Hosting generously provided by
www.mv.com





Pick Your Language


PHPBB flaw used to infect infect 200,000 websites with pr0n, fake trojan codec
Posted 3/18/08 by Robert from the 'I thought I couldn't catch anything from porn department'

"Hot on the heels of a recent hack in which 10,000 sites were compromised, researchers have disclosed a new large-scale attack..

Researchers at McAfee estimated that the attack has been active for roughly one week, and in that time frame has managed to place itself on roughly 200,000 web pages.

Most of the infected pages are running the phpBB forum software, said McAfee. The compromised pages are embedded with a Javascript file that links to the site hosting the attack."

"The infected pages bring up what appears to be a pornographic web site. Upon loading the page, a 'fake codec' social engineering attack is attempted. The user is told that in order to view the movie on the page, a special video codec must be installed."

Article Link: http://www.itnews.com.au/News/72214,second-mass-hack-exposed.aspx
Link to this Story: PHPBB flaw used to infect infect 200,000 websites with pr0n, fake trojan codec
Link: Have a Site Suggestion, Material Request, or News? Submit it!
News RSS Feed: Web Security news RSS Feed
Discuss this article    Find Related Stories



External Links:
Copyright 2000-2007 Cgisecurity.com.
Providing Web Security news since 2000.
Information contained on this website may not be copied without explicit permission.
Best Viewed with Netscape.
Website Security Web Application Security solid state drives ssd ebay ebay topdeals . buy macbook air not work safe software security


Popular Links By Subject

Sponsored Link (Advertise)


Subscribe to CGISecurity.com


The Web Security Mailing List
  • Re: [WEB SECURITY] Normalization of page response times to prevent timing attacks in a production environment?
  • Re: [WEB SECURITY] Fake Captcha Protection
  • Re: [WEB SECURITY] Fake Captcha Protection
  • [WEB SECURITY] Re: Odd XSS Exploit
  • Re: [WEB SECURITY] Fake Captcha Protection
  • Re: [WEB SECURITY] Fake Captcha Protection
  • Re: [WEB SECURITY] webapp security curse
  • Re: [WEB SECURITY] Fake Captcha Protection
  • Re: [WEB SECURITY] Fake Captcha Protection
  • Re: [WEB SECURITY] Fake Captcha Protection

  • Contact us
    Post News, get linkage!

    Name

    Email or Homepage:

    Subject

    Finish the word below: deadb33f

    Body