Welcome to WebProNews Breaking eBusiness and Search News
Advertise | Newsletter | Sitemap | News Feeds News Feed 
 WebProNews Search Part of the iEntry network iEntry inc. 

Dolphin Stadium Sacked By Hackers

David A. Utter
Staff Writer
Published: 2007-02-02

WebProNews RSS Feed


Do not visit the Dolphin Stadium website. It's been hacked with malicious code placed on the server, as security firm Websense Security Labs discovered.

There is a wicked little piece of JavaScript in place on the site in question. By visiting the site, the code gets triggered and a couple of exploit attempts commence. Websense reported more in their alert:

The site is linked from numerous official Super Bowl websites and various Super Bowl-related search terms return links to the site.

A link to a malicious javascript file has been inserted into the header of the front page of the site. Visitors to the site execute the script, which attempts to exploit two vulnerabilities: MS06-014 and MS07-004. Both of these exploits attempt to download and execute a malicious file.

The file that is downloaded is a NsPack-packed Trojan keylogger/backdoor, providing the attacker with full access to the compromised computer. The filename is w1c.exe and its MD5 is ad3da9674080a9edbf9e084c10e80516

The first exploit focuses on a Microsoft Data Access Component flaw reported last April. The other exploit just received a patch in January, to correct a vulnerability in Vector Markup Language that could permit remote code execution.

Although the site owner has been notified, Websense has not seen the code being removed from the site's headers yet. The exploits they have found affect Windows, but if the site has been hacked to place the JavaScript on it, the possibility exists that other malware affecting other operating systems, like cross-site scripting or OS-specific attacks, could be present.

---
Tag:

Add to Del.icio.us | Digg | Reddit | Furl

Bookmark WebProNews:



View All Articles by David A. Utter



Receive Our Daily Email of Breaking eBusiness News


About the Author:
David Utter is a staff writer for WebProNews covering technology and business.

WebProNews RSS Feed

More Top News Articles

Contact WebProNews
Advertisement





TOP NEWS

WebProBlog
The official blog of WebProNews.

Go to WebProBlog

Targeted Information for Business
WebProNews is part of the iEntry network

Internet Business: Marketing: Small Business:
WebProNews MarketingNewz SmallBusinessNewz
WebProWorld AdvertisingDay PromoteNews
EcommNewz SalesNewz EntrepreneurNewz

Software: Search Engines: Web Design:
WebMasterFree Jayde B2B DesignNewz
NetworkingFiles SearchZA FlashNewz
SecurityConfig SearchNewz WebSiteNotes

Developer: IT Management: Security:
DevWebPro ITManagement SecurityProNews
DevNewz SysAdminNews SecurityConfig
TheDevWeb NetworkingFiles NetworkNewz

The iEntry Network consists of over 100 web publications reaching millions of Internet Professionals. Contact us to advertise.
eBUSINESS RESOURCES






 Advertise | Contact Us | Corporate | Newsletter | Sitemap | Submit an Article | News Feeds
 WebProNews is an iEntry, Inc. ® publication - $line) { echo $line ; } ?> All Rights Reserved
WebProWorld
Ten most recent posts.


SearchBrains.com
NetworkingFiles
Featured Software


About WebProNews
WebProNews is the number one source for eBusiness News. Over 5 million eBusiness professionals read WebProNews and other iEntry business and tech publications.

WebProNews provides real-time coverage of internet business.

Free Email Newsletters:
WebProNews SearchNewz
WebProWorld DevWebPro
Marketing SecurityNews
Plus over 100 other newsletters!

Send me relevant info on products and services.


iEntry.com WebProWorld RSS Feed WebProWorld Contact WebProNews Print Version Email a friend Bookmark us SearchBrains.com SearchBrains RSS Feed