Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][tlug] Possible malware attack on my site?
- Date: Fri, 02 Oct 2009 19:22:23 +0900
- From: "Stephen J. Turnbull" <stephen@example.com>
- Subject: [tlug] Possible malware attack on my site?
- References: <4AC5C2F1.6090002@example.com>
Dave M G writes: > Apparently when a user clicks on the Facebook ad, the browser is > first directed to the malware site, and then it forwards to > tokyocomedy.com, so that they may not ever notice the intrusion. Let me count the ways.... 1. The browser may have been subverted. 2. The OS may have been subverted, so that HTTP is proxied through the malware site. 3. Facebook's ad may have been subverted. 4. A nameserver cache between that user and tokyocomedy's authoritative server may have been poisoned. 5. A nameserver may have been subverted. 6. tokyocomedy's webserver may have been subverted to redirect to the malware site and then back to tokyocomedy. > If anyone has any suggestions for how I might assure myself that the > site is secure, then I would be very interested. The only way to assure yourself it is secure is to shut it off! Obviously that's not an acceptable solution. So accept that the site is not secure, and pay attention to it so you can ward off intrusions and recover from successful ones as quickly as possible. With respect to this incident, first try browsing Facebook yourself to see what happens (preferably with IE, but many browsers will allow you to claim that they are IE). That doesn't prove anything if the results come up negative but if they're positive you have a trail to follow. Check your logs for access by the malware site and see what's happening there. If the malware site is proxying your site, you can try firewalling it out so that it can't reach you (easily) to get your content to fake. Make sure you log those attempts so you can correlate if somebody says they can't see your ads. HTH
- Follow-Ups:
- Re: [tlug] Possible malware attack on my site?
- From: eredicatorx@example.com
- References:
- [tlug] Possible malware attack on my site?
- From: Dave M G
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] 15th Aniversary Party 22nd October
- Next by Date: Re: [tlug] 15th Aniversary Party 22nd October
- Previous by thread: [tlug] Possible malware attack on my site?
- Next by thread: Re: [tlug] Possible malware attack on my site?
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links