Yes, I was curious! Been working a little more than usual lately on a few sites and stuck my nose into some matters of websites security by pure chance. Seen a random complaint somewhere, the guy was yelling desperately "please help me please help me!", "I reinstalled twice my forum and a link to a .cn site keeps appearing in the pages! I didn't put it there! Where does it come from".
Heh. I had to see. So I accessed his forum, to see what he means.
It was a link in an iframe, and, taking advantage of a Firefox vulnerability, it had the possibility to execute the code from the .cn site without me clicking on any .cn link...
Simply, while his forum was loading in my browser, my kaspersky antivirus started yelling "services.exe has changed!".
*...peers at kaspersky with the look of one who thinks the poor antivirus has gone loony now*
Still, in a matter of minutes, I wanted to make sure, so I ran a quick scan of critical areas.
And got: "Svchost.exe is infected: Trojan.PSW.Win32.Agent.mzh. Cannot disinfect nor delete a running process."
*searches on internet: Trojan and keylogger*
*dies*
I'll be back online when I'll be able to login somewhere, anywhere, without the whole world finding out where and how I do it... heh.
And I'm no cat.
Heh. I had to see. So I accessed his forum, to see what he means.
It was a link in an iframe, and, taking advantage of a Firefox vulnerability, it had the possibility to execute the code from the .cn site without me clicking on any .cn link...
Simply, while his forum was loading in my browser, my kaspersky antivirus started yelling "services.exe has changed!".
*...peers at kaspersky with the look of one who thinks the poor antivirus has gone loony now*
Still, in a matter of minutes, I wanted to make sure, so I ran a quick scan of critical areas.
And got: "Svchost.exe is infected: Trojan.PSW.Win32.Agent.mzh. Cannot disinfect nor delete a running process."
*searches on internet: Trojan and keylogger*
*dies*
I'll be back online when I'll be able to login somewhere, anywhere, without the whole world finding out where and how I do it... heh.
And I'm no cat.