Another Website Poisoning Attack

LOS ANGELES – Hackers have succeeded in poisoning thousands of small e-commerce operations, planting a malicious code that in turn infects visitors to the host website.

Coming on the heels of recent, similar attacks on Flash files and the Real player, the latest of these campaigns also targets computers running Microsoft's Windows operating system, allowing hackers to steal passwords, system information and reports on Internet surfing preferences, along with online bank account information, login names and more.

Estimates vary on the size of the attack, which could have compromised up to 10,000 compromised computer systems.

"It's safe to say that there are thousands of these out there," Yuval Ben-Itzhak, security firm Finjan's CTO, said.

Researchers haven't uncovered all of the new attacks secrets, which they've been monitoring since December, but say that the poisoned websites rely on similar server and administration software.

"We know some of the methods," Ben-Itzhak said. "They are trying to exploit known vulnerabilities in open source content management software that the sites are using."

Many adult websites are driven by content management systems (CMS), which could face similar vulnerabilities to the compromised platforms.

The malicious code hides itself by generating random character names for each unique visitor and by remembering repeat visitors, which are not attacked a second time.

According to Simon Heron, managing director for the security firm Network Box, the attack finds vulnerabilities in common browsing software, and other applications such as instant messaging and multimedia programs, which it can exploit by installing a Trojan that will remain undetected as it waits for sensitive data such as online banking logins to be used.

"It looks like the root kit type technique that we have been worried about for the last two or three years," Heron said. "It's very clever."

Many anti-virus programs fail to detect the presence of the Trojan.

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Cherry Kiss, Derek Kage Cap AEBN's Top Stars for 4th Quarter of 2024

AEBN has revealed its most popular performers in gay and straight theaters for the fourth quarter of 2024.

A Golden Night in Hollywood: 2025 XMAs Shine on Adult Entertainment's Best

To paraphrase the unofficial U.S. Postal Service motto: Neither rain nor cold nor the chaos of natural disasters can stop members of the adult entertainment community from the completion of their appointed duty every January: to honor the artistic and commercial achievements of their peers.

What Changes in DC Could Mean for the Adult Industry

On November 5, 2024, American voters were called to the polls. The results of that election revealed an unquestionably uncomfortable truth for everyone, regardless of party or ideology: the “united” part of United States does not appear to be holding strong.

Byborg Acquires Gamma Entertainment

Luxembourg-based Byborg Enterprises SA has acquired 100% of Canadian adult conglomerate Gamma Entertainment.

Adult Creative Debuts 'Pornful' Website Management Platform

Web design and marketing firm Adult Creative has launched its new Pornful website management platform.

2025 XMA Winners Announced

Winners of the 2025 XMAs were revealed Sunday night during a ceremony hosted by Vanna Bardot and Ryan Reid at the world-famous Hollywood Palladium.

X3 Expo Day 2 Looks at the Industry's Past, and Ahead to Its Future

A gorgeous day in LA saw a massive procession making its way along Sunset Blvd., as hundreds of excited fans headed to the historic Hollywood Palladium for a rendezvous with the galaxy of A-list adult stars awaiting them on Day 2 of the 2025 X3 Expo.

X3 Expo Pops Off With All-Star Lineup

A wave of excited fans cascaded down Sunset Blvd., cresting and breaking with anticipation as they flowed into the historic Hollywood Palladium, where the A-list echelon of the adult world stood ready to greet them, pose with them, chat them up, and showcase the latest in spicy entertainment, as the 2025 X3 Expo popped off.

XBIZ Honors Uplifts Spirits Amid Challenging Times for LA and the Adult Industry

"A bunch of misfit toys." That’s how MojoHost founder Brad Mitchell described himself and his industry peers at the 2025 XBIZ Honors ceremony at Hollywood’s Kimpton Everly Hotel. Everyone cheered in agreement. Frankly, they wouldn’t have it any other way.

Kansas Sues Adult Website Operator Under AV Law

Kansas Attorney General Kris Kobach has filed suit against SARJ LLC, alleging that the company’s adult websites have failed to implement age verification as mandated by state law.

Show More