On The Insider: Miley Cyrus in Sex and the City 2
BNET Business Network:
BNET
TechRepublic
ZDNet

November 10th, 2009

Major online ad site hacked, serving up exploit cocktail

Posted by Ryan Naraine @ 9:55 am

Categories: Adobe, Anti Virus, Arbitrary Code Execution, Browsers, Data theft, Exploit code, Flash, Patch Watch, Responsible disclosure, Spam and Phishing, Spyware and Adware

Tags: Websense Inc., Microsoft Corp., Exploit, Online Advertising, Security, Viruses And Worms, Databases, Enterprise Software, Software, Data Management

A high-profile online advertising Web site has been hacked and rigged to serve multiple exploits to Microsoft Windows users surfing the net with unpatched third party desktop software.

According to a warning issued by Websense Security Labs, the malicious code was found on media-servers.net, which is described as a high-profile advertiser on the Internet realm.  The site has been firing an assortment of exploits for several months, including exploits for vulnerabilities in Microsoft DirectShow and Adobe PDF Reader.

Here’s a list of the exploits associated with this attack:

  • Microsoft DirectShow (CVE-2008-0015)
  • Microsoft Snapshot Viewer (CVE-2008-2463)
  • Microsoft Data Access Components (MDAC) CVE-2006-0003
  • AOL ConvertFile() remote buffer overflow exploit

Websense said the rigged site also comes with an auto-loading malicious PDF file that attempts to exploit these vulnerabilities:

  • Adobe Reader and Acrobat 8.1.1 buffer overflow (CVE-2007-5659)
  • Adobe Acrobat and Reader 8.1.2 buffer overflow (CVE-2008-2992)

If the user’s browser is successfully exploited, Websense says a malicious file is downloaded and run in the user’s Windows home directory from another collaborated exploit site.

The company’s blog has screenshots of the attack site.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 33 Talkback(s)
LOL!
Most anti-virus type programs only work for known
threats. Do you have any clue how easy it is to
make a packer that's completely undetected by like
99% of the AVs out there?

The solution is what he mentioned; not letting the
crap onto your system to begin with.... (Read the rest)
Posted by: AzuMao Posted on: 11/12/09 You are currently: a Guest | | Terms of Use
One more reason to use Firefox  davebarnes | 11/10/09
Agreed  NStalnecker | 11/10/09
Not enough!  Linux Geek | 11/10/09
One more reason to patch  mdemuth | 11/10/09
RE: One more reason to use Firefox  bfilipiak@... | 11/10/09
Thanks  ttocsmij | 11/10/09
the same thing is possible with Internet Explorer  directory | 11/11/09
NOT a reason to use FireFox  donc13 | 11/11/09
LOL!  AzuMao | 11/12/09
RE: Major online ad site hacked, serving up exploit cocktail  sj2@... | 11/10/09
Sounds like an inside job  Stan57 | 11/10/09
Please provide more information  NonZealot | 11/10/09
The ABMer crowd...   they are not too clever are they?  The Mentalist | 11/10/09
But..  Ceridan | 11/10/09
He keeps firing acronyms and dates knowing no one will check them...  The Mentalist | 11/10/09
You are right in one aspect, you shouldn't have to check these  NonZealot | 11/10/09
Still trying to cover it up, eh, -3?  James T. Kirk | 11/10/09
ABMER  dgrainge | 11/11/09
How is it that everyone but you understand that  GuidingLight | 11/10/09
No, that's not it at all.  James T. Kirk | 11/11/09
Nonsense article without describing correction  Narr vi | 11/10/09
Open up, here comes the spoon!  ejhonda | 11/10/09
well, sorry, but you miss the point  Narr vi | 11/10/09
So was this an Apache vulnerability?  Johnny Vegas | 11/10/09
Linux, that's how the hackers took control  honeymonster | 11/10/09
The irony is ...  n0neXn0ne | 11/10/09
Let me see if I understand this  Real World | 11/10/09
re: Let me see if you overstand this  n0neXn0ne | 11/11/09
Damn  Real World | 11/11/09
grin  n0neXn0ne | 11/11/09
So if ...  n0neXn0ne | 11/11/09
RE: Major online ad site hacked, serving up exploit cocktail  peter.kumar@... | 11/11/09
What???  James T. Kirk | 11/11/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads