[ Catch 22 @ 18.11.2009. 22:50 ] @
Članak poznatog IT magazina ZDNet o preko 200.000(!) inficiranih sajtova koji upućuju posetioce ka lažnom sigurnosnom softveru, koji bi trebalo da instaliraju (Inst_58s6.exe), poznatijem kao "scareware"...

Thousands of web sites compromised, redirect to scareware

Citat:

November 17th, 2009
Thousands of web sites compromised, redirect to scareware


Security researchers have detected a massive blackhat SEO (search engine optimization) campaign consisting of over 200,000 compromised web sites, all redirecting to fake security software (Inst_58s6.exe), commonly referred to as scareware.

More details on the campaign:


The compromised sites are using legitimately looking templates using automatically generated bogus content, with a tiny css.js (Trojan-Downloader.JS.FraudLoad) uploaded on each of them which triggers the scareware campaign only if the visitor is coming a search engine listed as known http referrer by the gang - in this case Google, Yahoo, Live, Altavista, and Baidu
...


Ostatak teksta na gornjem linku