From today’s SANS NewsBites Vol. 9 Num. 11
ATTACKS, INTRUSIONS, DATA THEFT & LOSS
--Superbowl Sites Infected with Malware
(5 & 2 February 2007)
At least two web sites that were likely to have been visited by football
fans in the days before the Superbowl have been discovered to contain
malicious code that can infect users' computers with keylogging and
Trojan horse programs. The malware exploits two known Windows
vulnerabilities; patches for these flaws were released in April 2006 and
January 2007. The Dolphin Stadium web site has reportedly been
cleansed.
Internet Storm Center: http://isc.sans.org/diary.html?storyid=2151
http://www.theregister.co.uk/2007/02/05/superbowl_trojan/print.html
http://www.eweek.com/print_article2/0,1217,a=200254,00.asp
http://www.vnunet.com/vnunet/news/2174135/super-bowl-host-website-hacked
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9010164
[Editor's Note (Northcutt): Once again, the Internet Storm Center played
a significant role in managing the response to these events. I expect
to see much more sophisticated attacks at future Superbowls or other
uber-news-worthy events. You can make a difference in response time, if
you are willing to contribute your log files. The 6,000 sites that
participate empower the storm center to deal with events such as these:
http://isc.sans.org/diary.html?storyid=2166 ]
Doc
ATTACKS, INTRUSIONS, DATA THEFT & LOSS
--Superbowl Sites Infected with Malware
(5 & 2 February 2007)
At least two web sites that were likely to have been visited by football
fans in the days before the Superbowl have been discovered to contain
malicious code that can infect users' computers with keylogging and
Trojan horse programs. The malware exploits two known Windows
vulnerabilities; patches for these flaws were released in April 2006 and
January 2007. The Dolphin Stadium web site has reportedly been
cleansed.
Internet Storm Center: http://isc.sans.org/diary.html?storyid=2151
http://www.theregister.co.uk/2007/02/05/superbowl_trojan/print.html
http://www.eweek.com/print_article2/0,1217,a=200254,00.asp
http://www.vnunet.com/vnunet/news/2174135/super-bowl-host-website-hacked
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9010164
[Editor's Note (Northcutt): Once again, the Internet Storm Center played
a significant role in managing the response to these events. I expect
to see much more sophisticated attacks at future Superbowls or other
uber-news-worthy events. You can make a difference in response time, if
you are willing to contribute your log files. The 6,000 sites that
participate empower the storm center to deal with events such as these:
http://isc.sans.org/diary.html?storyid=2166 ]
Doc