Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.computer.security
Register FAQ Forum Rules Members List Calendar Search Today's Posts Advertise Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 12-01-2006, 11:10 AM
Terry_P
Guest
 
Posts: n/a
Default Hidden spam links injected into web pages

I have become aware that a hidden list of spam links were inserted at
the end of several of my web pages a few days ago. My web host claims that
my FTP password must have been cracked but I am sceptical of this
explanation. The links pointed to what has now been confirmed as a
compromised computer at uchicago.edu and were then redirected to nudai.com
which has further links to peakpc.com . The links related to phentermine
and other drugs.

A Google search for "how long does phentermine stay in the body" reveals
that a large number of blog sites have phentermine comment spam. However
what I am reporting is HTML pages altered presumably by a script to include
spam links. Is this a new as yet unreported strategy by spammers?

Please check your web pages for spam link injection. The links are hidden
so you must check the source for alterations.

Reply With Quote
  #2 (permalink)  
Old 12-01-2006, 03:03 PM
Todd H.
Guest
 
Posts: n/a
Default Re: Hidden spam links injected into web pages

Terry_P <me@privacy.net> writes:

> I have become aware that a hidden list of spam links were inserted at
> the end of several of my web pages a few days ago. My web host claims that
> my FTP password must have been cracked but I am sceptical of this
> explanation. The links pointed to what has now been confirmed as a
> compromised computer at uchicago.edu and were then redirected to nudai.com
> which has further links to peakpc.com . The links related to phentermine
> and other drugs.
>
> A Google search for "how long does phentermine stay in the body" reveals
> that a large number of blog sites have phentermine comment spam. However
> what I am reporting is HTML pages altered presumably by a script to include
> spam links. Is this a new as yet unreported strategy by spammers?
>
> Please check your web pages for spam link injection. The links are hidden
> so you must check the source for alterations.


Web page defacements aren't all that new, but perhaps this is a novel
use for them.

What active scripting are you using on your site (e.g. php?, what
scripts?) ? That's a more likely injection vector than a cracked ftp
password?

--
Todd H.
http://www.toddh.net/

Reply With Quote
  #3 (permalink)  
Old 12-01-2006, 03:31 PM
Terry_P
Guest
 
Posts: n/a
Default Re: Hidden spam links injected into web pages

On Fri, 1 Dec 2006 12:10:05 +0000, Terry_P wrote:


> The links pointed to what has now been confirmed as a
> compromised computer at uchicago.edu and were then redirected to nudai.com
> which has further links to peakpc.com . The links related to phentermine
> and other drugs.


Sorry, there was a typo. The spamming sites are nudai.com and peakc.com
(*not* peakpc.com).

Reply With Quote
  #4 (permalink)  
Old 12-02-2006, 11:18 PM
MC
Guest
 
Posts: n/a
Default Re: Hidden spam links injected into web pages

Todd H. wrote:
>
> Web page defacements aren't all that new, but perhaps this is a novel
> use for them.
>
> What active scripting are you using on your site (e.g. php?, what
> scripts?) ? That's a more likely injection vector than a cracked ftp
> password?
>


Actually, since regular FTP passwords are all sent in cleartext, it
doesn't have to be cracked, it can be sniffed out. FTP is quite a likely
injjection vector because of that.
A decent webhosting company keeps logs of FTP connections though, so
they should be able to track at the very least connections made to the
web space from IPs different than normal, and that way track the
defacers/crackers and report them to the authorities (it's a crime in
many countries punishable by law). If they don't log, demand they start
logging, or find another hosting company :P

Something you could do instead would be to ask for SFTP access instead
of FTP to update your pages. This way neither the login nor the data
uploaded can be sniffed out.

HTH

MC

Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Pages with buttloads of links whetu Interesting Links 1 06-13-2009 06:41 AM
Anyone else get TXT Message Spam from Cingular lately? karlkrandall@sbcglobal.net alt.cellular.cingular 41 03-12-2007 10:55 PM
Oxygen Phone Manager II v2.11 for Symbian OS smartphones is just released! Oxygen Software alt.cellular.nokia 3 09-16-2006 10:16 AM


All times are GMT. The time now is 04:39 PM.



Powered by vBulletin® Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0 PL2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45