Archived Blog

Mass Attack JavaScript injection

03.14.2008 - 10:37 AM

Websense® Security Labs has been tracking the recent malicious JavaScript iframe that has been injected into the source code of tens of thousands of websites world-wide. This is not new to us, as we have been protecting customers against the payload hosted by these malicious hosts located in China since February. When a user's browser opens the compromised site, the JavaScript ultimately serves up a concoction of exploits designed to gain access to the visitor's computer. At time of writing the web site serving the first link in the chain at www.2117[removed].net is currently down.

As reported by The Register, a simple Google search for a script snippet reveals the extent of the attack.

Further details on the attack can be found here and here.

US-CERT Advisory March 13, 2008 at 12:04 pm: Compromised Websites Redirect Users to Malicious Websites

Bookmark This Post: