 
Full Disclosure mailing list archives
Re: what is this?
From: "Robert McArdle" <robertmcardle () gmail com>
Date: Mon, 14 Jan 2008 15:41:34 +0000
Looks like your site was compromised along with several hundred others in the last day or so. A full account is up on http://blog.trendmicro.com/e-commerce-sites-invaded/but the JS you posted is the exact same as the one used in those attacks. I'm guessing you have Javascripts embedded in your pages that pointed to a randomly named js in the same directory, right? Robert McArdle -- www.RobertMcArdle.com/blog/ - Techie/Security/Inane Ramblings On Jan 13, 2008 4:01 PM, crazy frog crazy frog <i.m.crazy.frog () gmail com> wrote:
Hi, Recently on opening one of my site,my antivirus pops up saying that it has found on malicious script.the url is random and i have managed to get tht script.it is using some flaw in apple quick time. u can get the zip file for java script here: http://secgeeks.com/what.zip password is 12345 can somebody guide/help me what is this and how can i remove it? -- advertise on secgeeks? http://secgeeks.com/Advertising_on_Secgeeks.com http://newskicks.com
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- what is this? crazy frog crazy frog (Jan 13)
- Re: what is this? crazy frog crazy frog (Jan 13)
- Re: what is this? Robert McArdle (Jan 14)
 
- Re: what is this? 3APA3A (Jan 14)
- Re: what is this? Nick FitzGerald (Jan 14)
- Re: what is this? crazy frog crazy frog (Jan 14)
- Re: what is this? 3APA3A (Jan 14)
 
 
- Re: what is this? Nick FitzGerald (Jan 14)
- Re: what is this? Robert McArdle (Jan 14)
- Re: what is this? Robert McArdle (Jan 14)
 
- Re: what is this? Jose Nazario (Jan 14)
- Re: what is this? crazy frog crazy frog (Jan 14)
- Re: what is this? 3APA3A (Jan 14)
- Re: what is this? Mario Contestabile (Jan 14)
 
- Re: what is this? Gadi Evron (Jan 14)
- Re: what is this? reepex (Jan 16)
- Re: what is this? Paul Schmehl (Jan 16)
- Re: what is this? worried security (Jan 16)
- Re: what is this? reepex (Jan 16)
 
 
- Re: what is this? reepex (Jan 16)
 
- Re: what is this? crazy frog crazy frog (Jan 13)


