« Koobface Worm on the rise again
New DNS Changer Trojan »

Firefox 3.5 exploit (with out of date plugins)

July 7th, 2009

Edit: As reported by F-Secure, this is not an exploit with Firefox itself. It is using out of date plugins to launch its payload.

Sorry for the confusion.

Think you are safe browsing the web with the latest version of Firefox? Well, maybe not…

Today I found a malicious web site that triggers a drive-by download and will infect your PC. You can watch it happen here.

Interestingly, IE7 is not vulnerable to the attack. The browser will crash instead of letting the payload happen:

crash

The exploit seems to be triggered by a malicious JavaScript line:

exploit1

exploit2

At first I thought that the domain pushing this malicious JavaScript had been hacked, but I’m not so sure now. Or at least, it has some rather odd connections (same nameserver), like porn sites???

domains sharing nameservers under another name 6.21.72.in-addr.arpa

7.21.72.in-addr.arpa

adagencypro.com

arpsystems.com

bigblogworld.com

blogsbyindia.com

buy-web-site-traffic.net

buy-web-traffic.net

buy-website-traffic.net

byindia.com

byindia.net

centurygroupus.com

cheapcoder.com

classifiedsbyindia.com

constituentbuilder.com

crayground.com

directorybyindia.com

ebenefitsprocessing.com

emailresponsepro.com

familyhomepages.com

flyadspro.com

free-movie-porn.net

freeseal.net

freestuffmakemoney.com

funnyphotos-funnyvideos.com

funnyvideoworld.com

getmyfreeseal.com

getmyseal.com

getmyseal.net

hobbitsloveal.com

hobbitsloverandy.com

hothomepages.com

improve-search-engine-ranking.net

live-websupport.com

live-websupport.net

miilikewii.com

millionnewjobs.com

miredlatina.com

mycollegemates.com

myjokespace.com

mylaughspace.com

myprayerclub.com

myprayersclub.com

mysickspot.com

mywhipspot.com

nightwolfemedia.com

onlinepulpit.com

picturesofporn.net

porn-gallery-free.com

pornpicfree.net

searchbyindia.com

searchenginerankingcompany.net

sexyhomepages.com

sexysupplystore.com

sickspot.com

tuluso.net

video-free-porn.com

voiceresponsepro.com

web-site-rank.com

web2corp.com

web2corporation.com

web2corporation.net

websiteowner.com

websitepromotionsscompany.com

Those sites are dangerous, please use caution!

Jerome Segura

    This entry was posted on Tuesday, July 7th, 2009 at 10:40 am and is filed under Exploits. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    1.      by
    2.      by
    3.      by
    • (2) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (33)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (15)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (110)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.