Results 1 to 11 of 11
  1. #1
    Thailand Expat
    rawlins's Avatar
    Join Date
    Oct 2007
    Last Online
    13-04-2020 @ 05:52 PM
    Posts
    2,942

    Anybody else fall for this one?

    Was browsing a few nights ago and was hit with a 'windows security centre' page telling me I had key stroke loggers and a few other viruses... Looked pretty genuine so I ran a scan which came up with nothing.



    Anyway, twas all a hoax but experts are saying it was the most successful SQL injection attack ever seen.

    Full story: BBC News - Sites hit in massive web attack

  2. #2
    Thailand Expat
    Mid's Avatar
    Join Date
    Aug 2007
    Last Online
    @
    Posts
    1,411
    hi bloke , been a while , good to see you posting again

  3. #3
    Thailand Expat
    rawlins's Avatar
    Join Date
    Oct 2007
    Last Online
    13-04-2020 @ 05:52 PM
    Posts
    2,942
    ^Thanks... Back offshore and sane again..

    Been lurking for a while but not very busy at work as can be seen from above.

  4. #4
    Thailand Expat
    Mid's Avatar
    Join Date
    Aug 2007
    Last Online
    @
    Posts
    1,411

    LizaMoon

    The LizaMoon mass-injection campaign is still ongoing and more than 500,000 pages have a script link to lizamoon.com according to preliminary Google Search results.

    Update on LizaMoon mass-injection and Q&A - Security Labs


    What happens to the user?

    We wrote in an earlier post that the payload site doesn't work properly, but further testing shows that it does and we created a video showing what happens if a user visits a website that contains the injected code. The video is available at the end of this post. The user only gets the malicious code once per IP address, so if you've already visited the site you won't get the code again. This is something we see often in attacks, especially in exploit kits.

    The Rogue AV software that is installed is called Windows Stability Center and the file that is downloaded is currently detected by 13/43 anti-virus engines according to VirusTotal.



    The software then displays a warning that there are lots of problems on your PC. To fix them you have to pay for the full version of the application. Very traditional rogue AV scam. Dancho Danchev has some more information on his blog.



    Where are users coming from?

    We looked at reports of traffic to lizamoon.com as indicated by data collected by the Websense Threatseeker Network and here's a graph of where those users are located.


    community.websense.com

  5. #5
    On a walkabout Loy Toy's Avatar
    Join Date
    Jun 2008
    Last Online
    @
    Posts
    30,531
    Quote Originally Posted by rawlins
    ^Thanks... Back offshore and sane again
    Good on ya mate.................I'm looking forward to that beer.

  6. #6
    Thailand Expat
    rawlins's Avatar
    Join Date
    Oct 2007
    Last Online
    13-04-2020 @ 05:52 PM
    Posts
    2,942
    ^ Me too... Back in about a week - will give you a shout. Few new bars popped up on the darkside that I haven't checked out yet...

  7. #7
    On a walkabout Loy Toy's Avatar
    Join Date
    Jun 2008
    Last Online
    @
    Posts
    30,531
    I'll be back in Thailand (arriving today) for about 2 weeks so timing is everything.

  8. #8
    Thailand Expat nedwalk's Avatar
    Join Date
    Aug 2007
    Last Online
    28-02-2020 @ 11:00 AM
    Location
    sunshine coast
    Posts
    7,714
    Bloody Hell I,m Back In 16 Days...does That Mean I Miss Out????

  9. #9
    Member
    ShilohJim's Avatar
    Join Date
    Jun 2009
    Last Online
    31-08-2016 @ 10:35 AM
    Location
    Shiloh, Tennessee
    Posts
    145
    Well, guys, if this is another TD April Fools joke you got me. Very real looking. The one about TD and TV merging had me hook line and sinker until I continued to read posts until the joke was outed. I truly enjoy TD even with some of the more crass members continuely being seemingly ass-holes.

    Shiloh Jim

  10. #10
    Member
    Join Date
    Jul 2010
    Last Online
    18-08-2014 @ 10:32 AM
    Posts
    101
    They need to hang the bastards who are doing this stuff!!!

  11. #11
    Thailand Expat harrybarracuda's Avatar
    Join Date
    Sep 2009
    Last Online
    @
    Posts
    96,892
    I've never seen this. Mind you I apply all updates, use a firewall, AV and a few other tools as well.

    Oh, and a popup blocker doesn't hurt.

    Having said that, two points in the article are worth a mention:

    (1) It's a flaw in badly written web applications, not SQL or Windows.
    (2) Don't click on shit if you don't know what it is.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •