Security Site Forum  

Go Back   Security Site Forum > Technology > Internet and Computer Security

Reply
 
Thread Tools Display Modes
Scareware tool dumps smut on Windows PCs
Old
  (#1 (permalink))
SSF Active Member
 
Sardonicus's Avatar
 
Status: Offline
Posts: 3,142
Join Date: May 2002
Scareware tool dumps smut on Windows PCs - 11-20-2009, 12:28 AM

Scareware tool dumps smut on Windows PCs

Rogue anti-virus slingers are getting even sneakier. Instead of offering to clean up non-existent malware threats as per the traditional approach, one rogue scanner offers to clean up images of porn it claims to have found on a prospective mark's PC.

In reality, these images get downloaded by the purported clean-up package itself. Victims were exposed to the pitch on behalf of a especially malodorous scareware package called Win Spy Protect simply by visiting a hacked website.

Roger Thompson, chief of research at security firm AVG, ran across the threat months ago but held back on publishing details until Thursday. Heightened concerns about how malware infection could result in presence of image of child abuse on the PCs of non-paedophiles prompted Thompson into publishing a video of the threat (below).

The hacked website linked to the attack was a children's site and the content strictly adult porn. However, the tactic could result in child abuse images getting dropped onto the machines of surfers whose only mistake was to stray onto hacked websites, as Thompson explains.
Fortunately, LinkScanner detects the rogue-spyware aspects of this and blocks it just fine, but without LinkScanner, these images would now be in the browser cache, and it would sure look like the owner was guilty. Worse still, the images could just as easily be kiddy porn, and just being your cache would be regarded as possession, and therefore highly illegal by most law enforcement agencies.


Poisoned blogs

In related scareware news, hackers have set up 260,000 fake blog pages on compromised sites in preparation for a scareware distribution campaign that relies on manipulating search engine rankings so that booby-trapped sites appear prominently in the search indexes for topical terms.

Between the latest attack (detected this week) and an even larger assault along the same lines detected in September, there are now well over 800,000 fake blog pages. Few of these pages are detected by Google as malicious, net security firm eSoft warns.

A blog post by eSoft explains the mechanism of the scam.

"The key to this scheme is JavaScript uploaded to the compromised server and used in the fake blog pages. The file, css.js, contains obfuscated JavaScript which redirect users to Rogue AV [anti-virus] if the site is accessed through certain search engines," it said.

"Using this technique allows the attackers to quickly and easily change distribution points and payloads. The current payloads have low detection rates among AV [anti-virus] scanners." ®



[Only registered and activated users can see links. ]
   
Reply With Quote
 
Old
  (#2 (permalink))
SSF Active Member
 
holaschaus's Avatar
 
Status: Offline
Posts: 205
Join Date: Apr 2008
Location: On a spiral in the sky
11-22-2009, 05:37 AM

I can't understand how some people can do things like this. To make someone else's computer download child porn is really terrible. There aren't words to describe those animals, because they shouldn't be called human beings.


There's nothing here, move on!
   
Reply With Quote
Old
  (#3 (permalink))
SSF Active Member
 
shadowzone's Avatar
 
Status: Offline
Posts: 118
Join Date: Aug 2007
11-23-2009, 04:34 AM

Came across this one on a clients PC only last week. Mum blamed her teenage son for looking at porn. Clean up was easy enough, ans she's running with parental controls to see where he goes.
   
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows 7 USB/DVD Download Tool A Guy Windows 95/98/Me/NT/2000/XP/Vista/Win7 1 10-28-2009 05:17 PM
2009 Ultimate Developer and Power Users Tool List for Windows A Guy Windows 95/98/Me/NT/2000/XP/Vista/Win7 0 10-01-2009 06:43 AM
Official Windows Genuine Validation Tool zooneytunes Applications Sector 0 08-04-2009 10:32 AM



Powered by vBulletin® Version 3.6.8 PL2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.

...... XXX adult password pass board forum
Stand With Haiti

Page generated in 0.07163191 seconds (67.11% PHP - 32.89% MySQL) with 16 queries