RSS
Follow us on:
  • Recommend:
  • 0 Comments
  • Print

Super Bowl Virus Spreads

The game's over and patches are available, but many sites are infected with malicious code.

Security experts are finding an increasing number of Web sites hosting malicious JavaScript code first detected on Super Bowl-related sites last week.

Sites covering topics ranging from health care to government have been hacked to host the JavaScript, SANS Internet Storm Center Director Marcus H. Sachs wrote on the SANS blog, listing some of the hacked sites.

"System administrators might want to check their network flow logs for any traffic to these sites and for any traffic to the five sites that hosted the hostile JavaScript," Sachs wrote.

Patches Available

The attack targets two known vulnerabilities in Microsoft Windows, for which Microsoft introduced patches in April and in January.

Computers with unpatched software are vulnerable to the attack. If one of the hacked sites is visited, the JavaScript code directs the browser to a second Web server, based in China, and tries to install a Trojan Horse downloader and password-stealing program on the victim's computer.

Bowl Site Hit First

Initially, the exploit appeared isolated to Web sites related to U.S. football, as hackers tried to capitalize on the surge of traffic to sites concerning the Super Bowl sporting event, which was played on Sunday. The site of the Miami Dolphins team, and another site for its stadium, were hacked, although they were eventually cleaned up.

Security company Websense reported the problem on the stadium site on Friday. Websense recommended users stay away from the affected sites until they had been cleaned up.

Would you recommend this story? YES NO

  • Recommend:
  • 0 Comments
  • Print
Comments

Subscribe to the Security & Privacy Newsletter - weekly

See All Newsletters »
Lenovo Laptop Deals

Subscribe to the Security & Privacy Newsletter - weekly

See All Newsletters »
Today's Special Offers