<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Trend Micro Hacked - Serving Malicious Iframes in Security</title>
<link>http://www.dslreports.com/forum/r20211800</link>
<description></description>
<language>en</language>
<pubDate>Tue, 02 Dec 2008 15:59:35 EDT</pubDate>
<lastBuildDate>Tue, 02 Dec 2008 15:59:35 EDT</lastBuildDate>

<item>
<title>Re: Trend Micro Hacked - Serving Malicious Iframes</title>
<link>http://www.dslreports.com/forum/remark,20212604</link>
<description><![CDATA[<A HREF="/useremail/u/170670"><b>JTM1051</b></A> : <div class="bquote"><small>said by  EGeezer <A HREF="/useremail/u/668609"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>...Based on that incident, I'm glad I have NoScript enabled. This goes to demonstrate that "trusted sites" can still serve up malware. ...</div>Ditto; using Fx with NoScript and <u>all</u> the <i>"Additional restrictions for untrusted sites "</i> (NoScript's Options > Plugins) enabled.<br><br>Since I only use IE for few sites that need/work best with IE, easy for me to lock down IE using customized settings for Trusted Sites, all other security zones set to max high settings.<br><br>Also using Online Armor's "Run Safer" setting for Fx, Opera and IE.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20212604</guid>
<pubDate>Sun, 23 Mar 2008 14:13:37 EDT</pubDate>
</item>

<item>
<title>Re: Trend Micro Hacked - Serving Malicious Iframes</title>
<link>http://www.dslreports.com/forum/remark,20211800</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : <div class="bquote"><small>said by  Bubba1 <A HREF="/useremail/u/1395696"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Frustrating.  I operate a locked-down IE7 .. greatly utilizing the trusted/NOT scheme.<br><br>Presently, should KIS7's web protection component fail to detect a trusted(s) compromise .. there is no second line.<br> </div>Does the web scanner of *any* antivirus program really offer any needed protection? <br><br>If the antivirus program is going to catch the threat, would it not catch it just as well without the use of a web scanner?<br><br>I have often wondered if including a web scanner in an antivirus program was more marketing hype than truly being useful. Am I wrong?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20211800</guid>
<pubDate>Sun, 23 Mar 2008 11:17:22 EDT</pubDate>
</item>

<item>
<title>Re: Trend Micro Hacked - Serving Malicious Iframes</title>
<link>http://www.dslreports.com/forum/remark,20169242</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : The infection of legitimate and normally trusted websites also brings mitigation and recovery to the forefront. If one assumes that at some point they may be breached, then they can start putting together a response and recovery plan. One example is a mini-<A HREF="http://www.davis.k12.ut.us/emrprep/excer3.htm"><b>TTX </b></a>where we "pretend" that our PC has been hacked, corrupted, logins stolen, ID and CC info captured etc. and our recent available backups may be suspect. From that point, practice or develop a response and document as needed. <br><br>Although <A HREF="http://www.deq.state.mi.us/documents/deq-wb-wws-Binder9.pdf"><b>this PPT</b></a> relates to school and organizational training, many of the tips for planning and doing the exercise are applicable. <br><small>--<br>Mayors of New York come from nowhere and go nowhere.<br>Wallace Sayre (apparently, so do governors... )</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20169242</guid>
<pubDate>Sat, 15 Mar 2008 12:14:38 EDT</pubDate>
</item>

<item>
<title>Re: Trend Micro Hacked - Serving Malicious Iframes</title>
<link>http://www.dslreports.com/forum/remark,20168925</link>
<description><![CDATA[<A HREF="/useremail/u/429050"><b>La Luna</b></A> : <i>Web Attack on Trend Micro Fails to Infect Users<br>March 14th, 2008 by Trend Micro<br><br>Earlier this week, we realized that part of our public online Virus Encyclopedia (VE) was altered via external hacking.  The redirect placed on our site didn&#8217;t work properly so nobody visiting the hacked pages was at risk of infection.  In response to this incident, we shut down the VE for several hours, patched the systems, removed the inserted code, and brought it back to life again.  We have already taken interim measures to further harden the VE system against future attacks.  This incident was part of a wider attack on Web sites around the world.</i><br><small>--<br><b><A HREF="http://www.thereligionofpeace.com/">10,729 DEADLY TERROR ATTACKS SINCE 9/11</a></b>~~<b><A HREF="/forum/disco">TEAM DISCOVERY</a></b><br><i>Can't feel you anymore, don't need you anymore, don't believe you anymore, I don't need you anymore</i><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20168925</guid>
<pubDate>Sat, 15 Mar 2008 11:03:03 EDT</pubDate>
</item>

<item>
<title>Re: Trend Micro Hacked - Serving Malicious Iframes</title>
<link>http://www.dslreports.com/forum/remark,20168847</link>
<description><![CDATA[<A HREF="/useremail/u/829260"><b>IBK</b></A> : Web Attack on Trend Micro Fails to Infect Users:<br>&raquo;<A HREF="http://blog.trendmicro.com/web-attack-on-trend-micro-fails-to-infect-users/" >blog.trendmicro.com/web-attack-o&middot;&middot;&middot;t-users/</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20168847</guid>
<pubDate>Sat, 15 Mar 2008 10:37:33 EDT</pubDate>
</item>

