Advertisement
Promo

Security threats Toolkit

Latest MyDoom worm exploits Web site guestbooks

Ingrid Marson ZDNet

Published: 16 Aug 2004 17:30 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new variant of the MyDoom worm discovered on Tuesday downloads malware from an MP3-downloading site and a personal Web site, according to security experts, who claim that hackers have compromised these sites by exploiting scripting vulnerabilities in their guestbooks.

Security company F-secure is trying to close down the hacked sites but has not yet managed to contact the US-based site administrators or ISPs hosting the threat. Mikko Hyppönen, director of antivirus research at F-Secure, warned that until the sites are brought down and the security holes closed, the worm, MyDoom.S, will continue to cause problems.

"As long as the sites are up and running we have to keep monitoring them," says Hyppönen. "The hackers can keep changing what is on the sites -- if we block a data-stealing Trojan, they can simply replace that with a different application."

Many Web developers use standard scripts to add features to their sites such as guestbooks or feedback forms. Hyppönen warns that these scripts create security problems.

"If a script is very popular and lots of sites use it, then it is vulnerable to being hacked," he says. "Hackers can quickly scan a large number of different Web sites to find those which have vulnerable applications."

F-secure recommends that companies protect themselves by setting their firewalls to block the URLs of the compromised Web sites, www.richcolour.com and www.zenandjuice.com. More details of the MyDoom.S can be found here.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
111 out of 212 people found this useful


Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters