Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | HTML/Javascript attached emails

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

HTML/Javascript attached emails
Reply
 
Thread Tools
Old 15-06-2010, 10:18   #1
Kymmy
Inactive
 
Join Date: Dec 2007
Posts: 18,385
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Exclamation HTML/Javascript attached emails

Just a word of warning guys, there's aquite a few emails going around with a HTML attachment which contains some nice little javascript that will probably either bypass your firewall or give them all of your details.

I've had two types atm

First one is

Quote:
Hey there.

Because of the measures taken to provide safety to our clients, your password has been changed.
You can find your new password in attached document.

Yours,
Facebook=


facebook_newpass.html
and the second (since deleted) was from my email administrator telling me that my account had been accessed by a thrid party and could I follow the link to reset the password (really weird that one as I only use my own domains and I fully administrate it myself) but I can see a few people getting caught.

So watch out guys as these files are NOT being caught by any virus checkers atm.
Kymmy is offline   Reply With Quote
Advertisement
Old 15-06-2010, 10:48   #2
Raistlin
Inactive
 
Join Date: Feb 2004
Location: There's no place like 127.0.0.1
Services: Depends on the person and the price they're offering
Posts: 12,384
Raistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered stars
Raistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered stars
Re: HTML/Javascript attached emails

Don't suppose you've still got the attachment or the script by any chance?
Raistlin is offline   Reply With Quote
Old 15-06-2010, 10:49   #3
Kymmy
Inactive
 
Join Date: Dec 2007
Posts: 18,385
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: HTML/Javascript attached emails

Yep, will zip and send to you
Kymmy is offline   Reply With Quote
Old 15-06-2010, 10:50   #4
Raistlin
Inactive
 
Join Date: Feb 2004
Location: There's no place like 127.0.0.1
Services: Depends on the person and the price they're offering
Posts: 12,384
Raistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered stars
Raistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered stars
Re: HTML/Javascript attached emails

Thx, I'll PM you a different email address - slightly safer one
Raistlin is offline   Reply With Quote
Old 15-06-2010, 10:53   #5
Kymmy
Inactive
 
Join Date: Dec 2007
Posts: 18,385
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: HTML/Javascript attached emails

Oh, too late, it's gone to your registered address.. It's quite safe and RAR'd up
Kymmy is offline   Reply With Quote
Old 15-06-2010, 10:58   #6
Raistlin
Inactive
 
Join Date: Feb 2004
Location: There's no place like 127.0.0.1
Services: Depends on the person and the price they're offering
Posts: 12,384
Raistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered stars
Raistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered stars
Re: HTML/Javascript attached emails

Ok, thanks
Raistlin is offline   Reply With Quote
Old 15-06-2010, 11:00   #7
Kymmy
Inactive
 
Join Date: Dec 2007
Posts: 18,385
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: HTML/Javascript attached emails

Just found out more info on it, turns out it's just a simple compessed script with a redirect to a pharmasutical spam site

http://translate.google.co.uk/transl...lab.com%2Fasec

Link to Korean blog where they've investigated the script (through google translate)

Either way you just know the destination site has got the full spyware/adware packages on it
Kymmy is offline   Reply With Quote
Old 15-06-2010, 11:14   #8
Raistlin
Inactive
 
Join Date: Feb 2004
Location: There's no place like 127.0.0.1
Services: Depends on the person and the price they're offering
Posts: 12,384
Raistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered stars
Raistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered stars
Re: HTML/Javascript attached emails

Yup.

Just done some playing with the script myself, it's pretty simple as you say - I went to that site very carefully, I didn't do any real poking around but as you say I'm sure it will be full of all sorts of nasty crap.
Raistlin is offline   Reply With Quote
Old 15-06-2010, 11:16   #9
Kymmy
Inactive
 
Join Date: Dec 2007
Posts: 18,385
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: HTML/Javascript attached emails

I wonder what else they'll try next ??
Kymmy is offline   Reply With Quote
Old 22-06-2010, 11:42   #10
Kymmy
Inactive
 
Join Date: Dec 2007
Posts: 18,385
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: HTML/Javascript attached emails

Norton, Microsoft, AVG and a few others are now starting to catch this javascript redirector Just got a new one from PayPaI.com (yes paypai and not paypal )
Kymmy is offline   Reply With Quote
Old 22-06-2010, 18:32   #11
Matty_
cf.geek
 
Join Date: May 2008
Location: Wherever i lay my hat!
Age: 54
Posts: 736
Matty_ has reached the bronze age
Matty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze age
Re: HTML/Javascript attached emails

On a slightly different note also be aware that quite a few Java exploits are going around in the wild, some from legit websites, blogs, etc.

I know there are a lot of Java based apps out there but if you don`t really use/need it, is it worth having it installed seen as the bad guys seem to be targeting it more often (plus Sun/Oracle`s dire security patching)

At the very least if your a 32Bit user you could use sandboxie thus mitigating the risk.

Some debate here http://krebsonsecurity.com/2010/06/d...-java-junk-it/
Matty_ is offline   Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 09:02.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum