HTML/Javascript attached emails
15-06-2010, 10:18
|
#1
|
|
Inactive
Join Date: Dec 2007
Posts: 18,385
|
HTML/Javascript attached emails
Just a word of warning guys, there's aquite a few emails going around with a HTML attachment which contains some nice little javascript that will probably either bypass your firewall or give them all of your details.
I've had two types atm
First one is
Quote:
Hey there.
Because of the measures taken to provide safety to our clients, your password has been changed.
You can find your new password in attached document.
Yours,
Facebook=
facebook_newpass.html
|
and the second (since deleted) was from my email administrator telling me that my account had been accessed by a thrid party and could I follow the link to reset the password (really weird that one as I only use my own domains and I fully administrate it myself) but I can see a few people getting caught.
So watch out guys as these files are NOT being caught by any virus checkers atm.
|
|
|
15-06-2010, 10:48
|
#2
|
|
Inactive
Join Date: Feb 2004
Location: There's no place like 127.0.0.1
Services: Depends on the person and the price they're offering
Posts: 12,384
|
Re: HTML/Javascript attached emails
Don't suppose you've still got the attachment or the script by any chance?
|
|
|
15-06-2010, 10:49
|
#3
|
|
Inactive
Join Date: Dec 2007
Posts: 18,385
|
Re: HTML/Javascript attached emails
Yep, will zip and send to you
|
|
|
15-06-2010, 10:50
|
#4
|
|
Inactive
Join Date: Feb 2004
Location: There's no place like 127.0.0.1
Services: Depends on the person and the price they're offering
Posts: 12,384
|
Re: HTML/Javascript attached emails
Thx, I'll PM you a different email address - slightly safer one
|
|
|
15-06-2010, 10:53
|
#5
|
|
Inactive
Join Date: Dec 2007
Posts: 18,385
|
Re: HTML/Javascript attached emails
Oh, too late, it's gone to your registered address.. It's quite safe and RAR'd up
|
|
|
15-06-2010, 10:58
|
#6
|
|
Inactive
Join Date: Feb 2004
Location: There's no place like 127.0.0.1
Services: Depends on the person and the price they're offering
Posts: 12,384
|
Re: HTML/Javascript attached emails
Ok, thanks
|
|
|
15-06-2010, 11:00
|
#7
|
|
Inactive
Join Date: Dec 2007
Posts: 18,385
|
Re: HTML/Javascript attached emails
Just found out more info on it, turns out it's just a simple compessed script with a redirect to a pharmasutical spam site
http://translate.google.co.uk/transl...lab.com%2Fasec
Link to Korean blog where they've investigated the script (through google translate)
Either way you just know the destination site has got the full spyware/adware packages on it
|
|
|
15-06-2010, 11:14
|
#8
|
|
Inactive
Join Date: Feb 2004
Location: There's no place like 127.0.0.1
Services: Depends on the person and the price they're offering
Posts: 12,384
|
Re: HTML/Javascript attached emails
Yup.
Just done some playing with the script myself, it's pretty simple as you say - I went to that site very carefully, I didn't do any real poking around but as you say I'm sure it will be full of all sorts of nasty crap.
|
|
|
15-06-2010, 11:16
|
#9
|
|
Inactive
Join Date: Dec 2007
Posts: 18,385
|
Re: HTML/Javascript attached emails
I wonder what else they'll try next ??
|
|
|
22-06-2010, 11:42
|
#10
|
|
Inactive
Join Date: Dec 2007
Posts: 18,385
|
Re: HTML/Javascript attached emails
Norton, Microsoft, AVG and a few others are now starting to catch this javascript redirector  Just got a new one from PayPaI.com (yes paypai and not paypal  )
|
|
|
22-06-2010, 18:32
|
#11
|
|
cf.geek
Join Date: May 2008
Location: Wherever i lay my hat!
Age: 54
Posts: 736
|
Re: HTML/Javascript attached emails
On a slightly different note also be aware that quite a few Java exploits are going around in the wild, some from legit websites, blogs, etc.
I know there are a lot of Java based apps out there but if you don`t really use/need it, is it worth having it installed seen as the bad guys seem to be targeting it more often (plus Sun/Oracle`s dire security patching)
At the very least if your a 32Bit user you could use sandboxie thus mitigating the risk.
Some debate here http://krebsonsecurity.com/2010/06/d...-java-junk-it/
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +1. The time now is 20:58.
|