'm bookmarking this Thread for my Hubby. He'll understand what precautions I have to take better than I do. We keep away from IE as we are 'infected' with a site called 'WIN Fixer'. It acts like an advertisement, but it's nasty and never gets out of the way.


20 posted on 10/21/2005 7:03:56 AM PDT by AmericaUnite
[ Post Reply | Private Reply | To 6 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-31 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson