On TechRepublic: 10 ways to deal with a bad boss
BNET Business Network:
BNET
TechRepublic
ZDNet

September 18th, 2009

PBS.org hacked, serving malware cocktail

Posted by Ryan Naraine @ 10:26 am

Categories: Adobe, Anti Virus, Arbitrary Code Execution, Botnets, Browsers, Complex Attacks, Data theft, Flash, Locally Running Web Servers, Malware, Spam and Phishing, Spyware and Adware, Viruses and Worms

Tags: Cocktail, PBS, Malware, Web Site, Exploit, Spyware, Adware & Malware, Cyberthreats, Web Site Development, Web Technology, Viruses And Worms

Some sections of the popular PBS.org Web site have been hijacked by hackers serving up a cocktail of dangerous exploits.

According to researchers at Purewire, attempts to access certain PBS Web site pages yielded JavaScript that serves exploits from a malicious domain via an iframe.

The malicious JavaScript was found on the “Curious George” page that provides content on the popular animation series.

A look at the code on the hijacked site shows malicious activity coming from a third-party .info domain.

The URL serves exploits that target a variety of software vulnerabilities, including those in Acrobat Reader (CVE-2008-2992, CVE-2009-0927, and CVE-2007-5659), AOL Radio AmpX (CVE-2007-6250), AOL SuperBuddy (CVE-2006-5820) and Apple QuickTime (CVE-2007-0015).

Purewire said the exploit site is part of a malware campaign that includes tens of similar Web sites hosted off of a handful of common IP addresses.

Read the Purewire blog for more information on this attack.

UPDATE: A representative for PBS.org tells me the malicious code has been removed from the site.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 19 Talkback(s)
Loser
nt (Read the rest)
Posted by: Duke E. Love Posted on: 09/22/09 You are currently: a Guest | | Terms of Use
PBS.org hacked, serving malware cocktail  Loverock Davidson | 09/18/09
yes, they are running Linux  honeymonster | 09/18/09
RE: yes, they are running Linux  bendib | 09/19/09
Show me proof about Linux being better than Windows environment.  Grayson Peddie | 09/20/09
Well  HypnoToad72 | 09/20/09
Yay! A human!  bendib | 09/20/09
Loser  Duke E. Love | 09/22/09
Dammit, Grayson!  bendib | 09/20/09
Show me proof about Linux being better than Windows environment  schmandel@... | 09/21/09
Stop calling me a child.  Grayson Peddie | 09/21/09
re: Stop calling me a child  schmandel@... | 09/21/09
what he said... {nt}  pgit | 09/21/09
clarity  pgit | 09/21/09
Am I vulnerable when using Foxit Reader?  Grayson Peddie | 09/18/09
RE: Am I vulnerable when using Foxit Reader?  bendib | 09/19/09
Unless you use WINE, or common apps such as Flash player...  HypnoToad72 | 09/20/09
Last I checked Foxit was vulnerable..  JCitizen | 09/21/09
Did I hurt someonce Feewings?  Duke E. Love | 09/21/09
XSS - Cross Site Scripting  Spats30 | 09/22/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads