Forum     

Go Back   Digit Technology Discussion Forum > Bandwidth Wastage > Chit-Chat
Register FAQ Calendar Mark Forums Read

Chit-Chat General discussions about anything that doesn't fit into the other sections to be had here

Closed Thread
 
LinkBack Thread Tools Display Modes
Old 01-09-2007, 08:32 AM   #1 (permalink)
Alpha Geek
 
Join Date: May 2005
Posts: 687
Default Bank of India site hijacked..lolz with video..don't miss it.

The Bank of India Web site has been hijacked by online criminals and is being used to serve up rootkits and backdoor Trojans on unpatched Windows machines.

Malware hunters at Sunbelt Software are warning that a snippet of code has been planted into the Bank of India Web site to redirect surfers to an exploit server.



Ryan Naraine Tracking the hackers Subscribe Alerts Bio Mobile
Pick a blog category Apple Black Hat Black Hat Federal Botnets Browsers Cisco Data theft Digital rights management Exploit code Firefox Google Hackers Hirings and firings McAfee Metasploit Microsoft Mozilla Open source Oracle Passwords Patch Watch Pen testing Piracy Privacy Punditocracy Responsible disclosure Rootkits Spam and Phishing Spyware and Adware Symantec Uncategorized Viruses and Worms Vulnerability research Wi-Fi security Windows Vista Wireless Zero-day attacks August 30th, 2007
Bank of India site hijacked, launching exploits
Posted by Ryan Naraine @ 3:26 pm

Categories: Patch Watch, Hackers, Zero-day attacks, Microsoft, Browsers, Rootkits, Vulnerability research, Responsible disclosure, Spam and Phishing, Spyware and Adware, Botnets, Exploit code, Viruses and Worms, Data theft, Pen testing, Digital rights management, Firefox, Metasploit, Passwords

Tags: Bank, Trojan Horse, Malware, Server, Sunbelt Software, Attack, Bank Of India Web Site, Ryan Naraine
+23
28 votes
Worthwhile? The Bank of India Web site has been hijacked by online criminals and is being used to serve up rootkits and backdoor Trojans on unpatched Windows machines.

Malware hunters at Sunbelt Software are warning that a snippet of code has been planted into the Bank of India Web site to redirect surfers to an exploit server.



There is evidence that the Russian Business Network (RBN), a group known for aggressive malware attacks, is behind this latest high-profile site compromise.

The RBN has been closely linked to the virulent Storm Worm attacks, VML, phishing, child pornography, Torpig, Rustock, and many other criminal attacks to date.

The Bank of India redirect is sending Windows users to a server hosting an e-mail worm file, two rootkits, two Trojan downloaders and three backdoor Trojans.

“Fully patched systems are likely unaffected,” Sunbelt Software president Alex Eckelberry said.

A source tracking the attack tells me the IcePack exploit launcher is the back-end being used for this run of drive-by downloads.

Download video:

Code:
http://rapidshare.com/files/52585970/boi.wmv
these video from Roger Thompson at Exploit Prevention Labs shows the kind of damage that’s done when an unpatched machine simply surfs to the Bank of India home page.

It’s been almost seven hours since the compromise was discovered but Bank of India is still serving up the malicious redirect code. Malware researchers are working behind the scenes to make contact with the authorities to get the site cleaned and patched.

The Bank of India site is now disinfected. This note appears on the home page:

This site is under temporary maintenance and will be available after 19:30 IST



To get a thorough understanding of what was happening at Bank of India during the site compromise read :

Code:
http://ddanchev.blogspot.com/2007/08/bank-of-india-serving-malware.html

of this attack, which used fast-flux networks to run multiple malware campaigns.



Hackers were greate...........
__________________
Any use of the collective descriptions and shared knowledge from any of my posts are at the sole discretion of the reader.I am not responsible for what you do with it.
rajas700 is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 01-09-2007, 01:47 PM   #2 (permalink)
-The BlacKCoaT Operative-
 
Rollercoaster's Avatar
 
Join Date: Mar 2005
Location: Dehradun, India
Posts: 1,205
Default Re: Bank of India site hijacked..lolz with video..don't miss it.

Pwned!
__________________
--------------------------------------------
Holding my last breath, safe inside myself.....
--------------------------------------------
I dont use my computer. I misuse it- रोलरकोस्टर
Rollercoaster is offline  
Old 09-09-2007, 03:17 PM   #3 (permalink)
Apprentice
 
vivekrules's Avatar
 
Join Date: Aug 2007
Posts: 55
Default Re: Bank of India site hijacked..lolz with video..don't miss it.

Damn !!!!!!!!!!!!
__________________
Life Is Beautiful !!
vivekrules is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Which is the best private bank in India? aryayush Chit-Chat 36 30-07-2007 02:01 PM
HDFC BANK --- a bank which is becoming worst day-by-day vickyadvani Chit-Chat 18 29-07-2007 10:14 AM
SonyEricsson India Site Stick Mobiles and Tablets 2 17-02-2007 10:06 AM
Is there any site available for info on all the available laptops in India? aryayush Laptops and Netbooks 7 01-08-2006 06:10 PM


All times are GMT +5.5. The time now is 04:06 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2