Phishing campaign uses UPS.com XSS vulnerability to distribute malware

Discussion in 'malware problems & news' started by guest, Aug 23, 2021.

  1. guest

    guest Guest

    Phishing campaign uses UPS.com XSS vuln to distribute malware
    August 23, 2021
    https://www.bleepingcomputer.com/ne...n-uses-upscom-xss-vuln-to-distribute-malware/
     
  2. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    With Micro there's one thing you can always count on. Wonders never cease. Novel intrusions either.
     
  3. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,066
    Location:
    Canada
    This just proves that XSS vulnerabilities should still be considered as a serious threat.
     
  4. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    To be honest, I didn't fully understand the attack, perhaps I should read it again. But wouldn't an adblocker like uBlock protect against this? And I thought browsers were already hardened against these type of attacks.
     
  5. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,066
    Location:
    Canada
    Absolutely yes, unless the end user allows the script.
     
  6. Bertazzoni

    Bertazzoni Registered Member

    Joined:
    Apr 13, 2018
    Posts:
    657
    Location:
    Milan, Italia
    Netcraft is one extension worth having for any sensitive web browsing like banking, etc., especially if you don't use Edge. And it's a trusted vendor.
     
  7. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,066
    Location:
    Canada
    I'm not typically a fan of extensions that utilize community feedback for even part of their functionality, but this one does look decent. Thanks.
     
  8. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
    I have been using the Netcraft extension for years for chrome on W10 and have it on my Android phone.
     
  9. Daveski17

    Daveski17 Registered Member

    Joined:
    Nov 11, 2008
    Posts:
    10,239
    Location:
    Lloegyr
    Netcraft looks useful, I believe they're based in Bath (The 'Georgian' City). Nice place. I once took a bath in Bath. Honestly.
     
    Last edited: Aug 30, 2021
  10. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I believe this is what I often get to see on adult sites, after clicking on certain links they try to redirect you to some other site that you didn't want to visit, I suppose this is about the same.

    I totally forgot about these guys, the Netcraft extension does indeed seem to be quite useful, thanks.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.