Register | Forget Password | Login
Search :
SecurityReason

News

Search

SecurityAlert

About SecurityAlert

ExploitAlert

SecurityReason Research

WLB

WLB Database

Send to WLB

About WLB

RSS

News

SecurityAlert

World Laboratory of Bugtraq

ExploitAlert

Apache

PHP

Corporate

Contact

About us

Services

SecurePHP

Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

News from: Virus

» Topic:  New Adware Alters Search Results

» Added by:  sp3x

» Date:  3.10.2005

  PandaLabs has identified Adware/PremiumSearch - a new malicious code that takes advantage of popular Internet search engines. This attack seems to mimic the actions of the worm that was detected last week that altered the sponsored links in Google searches.

In this case the infection originates from visits to a certain web page, when users are redirected from other pages containing warez (illegal software versions) or pornography. In addition to PremiumSearch, this page also installs application/WorldAntiSpy on victims' computers, along with a variant of Smitfraud, leading users to believe they have been infected by a series of threats and will have to pay to disinfect them.

PremiumSearch exploits some of the vulnerabilities most frequently used by spyware such as ByteVerify, LoadImage, and Mhtredir to install a malicious BHO (Browser Helper Object) on the computer. It then installs a "Google" toolbar (which does not come from Google but has been created by a third party), and modifies the HOSTS file. The BHO also changes the browser home page to the PremiumSearch search engine, even if a user specifies another in the browser settings.

The modifications to the HOSTS file and the action taken by the BHO direct users that request MSN, Yahoo! and Google (in versions for more than 60 countries) to spoof versions which are indistinguishable from the original versions, other than the fact that the first results displayed have been altered (the remaining results are the same as for the genuine web pages).

The same occurs with searches launched through the spoof Google toolbar. This malicious code can also affect the Alexa search, although it has failed to operate correctly on test systems. The web page from which the spoof versions are obtained, are hosted in the USA.

Luis Corrons, director, PandaLabs, said, "These actions are financially motivated and aim to exploit the popularity of these search engines, to increase visits to the pages with the altered results. To avoid this kind of attack, it is vital that users have reliable antivirus protection and keep their systems up-to-date, as the vulnerabilities used have often been in existence for some time."

Source : www.techtree.com



Alert

Microsoft VISTA TCP/IP stack buffer overflow

high- 2008-11-27

Microsoft Device IO Control wrapped by the iphlpapi.dll API shipping with Windows Vista 32 bit and 64 bit contains a possibly exploitable, buffer overflow corrupting kernel memory.

Apache rss

» Apache Tomcat information
   disclosure

» Apache Tomcat <=
   6.0.18 UTF8 Directory
   Traversal Vulnerability

» Apache Tomcat information
   disclosure vulnerability

» Apache Tomcat XSS
   vulnerability

PHP rss

» PHP 5.2.6 dba_replace()
   destroying file

» PHP 5.2.6 (error_log)
   safe_mode bypass

» PHP 5.2.6 chdir(),ftok()
   (standard ext) safe_mode
   bypass

» PHP 5.2.6 posix_access()
   (posix ext) safe_mode
   bypass

Copyright © SecurityReason. All Rights Reserved.