ICT Security-Sécurité PC et Internet
87.1K views | +0 today
Follow
ICT Security-Sécurité PC et Internet
ICT Security + Privacy + Piracy + Data Protection - Censorship - Des cours et infos gratuites sur la"Sécurité PC et Internet" pour usage non-commercial... (FR, EN+DE)...
Curated by Gust MEES
Your new post is loading...
Your new post is loading...
Scooped by Gust MEES
Scoop.it!

Over 99 percent of About.com links vulnerable to XSS, XFS iframe attack | CyberSecurity

Over 99 percent of About.com links vulnerable to XSS, XFS iframe attack | CyberSecurity | ICT Security-Sécurité PC et Internet | Scoop.it

About.com has a huge security problem, but it's likely worse for the over 98 million monthly visitors to the About Group's various topic-specific subdomains.

A security researcher disclosed Monday that "at least 99.88%" of all topic links and all domains related to About.com are vulnerable to open XSS (Cross Site Scripting) and Iframe Injection (Cross Frame Scripting, XFS) attacks.

According to the researcher's findings and proof-of-concept results, all subdomains of About.com are affected.


Learn more:


http://www.scoop.it/t/securite-pc-et-internet/?tag=iFrame-Injection


http://www.scoop.it/t/securite-pc-et-internet/?tag=XSS


Gust MEES's insight:

About.com has a huge security problem, but it's likely worse for the over 98 million monthly visitors to the About Group's various topic-specific subdomains.

A security researcher disclosed Monday that "at least 99.88%" of all topic links and all domains related to About.com are vulnerable to open XSS (Cross Site Scripting) and Iframe Injection (Cross Frame Scripting, XFS) attacks.

According to the researcher's findings and proof-of-concept results, all subdomains of About.com are affected.


No comment yet.
Scooped by Gust MEES
Scoop.it!

Mass injection attack compromised 20,000+ domains, delivers fake AV

Mass injection attack compromised 20,000+ domains, delivers fake AV | ICT Security-Sécurité PC et Internet | Scoop.it

A simple mistake on the part of cyber attackers has revealed another mass malicious iFrames injection attack that is currently under way, according to Armorize's researchers.

 

Initially, they forgot to include a tag before the actual malicious code, so it was indexed by Google and, therefore, searchable. The initial number of compromised domains was around 22,400, with a total of 536,000+ infected pages.

No comment yet.
Scooped by Gust MEES
Scoop.it!

Linux Rootkit Found Launching iFrame Injection Attacks

Linux Rootkit Found Launching iFrame Injection Attacks | ICT Security-Sécurité PC et Internet | Scoop.it
The Linux root kit targets 64-bit Linux platforms and uses advanced techniques to hide itself, and infects the websites hosted on attacked HTTP server working to launch drive-by download attacks.

 

“It's an outstanding sample, not only because it targets 64-bit Linux platforms and uses advanced techniques to hide itself, but primarily because of the unusual functionality of infecting the websites hosted on attacked HTTP server - and therefore working as a part of drive-by download scenario,” commented Marta Janus, a Kaspersky Lab Expert who examined the rootkit sample.

 

===> “This rootkit, though it's still in the development stage, shows a new approach to the drive-by download schema and we can certainly expect more such malware in the future.” <===

 

Read more:

http://www.securityweek.com/linux-rootkit-found-launching-iframe-injection-attacks

 

No comment yet.
Scooped by Gust MEES
Scoop.it!

90,000+ pages compromised in mass iFrame injection attack | ZDNet

90,000+ pages compromised in mass iFrame injection attack | ZDNet | ICT Security-Sécurité PC et Internet | Scoop.it
Security researchers from Armorize have intercepted a currently live mass iFrame injection attack, affecting over 90,000 Web pages.
No comment yet.