|
|
|
'Survivor' site contains malicious code
Andrew Colley
ZDNet Australia
May 13, 2004, 10:35 BST
A Web site likely to attract fans of the CBS-owned television series Survivor could contain a nasty surprise for its visitors.
The site, owned by a party that has licensed the word "survivor" in a top-level US domain -- not linked to the television network -- today contained a smorgasbord of malicious code embedded in HTML scripts.
A concerned Web user alerted ZDNet Australia about the site after noticing that content on the site had triggered his antivirus software.
Users who visit the site without adequate antivirus protection on their PCs are at risk of being infected by three Trojans coded into scripts maliciously embedded in its content: VBS/Psyme, Debeski and Java Script/IE.startgen.d.
The Trojans take advantage of known exploits in Microsoft ActiveX, Internet Explorer and Java virtual machine.
While antivirus vendors only rank the script Trojans as moderate or low risks, they may be designed to prompt a computer accessing the site to automatically download a secondary payload from another location on the Internet.
At this stage antivirus vendors that ZDNet Australia has approached have not revealed what the payload is, but miscreants have recently contrived similar forms of attack into maliciously designed HTML emails MessageLabs detected this month. |

|
Security Products:
HIPAA
Step by Step Training

April
20th and 22nd classes are closed out Additional class May
20th

PestPatrol
is a powerful security and personal privacy tool that
detects and eliminates destructive pests like trojans, spyware,
adware and hacker tools. It complements your anti-virus and
firewall software, extending your protection against
non-viral malicious software that can evade your existing
security and invade your personal privacy. These pests often
lurk silently on your computer until something – or
someone – sets them off. When that happens, you could lose
passwords, personal data, credit card numbers, and - if you
telecommute and connect to your office via a VPN - open up a
back door for the hacker into your entire company network. Click
here for Pest Patrol
Intrusion
Detection Systems
Vulnerability
Scanners
Firewalls
 | Netscreen |
 | Checkpoint |
Management
Virus
Control
 | Mail Marshall |
Services
 | Security audit |
 | Perimeter Vulnerability Scan |
 | Router/ switch optimization for
security |
 | Firewall checking and configuration |
 | VPN Design and Implementation |
 | Network design |
 | network based application analysis |
 | Network Baselining |
 | Security baselining |
|
|
This mailing has been performed by Aavex Technology
Corporation
42w588 Still Meadows Lane, Elburn IL 60119 USA, 630-365-0025 in compliance
with the "CAN-SPAM Act of 2003", approved and signed by
the president of The United States of America on Dec. 16, 2003. For this
reason, this email cannot be considered SPAM This newsletter contains
commercial advertisement.
|
|