« Antivirus Vendor TrendMicro Has Website SQL Injected, Malware Uploaded | Main | WASC Beerfest 2008 @ RSA April 9th »

PHPBB flaw used to infect infect 200,000 websites with pr0n, fake trojan codec

"Hot on the heels of a recent hack in which 10,000 sites were compromised, researchers have disclosed a new large-scale attack..

Researchers at McAfee estimated that the attack has been active for roughly one week, and in that time frame has managed to place itself on roughly 200,000 web pages.

Most of the infected pages are running the phpBB forum software, said McAfee. The compromised pages are embedded with a Javascript file that links to the site hosting the attack."

"The infected pages bring up what appears to be a pornographic web site. Upon loading the page, a 'fake codec' social engineering attack is attempted. The user is told that in order to view the movie on the page, a special video codec must be installed."

Article Link: http://www.itnews.com.au/News/72214,second-mass-hack-exposed.aspx

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.


All Comments are Moderated and will be delayed!