nasty new url insertion program

From: Alex Gogan (alex_at_fbi.ie)
Date: 10/01/04

  • Next message: David Gillett: "RE: Layer 2 Switches"
    Date: Fri, 01 Oct 2004 13:20:54 +0100
    To: security-basics@securityfocus.com
    
    
    

    Hi All,

    Just a quick note, a client rang me this morning in a panic saying the
    site we developed and hosted was compromised, what was happening was
    every time he made a change on the CMS system to one of the pages, where
    there was a URL field it would (he was unaware) insert
    "http://younghotgirls.net/2504/" it was only when he was checking the
    pages online did he notice this.

    Needless to say I told him to download the spy ware and antivirus to try
    and catch this but I must admit I find this troubling.

    Has anybody else found or heard of something similar ??

    -- 
    Alex Gogan
    alex@fbi.ie
    Future Business Intercommunications
    ~The Complete Internet Services Company~
    http://www.fbi.ie
    Communications House
    11 Leeson Park Villas, Sallymount Avenue, Ranelagh,
    Dublin 6, Ireland
    Tel:+353.14988588 | Fax: +353.14988589
    Web: www.fbi.ie | Email: alex@fbi.ie
    

  • Next message: David Gillett: "RE: Layer 2 Switches"