Results 1 to 5 of 5

Thread: Nine Ball Web Threat

  1. Registered TeamPlayer
    Join Date
    08-29-08
    Posts
    351
    Post Thanks / Like
    Stat Links

    Nine Ball Web Threat
    Gamer IDs

    Steam ID: cman19
    #1

    Nine Ball Web Threat

    From
    teck.in

    http://teck.in/nine-ball-new-web-thr...-websites.html
    Nine Ball – New Web Threat Infecting Websites

    Posted by Sree Pillai on June 20th, 2009 under category Internet
    Topics: Adobe, Nine Ball, Security, Virus

    Nine Ball is a recent multi-layered Web browser attack that have already infected approximately 40,000 sites. Nine Ball targets legitimate websites to redirect users to malicious sites owned by the attacker and infects PCs through a number of exploits, including Adobe Reader and Quick Time, and then trying to download Trojans and keylogger code without the user’s consent or knowledge. Once infected, anything the victim types can be monitored and used to commit identity theft, such as credit card numbers, passwords and more.

    According to Websense, the compromised website, loaded with malware, will first try to identify a visitor by IP address to discover if it’s a repeat visitor. To evade security researchers and investigators who would likely be among any repeat visitors, the Web page will dump a repeat visitor onto Ask.com.

    If a web visitor is new, the victim is pushed through a few more re-directions to land at the site www.nine2rack.in (sometimes a .cn domain), which may sound like a site in India, but is in Ukraine.

    The final stop for a Web victim includes a drive-by download attempt after the malware checks for vulnerabilities in the browser, Adobe or Quicktime software on the user’s desktop. If it succeeds, the attack will download a Trojan with a keylogger component that many anti-virus software packages do not yet identify, according to Websense.

    There are a number of security failures that can help Nine Ball to compromise so many Web sites, including SQL-injection attacks on susceptible websites as well as bots that have stolen user passwords and logins for administrators of websites.
    thoughts?

  2. Registered TeamPlayer Anti-Squeaker's Avatar
    Join Date
    06-29-07
    Location
    Rock Hill, South Carolina, United States
    Posts
    4,269
    Post Thanks / Like
    Gamer IDs

    Steam ID: Anti-Squeaker
    #2

    Re: Nine Ball Web Threat

    maybe you should take the link down? sounds like its not a site that you want to put on TTP...

  3. Registered TeamPlayer FragRaptor's Avatar
    Join Date
    08-11-07
    Posts
    9,651
    Post Thanks / Like
    Stat Links

    Nine Ball Web Threat Nine Ball Web Threat Nine Ball Web Threat Nine Ball Web Threat Nine Ball Web Threat Nine Ball Web Threat
    Gamer IDs

    Gamertag: FragRaptor Steam ID: FragRaptor
    #3

    Re: Nine Ball Web Threat

    *run virus scan*

  4. Registered TeamPlayer Ruukil's Avatar
    Join Date
    12-28-07
    Posts
    4,888
    Post Thanks / Like
    Blog Entries
    1
    Stat Links

    Nine Ball Web Threat
    Gamer IDs

    Steam ID: Ruukil
    #4

    Re: Nine Ball Web Threat

    Quote Originally Posted by FragRaptor
    *run virus scan*
    *Runs 3 separate scans* OH fuuu.

  5. Registered TeamPlayer Rumble's Avatar
    Join Date
    07-26-07
    Location
    Greenville, TX
    Posts
    942
    Post Thanks / Like
    Stat Links

    Nine Ball Web Threat Nine Ball Web Threat
    Gamer IDs

    PSN ID: Kusanhagi Steam ID: Kusanhagi
    #5

    Re: Nine Ball Web Threat

    Virus scan ftw!
    Rumble
    "First we crack the shell, then we crack the nuts inside!"
    -Rumble (Transformers the Movie)
    "I want to change the world but nobody will give me the source code."
    -unknown

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Title