• Welcome to NamesLot.com Domain Name Forum

    NamesLot.com Domain Name Forum offers a fully open forum to discuss domain industry news and a 0% commission marketplace for you to buy and sell domain names.

    We have reorganized our Marketplace so now it is easier to get attention to your domain while it is also easier for buyers to find the right domain name.

    If you want us to add more threads to our marketplace, please contact us! Listing on our marketplace as always, 100% free! Register NOW or Login HERE!

Severe FTP Client Vulnerability

Status
Not open for further replies.

slash75

New Member
Description: A nasty bug is infecting users via a website. The bug installs a virus from the page that will steal your Filezilla, CuteFTP, (and maybe others), then sends the passwords to a central server. From there they run a bot to access all of the stolen FTP accounts and ten an iframe injection attack on other pages, creating even more infected machines. This is a severe vulnerability.

"When a search engine such as Google detects the infection in a site, they may remove the site from their index, resulting in a financial loss to the site owner. Some browsers may flag the site as infected and show a warning that scares away users.

This attack is interesting because of the way it spreads, and the risk to developers. I would not want to be the freelance Web professional who has to explain to a few dozen clients why their sites all got hacked.

Presumably, this attack vector will eventually be used to install a payload, such as software for sending spam or executing denial-of-service attacks. After all, today's best malware is all about making money.

Big sites have security measures that would probably protect them. But what if a few million small sites are compromised and used to launch a coordinated attack? As we recently saw with Twitter's vulnerability to distributed denial-of-service attacks, there's no such thing as "not my problem" on a shared network like the Internet.
 
Status
Not open for further replies.

Members online

No members online now.

Forum statistics

Threads
20,602
Messages
70,607
Members
44,662
Latest member
anilathomas
Active members today
5
New members today
0
New threads today
12
New posts today
13

Latest Listings

Follow NamesLot on Twitter!

NamesLot proudly supported by

NamesLot proudly supported by

Top