madison

Malicious widget attacks compromise parked domains

Elinor Mills CNET News | August 17, 2010 7:32 AM PDT

Summary

Some parked domains from Network Solutions that display "page under construction" messages were found to be serving up malware.


This screenshot shows the fake chat message and the malicious widget on the test site that Armorize registered to test the attack.(Credit: Armorize)

Some parked domains from Network Solutions that display "page under construction" messages were found to be serving up malware from a widget that was later disabled over the weekend, a security researcher told CNET on Monday.

However, parked domains still had malware in the form of a malicious script that targets IP addresses coming from Taiwan and Hong Kong and which serves up a fake chat message and redirects to other Web sites, said Wayne Huang, co-founder and chief technology officer at security firm Armorize. The company is still analyzing the malware and it is unclear exactly what happens when computers are redirected, he said.

The malware that was embedded in the now-disabled "Small Business Success Index" widget, from Network Solutions' GrowSmartBusiness.com site, did what is called a "drive-by-download," according to Huang. It monitored what Web pages were visited and served up ads based on search queries, among other actions, he said.

For more on this story, read Parked Network Solutions domains served up malware on CNET News.

Talkback Most Recent of 1 Talkback(s)

  • Network Solutions Update on Malware Issue
    Hi, Thanks for the update on the Network Solutions malware issue. I work for Network Solutions, and I am on the SWAT team working around the clock on this issue. Please visit http://bit.ly/9g5qv4 for frequent updates and some clarifications around the malware issue. Thank you. ? Susan Wade
    ZDNet Gravatar
    netsolcares
    18th Aug 2010

Talkback - Tell Us What You Think

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity