Showing posts with label Code Injection. Show all posts
Showing posts with label Code Injection. Show all posts

Sunday, February 1, 2009

Injection Attacks Continue - Update iwdown

Well the Super Bowl is going to be starting in an hour and I'm ready to check those commercials out. I've watched the number of sites showing up that have been affected by hxxp://iwdown.com/inc/e.js that is hosted in China. A few days ago when I wrote my first post on this injection attack, the Google search results showed roughly 135,000 sites that been affected. Today, it is roughly 430,000. Now realize these numbers aren't exact, but it gives you an idea how things are progressing.

Hope your team wins tonight in the Super Bowl and hope your weekend has been great.

Thursday, January 29, 2009

Injection Attacks Continue

In my line of work I come across websites that have been hacked and code is injected leading to a website loaded with malware ready to take advantage of people who don't patch their PC's. Today was the website executivehomemaker.com. Hidden inside this legitimate site is a redirect to hxxp://iwdown.com/inc/e.js. A site hosted in China.

This is just another in a long line of sites with vulnerabilities that allow the bad guys to take advantage of the casual surfers. They don't patch, they probably click on links in spam e-mails and on and on. My last search on the iwdown site shows 135,000 sites with these injections. Click here an see the search results.

Stay safe and have a fabulous weekend and ROCK CHALK JAYHAWK!

Sunday, November 30, 2008

Small Credit Unions Equal Compter Security Risk

OK, it has been a long time since I've posted a story on my blog. I write about computer security. Today's story talks about a couple of small local credit unions here in my town of Topeka. Educational Employees Credit Union and Kansas Super Chief Credit Union sites had what is called a code injection attack on their websites. The site that their customers were re-directed to was hxxp://ytgw123.cn (Don't go to this site. It will attack you PC with exploits.) The attack happened somewhere around September 26th, 2008.

So how did this attack happen? First, the web sites were not coded securely which allowed the criminal attacker to inject this code into the online banking sites for these two credit unions. The attacker didn't actually access the credit union's customer accounts. However, if any of their customers innocently went to either credit union's website, they were re-directed to this malicious site. If not properly patched, these customers probably now have malicious code installed on their PC that could be a password stealer, keylogger, and is now a robot which means someone with bad intentions now controls your PC.

I've been told that the problem has been corrected but I have my doubts. Since I have an account at Educational Employees Credit Union, I will be watching this closely. The problem I see is that this was not reported and customers of EECU and KSCCU have spyware or malware installed on their PC and may not realize it.

Hopefully the company that is contracted to create and maintain these credit union's websites has found the actual vulnerability in their own code and closed this hole. From my experience in computer security, code developers are trained to write code quickly to add to a companies bottom line. They are not trained to code securely. I believe that this situation is so common and customers of these smaller banks and credit unions who have to contract with companies who develop and write code are putting the customers of these institutions in danger of criminal hackers stealing login credentials for their banks and credit union's accounts. I will be watching my credit union. Maybe you should too!