Welcome, Guest. Please login or register.

Author Topic: Utilitybase Infected  (Read 11909 times)

Description:

0 Members and 1 Guest are viewing this topic.

Offline Piru

  • \' union select name,pwd--
  • Hero Member
  • *****
  • Join Date: Aug 2002
  • Posts: 6946
    • Show all replies
    • http://www.iki.fi/sintonen/
Re: Help needed with programming Amiga development forum
« on: January 31, 2011, 02:58:44 PM »
Quote from: Trev;611094
The malware in UtilityBase is a script src reference to a site that no longer exists. (It's not accessible from my ISP, anyway.)
It was taken down because of hosting Neosploit Toolkit content. However, it is only the 2nd URL that is broken, the actual script src URL works. Thus the attack could easily be made functional again...

Even more worrying is the fact that someone is able to modify the site content at will.
« Last Edit: January 31, 2011, 03:20:23 PM by Piru »
 

Offline Piru

  • \' union select name,pwd--
  • Hero Member
  • *****
  • Join Date: Aug 2002
  • Posts: 6946
    • Show all replies
    • http://www.iki.fi/sintonen/
Re: Help needed with programming Amiga development forum
« Reply #1 on: February 01, 2011, 07:37:46 AM »
Quote from: Trev;611304
What makes you sure it wasn't placed there by the site or hosting administrators in the first place?
Of course I can't be sure. But it is far more likely that some automated bot using google and/or brute force scanning found the vulnerable forum software/cms and exploited it. The exploited site may have been sold to highest bidder on bulk pwned sites market even.