Hacking the Web: Hijacking search results

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
In this post, the first of a new series of posts in which I plan to expose some of the more interesting web attacks we encounter, I will describe some recent attacks that we have been following in which the victim's browser is 0wned, and their search results hijacked.

Attack overview

Infection triggers:
Browsing compromised sites
search engine optimisation (SEO)
Exploits:
CVE-2010-0840 (Java)
CVE-2010-0806 (uninitialized memory corruption vulnerability in IE)
CVE-2010-0886 (Java)
CVE-2010-1885 (Windows Help Center URL validation vulnerability)
Payload: Install rogue Firefox extension, to display popups and hijack search results
Threat names: Mal/Iframe-Gen, Mal/JavaDldr-B, Exp/CVE10-0840, Troj/ExpJS-BM, Mal/HcpExpl-A,

Read more - link
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top