/?pid=mass-web-infection-leaves-researcher-scratching-her-head-4027

Updated:04:49 AM EDT Sep 27


this is ggmania.com subsite Mass web infection leaves researcher scratching her head - TechAmok

Mass web infection leaves researcher scratching her head - [security]
06:57 PM EST - Feb,07 2008 - post a comment

Security maven Mary Landesman is in the midst of piecing together a who-done-it involving the infection of hundreds of websites that are generating an enormous amount of traffic. Or maybe it's a how-done-it. Either way, she's mostly drawing blanks. Landesman is a researcher for ScanSafe, a company that monitors the web surfing of employees at large companies and provides them with real-time intelligence about what sites are spreading malware. When a client visits a site that has already attacked someone else, the service automatically blocks the site from loading in the end user's browser. Viewing some seven billion web requests per month, company researchers see a fair amount of internet gremlins. Over the past four days, 15 per cent of the blocked malicious traffic has come from just a few hundred sites, which appear to be legitimate ecommerce destinations that have been compromised by attackers. This prompted Landesman to do some digging, and what she uncovered is unlike anything she's seen before. For one thing, the sites themselves are hosting the malware, which is then foisted on visitors. Most of the time attackers are unable to gain such a high degree of control over the sites they hack, so they redirect end users to servers under the control of bad guys and use them to drop malicious payloads.

Ed.note: People are linking Apache/PHP as Linux because all of the affected sites were running Linux! They have obviously not read over the WHT postings which detail those affected and whose servers have been exploited to serve this junk. What's more - it's not an Apache or PHP exploit (though some application layer stuff may have been used for the initial compromise), it's a rootkit which has buried itself deep down at the kernel. From what I've read it looks like there might be an unpublished flaw in cpanel (though I'm sure I've heard before that there are some lesser known exploits in cpanel) which allows an attacker to gain root on the box and install the rookit.

Short overview of recent news articles

The Astronaut - Official Trailer (2025) Kate Mara, Laurence (Sep,27 2025 )

iPhone 17 Durability Test -- What Scratches are Permanent? (Sep,25 2025 )

iPhone 17 Pro Max vs. Galaxy S25 Ultra Drop Test! (Sep,23 2025 )

Race Highlights: A Swing In The Drivers' Title Fight? | 2025 (Sep,21 2025 )

BYD Yangwang U9 Hits 496.22 KM/H - EV Supercar Speed Record (Sep,21 2025 )

I'm FIRST to Unbox The World's Biggest TV (Sep,21 2025 )

Samsung Begins Rollout of Android 16 to Rest of Lineup (Sep,21 2025 )

iOS 26 Now Available, with Visual Intelligence (Sep,21 2025 )

Apple's iPhone 17 Series is Nearly Hack-Proof (Sep,21 2025 )

Qualifying Highlights - 2025 Azerbaijan Grand Prix (Sep,21 2025 )

iPhone 17 Pro vs Samsung S25 Ultra Camera Comparison! (Sep,20 2025 )

iPhone Air Durability test -- I AM SHOCKED (Sep,20 2025 )

Microsoft warns Office 2016/2019 users to switch to the cloud as (Sep,15 2025 )

Get Windows 11 25H2 Right Now (Sep,15 2025 )

iPhone 17 Pro VS iPhone 16 Pro VS iPhone 15 Pro VS iPhone 14 Pro (Sep,14 2025 )

What's the AMD Alternative to an RTX 5070? (Sep,11 2025 )

Apple got my wife, they might get me next... (Sep,10 2025 )

Which Phone Has The Fastest Wi-Fi 7? (Sep,09 2025 )

Apple Event - September 9 (Sep,09 2025 )

Ferrari F430 *MANUAL* with TUBI EXHAUST SCREAMING on the AUTOBAHN! (Sep,08 2025 )

AMD Adrenalin 25.9.1 Driver (Sep,08 2025 )

Google Brings AI Text Tools to its Keyboard (Sep,08 2025 )

The Fastest Lap In F1 History: Max Verstappen's Pole Lap | 2025 (Sep,06 2025 )

You can't download and install Windows 11 25H2 yet as Microsoft (Sep,06 2025 )

A House of Dynamite - Official Teaser (2025) Rebecca Ferguson, Greta (Sep,04 2025 )

RTX 5060 Ti 16GB + Ryzen 5 5600 : Test in 17 Games (Sep,04 2025 )

BUGONIA Trailer 2 (2025) Emma Stone, Jesse Plemons (Sep,02 2025 )

Huawei unveils world-leading AI supercharged hard drive to power (Sep,02 2025 )

AM4 Lives: AMD Ryzen 5 5500X3D CPU Review & Benchmarks (Sep,01 2025 )

I was wrong, iPhone IS better than Android...- 30 Day iPhone (Aug,29 2025 )

303KM/H BMW X5 M50i GPOWER SOUNDS LIKE THUNDER (Aug,29 2025 )

NVIDIA GeForce 581.15 WHQL drivers (Aug,29 2025 )

Apple Intelligence vs Galaxy AI / Google Pixel AI / Xiaomi HyperAI - (Aug,28 2025 )

The Woman in Cabin 10 - Official Trailer (Aug,28 2025 )

YANGWANG U9 Breaks Global EV Top Speed Record (Aug,28 2025 )

AMD B850 Motherboard Roundup: Sub $200 Models (Aug,26 2025 )

Gamers Nexus: Our Channel Could Be Deleted (Aug,25 2025 )

2025 Audi A5 E-Hybrid 299HP "250KMH is back!!" // REVIEW on (Aug,24 2025 )

I Can't Stop You From Buying This... But I'll Try - GeForce RTX (Aug,23 2025 )

NVIDIA GeForce 581.08 WHQL Driver (Aug,23 2025 )

Murcielago with flames chasing an F1 car on highway (2025) (Aug,21 2025 )

Windows 11 24H2 Security Update Causes SSD/HDD Failures and (Aug,18 2025 )

Samsung Galaxy Z Fold 7 - Tips, Tricks & Hidden Features! (Aug,17 2025 )

500Hz OLEDs are Awesome - Gigabyte AORUS FO27Q5P Review (Aug,17 2025 )

They Said my Gaming & Badminton Club Would Never OPEN! (Aug,17 2025 )

NVIDIA GeForce Game Ready 580.97 WHQL Driver (Aug,13 2025 )

When your Bro needs a new computer... (Aug,13 2025 )

WhatsApp's latest update is a huge "convenience" for group chats (Aug,12 2025 )

COLLAPSE: Intel is Falling Apart (Aug,12 2025 )

Useless or Genius: NVMe SSD Coolers (Aug,11 2025 )

>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs