Advertisement
Promo

Security threats Toolkit

'Survivor' site contains malicious code

Andrew Colley ZDNet Australia

Published: 13 May 2004 10:35 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A Web site likely to attract fans of the CBS-owned television series Survivor could contain a nasty surprise for its visitors.

The site, owned by a party that has licensed the word "survivor" in a top-level US domain -- not linked to the television network -- today contained a smorgasbord of malicious code embedded in HTML scripts.

A concerned Web user alerted ZDNet Australia about the site after noticing that content on the site had triggered his antivirus software.

Users who visit the site without adequate antivirus protection on their PCs are at risk of being infected by three Trojans coded into scripts maliciously embedded in its content: VBS/Psyme, Debeski and Java Script/IE.startgen.d.

The Trojans take advantage of known exploits in Microsoft ActiveX, Internet Explorer and Java virtual machine.

While antivirus vendors only rank the script Trojans as moderate or low risks, they may be designed to prompt a computer accessing the site to automatically download a secondary payload from another location on the Internet.

At this stage antivirus vendors that ZDNet Australia has approached have not revealed what the payload is, but miscreants have recently contrived similar forms of attack into maliciously designed HTML emails MessageLabs detected this month.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
71 out of 160 people found this useful


Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters