Botnet forces infected firefox users to hack the sites they visit.

aztony

Level 9
Thread author
Verified
Oct 15, 2013
501
Hacktivism
Botnet forces infected Firefox users to hack the sites they visit

"Advanced Power" automates the process of finding sites vulnerable to data theft.
by Dan Goodin - Dec 16, 2013 4:48 pm UTC

17
advanced-power-640x491.png

Sites browsed by hacked PCs (left) and SQL injection flaws found by the botnet (masked, right).
KrebsonSecurity
Investigative journalist Brian Krebs has uncovered an unusual botnet that forces infected PCs to scour websites for security vulnerabilities that can cough up proprietary data or be exploited in drive-by malware attacks.

The botnet, dubbed "Advanced Power" by its operators, has discovered at least 1,800 webpages vulnerable to SQL injection attacks since May, Krebs reported in a post published Monday. SQL injection vulnerabilities exploit weaknesses in Web applications that allow attackers to send powerful commands to a website's backend databases. From there, attackers can download login credentials or other database contents or cause sites to post links that silently redirect visitors to malicious websites.

Advanced Power masquerades as a legitimate add-on for Mozilla's Firefox browser. Once installed, it looks for vulnerabilities on sites visited by the infected machine.
Continue reading: http://arstechnica.com/security/201...d-firefox-users-to-hack-the-sites-they-visit/
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top