<item>
<title>Re: Trend Micro Hacked - Serving Malicious Iframes</title>
<link>http://www.dslreports.com/forum/remark,20168769</link>
<description><![CDATA[<A HREF="/useremail/u/1395696"><b>Bubba1</b></A> : <div class="bquote"><small>said by  EGeezer <A HREF="/useremail/u/668609"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>This goes to demonstrate that "trusted sites" can still serve up malware. <br></div>Frustrating.  I operate a locked-down IE7 .. greatly utilizing the trusted/NOT scheme.<br><br>Presently, should KIS7's web protection component fail to detect a trusted(s) compromise .. there is no second line.<br><small>--<br>"Fast is fine, but accuracy is everything" --Wyatt Earp</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20168769</guid>
<pubDate>Sat, 15 Mar 2008 10:13:33 EDT</pubDate>
</item>

<item>
<title>Re: Trend Micro Hacked - Serving Malicious Iframes</title>
<link>http://www.dslreports.com/forum/remark,20162672</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : Good find - <br><br>Based on that incident, I'm glad I have NoScript enabled. This goes to demonstrate that "trusted sites" can still serve up malware. <br><br>It shoots down the often-repeated assumption that "careful browsing" is the silver bullet that eliminates the need for security tools. <br><small>--<br>Mayors of New York come from nowhere and go nowhere.<br>Wallace Sayre (apparently, so do governors... )</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20162672</guid>
<pubDate>Fri, 14 Mar 2008 01:42:40 EDT</pubDate>
</item>

<item>
<title>Re: Trend Micro Hacked - Serving Malicious Iframes</title>
<link>http://www.dslreports.com/forum/remark,20161766</link>
<description><![CDATA[<A HREF="/useremail/u/1215698"><b>mikenolan7</b></A> : Pretty scary.  How long until someone's online scanner, which usually require either ActiveX or Javascript, start infecting machines as people attempt to scan for malware?  That's a nasty vector.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20161766</guid>
<pubDate>Thu, 13 Mar 2008 21:30:36 EDT</pubDate>
</item>

<item>
<title>Re: Trend Micro Hacked - Serving Malicious Iframes</title>
<link>http://www.dslreports.com/forum/remark,20161729</link>
<description><![CDATA[<A HREF="/useremail/u/1531837"><b>Its a Secret</b></A> : Time to lock 'em down hardcore, folks.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20161729</guid>
<pubDate>Thu, 13 Mar 2008 21:23:27 EDT</pubDate>
</item>

<item>
<title>Trend Micro Hacked - Serving Malicious Iframes</title>
<link>http://www.dslreports.com/forum/remark,20161397</link>
<description><![CDATA[<A HREF="/useremail/u/634007"><b>SUMware</b></A> : From The Register</a><br>13th March 2008 -  <blockquote><small>said by The Reg :</small><hr>This week, researchers from the anti-virus provider uncovered at least two high-profile websites hacked so they try to infect visitors with some of the nastiest malware out there.<br><br>But as they were busy pointing out the attacks on web pages belonging to Swedish rock band The Hives and web blogs award site the Bloggies, nearly a dozen Trend Micro pages were busy trying to launch their own assaults, <A HREF="http://www.l.google.com/search?hl=en&q=%22script+src%3Dhttp%3A%2F%2Fwww.2117966.net%2Ffuckjp.js%22+site%3Atrendmicro.com&btnG=Google+Search&aq=f">this Google search</a> shows. The same malicious javascript at the heart of the Trend Micro attack had, at time of writing, managed to inject itself onto <A HREF="http://www.l.google.com/search?hl=en&q=%22script+src%3Dhttp%3A%2F%2Fwww.2117966.net%2Ffuckjp.js%22&btnG=Google+Search&aq=f">almost 23,000 pages</a> in all.<br><br>"Unfortunately, safe surfing measures can be useless as even the most trusted Web sites can be hacked to serve up malware," Trend Micro's JM Hipolito wrote on Monday when analyzing the attack on the Bloggies. Evidently, he didn't know just how correct he was.<br><br>A Trend Micro spokesman said the malicious iframes have already been removed and that steps have been taken to prevent the injection from happening again. He didn't have additional details.<br><br>As we <A HREF="http://www.theregister.co.uk/2008/03/13/mass_compromise/">reported earlier today</a>, the mass infection causes the once-benign sites to turn against their visitors by attempting to install password loggers, backdoors and other types of malware on their machines. The attacks appear to be the handiwork of a single criminal gang, according to McAfee researchers, who first discovered the cluster of hacked sites. They are part of a growing preference of miscreants to spread malware using legitimate websites that have been compromised rather than through destinations specifically set up for that purpose.<br><br>If even security providers like Trend Micro (and <A HREF="http://www.theregister.co.uk/2008/01/08/malicious_website_redirectors/">a few months back, Computer Associates</a>) can't protect their visitors from these assaults, chances are good that plenty of others can't either.<hr></blockquote>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20161397</guid>
<pubDate>Thu, 13 Mar 2008 20:16:16 EDT</pubDate>
</item>

</channel>
</rss>
