Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 9th, 2009, 03:47 PM
Lovecraft Lovecraft is offline
Infrequent Poster
 
Join Date: Mar 2008
Posts: 13
Question Am I experiencing something, or is a site a victim...

...of some sort of DNS hijack?

I wanted to remind myself of the link to the e-book reader Ubook, so obviously I typed it into Google. The first result is its official page, www.gowerpoint.com. However, if I click that, a random page, usually of a fake "virus scanner" or a Russian pseudo-porn site opens. The same happens with YahooSearch results. Curiously, if I disable referer, the page that opens seems to be the actual Gowerpoint.com.

Is anyone else experiencing this, meaning that (I assume) gowerpoint.com is a victim of some sort of URL hijacking attempt, or is there (gulp) something lurking on my system...? (Rootkit scans show nothing, the browser - Firefox - is in a sandbox)
  #2  
Old January 9th, 2009, 03:50 PM
Lovecraft Lovecraft is offline
Infrequent Poster
 
Join Date: Mar 2008
Posts: 13
Default Re: Am I experiencing something, or is a site a victim...

Curiously, too, clicking the www.gowerpoint.com link in the above message seems to open the proper page. The bad pages seem to only open from Google & Yahoo. I've tried several other terms to see if it's me after all, but all other searches open the proper target pages... only "ubook" results in the bizarre fake link.
  #3  
Old January 9th, 2009, 03:59 PM
Rmus Rmus is offline
Exploit Analyst
 
Join Date: Mar 2005
Posts: 3,624
Default Re: Am I experiencing something, or is a site a victim...

Can you post a screen shot of the search page?

thanks,

----
rich
  #4  
Old January 9th, 2009, 04:08 PM
Lovecraft Lovecraft is offline
Infrequent Poster
 
Join Date: Mar 2008
Posts: 13
Default Re: Am I experiencing something, or is a site a victim...

http://img220.imageshack.us/img220/2327/bbbne8.jpg

My own hosts file is also clean.
  #5  
Old January 9th, 2009, 04:15 PM
Rmus Rmus is offline
Exploit Analyst
 
Join Date: Mar 2005
Posts: 3,624
Default Re: Am I experiencing something, or is a site a victim...

Could you post a larger image?

Meanwhile, that site does not load here from Google nor Yahoo if I enable refererrer logging.

----
rich
  #6  
Old January 9th, 2009, 04:20 PM
Rmus Rmus is offline
Exploit Analyst
 
Join Date: Mar 2005
Posts: 3,624
Default Re: Am I experiencing something, or is a site a victim...

OK, thanks.

See this article, where the Google page is injected with bogus URLs. This doesn't seem to be related to your situation.

Troublesome Google hijacking - redirects results through 7.7.7.0
http://madmarvonline.com/blog/2009/0...-through-7770/

Since the page no longer loads from the search engine with referrer logging enabled, a good guess is that the russian site is not working.

But not enough information is available to determine if this is related to the old Goggle referrer exploit.

----
rich
  #7  
Old January 9th, 2009, 04:52 PM
Rmus Rmus is offline
Exploit Analyst
 
Join Date: Mar 2005
Posts: 3,624
Default Re: Am I experiencing something, or is a site a victim...

The exploit is now working again from Google. With the firewall set to alert, we can follow the steps.

First, the connection out to gowerpoint.com:

Name:  ubook-1.gif
Views: 131
Size:  13.5 KB

Name:  ubook-5.gif
Views: 131
Size:  9.9 KB

Then the first redirect to a russian site. Note that gowerpoint.com still shows in the status bar>

Name:  UBOOK-2.gif
Views: 131
Size:  15.0 KB

Now, another redirect:

Name:  ubook-3.gif
Views: 132
Size:  14.4 KB

And finally to the bogus antivirus site:

Name:  ubook-4.gif
Views: 136
Size:  20.6 KB

This is a classic Referrer exploit and the webmaster for gowerpoint.com needs to be notified.

----
rich
  #8  
Old January 9th, 2009, 05:50 PM
Lovecraft Lovecraft is offline
Infrequent Poster
 
Join Date: Mar 2008
Posts: 13
Default Re: Am I experiencing something, or is a site a victim...

Ah, I was suspecting something of the sort... thanks.
  #9  
Old January 10th, 2009, 02:45 PM
Rmus Rmus is offline
Exploit Analyst
 
Join Date: Mar 2005
Posts: 3,624
Default Re: Am I experiencing something, or is a site a victim...

I contacted the web site and the owner responded that he was not aware of this problem. But he has been looking for a new hosting company for a while because of some other issues, so plans to change soon.

Some of you may remember the SloanTreeFarm exploit a while back, discovered by noway - there was a long thread on it here. The owner of the site joined in the discussion and it was finally determined that it was a problem at the hosting company.

Evidently, as with XSS and SQL injection, there are tools that let hackers determine where vulnerabilities are. Once identified, it is rather easy to create the exploit.

----
rich
  #10  
Old January 10th, 2009, 10:21 PM
EASTER's Avatar
EASTER EASTER is offline
Massive Poster
 
Join Date: Jul 2007
Location: U.S.A. (South)
Posts: 4,506
Default Re: Am I experiencing something, or is a site a victim...

This exploit is being forced onto unsuspecting hosting companys as well as their customers websites are being laced with those type exploits because i have randomly run into that AV 2009 rogue page many times in the past 3 months alone without the owner knowing they been hacked with it.

And oddly enough those creeps are targetting the highest Google ratings for maximum distribution of their sneaky garabage exploit. So be on the watch even when innocently googling because this is epedemic right now and when one website fixes it they look for others to infect.

EASTER
__________________
★AX 64 Time Machine★
★Shadow Defender★| EQSecure v4.0 Beta3 |#Sandboxie 4.08 beta# |FirstDefense-ISR|★FileChangeAlarm★ |Linux Mint 14
Maxthon 3.3.6 | X Iron 17.0 | Chromium 19.0 | CometBird 11

Microsoft Windows 8 64bit (UEFI/GPT) Secure Boot
  #11  
Old January 11th, 2009, 09:25 AM
Lovecraft Lovecraft is offline
Infrequent Poster
 
Join Date: Mar 2008
Posts: 13
Default Re: Am I experiencing something, or is a site a victim...

I do hope a permanent solution against this is found, because the scum could easily use this method in an infinitely more dangerous way (which I better not suggest here )...
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:48 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums