Incidents.org is reporting on the defacement of a security related web site (winsnort.com). They say they usually decline to comment on those because the attention is what the defacers thrive on. However, it does pay to keep your browser updated and antivirus current. What’s more…. Several days ago there was the news that the President of Iran now has a blog (which is ironic in many ways given the restrictions they place on internet use….) But… anyway, I figured he is getting his propaganda tool our and ready in advance of the UN showdown over the nuclear program. Well, it turns out that some have noticed an interesting gift from the visit to Mr. Ahmadinejad’s site….
According to the post, if visiting the site from Israel and attempting to click on a link she received a Norton Antivirus warning about an IE exploit attempt. From the screenshots the ip was 126.96.36.199 and the exploit was tagged as “HTTP MS IE File DragDrop Embed Code” attack. It did check out to be an Iranian IP address according to her research and the link she describes as being from the www.ahmadinejad.ir to www.khamenei.ir
I can’t seem to confirm any exploit here in the US, however I just may not be lucky. Can anyone outside of Israel corroborate this? Or is this just targetted at Israeli IP’s? Or, is there another explanation? Be cautious out there.
Edit— BTW, the IP address above seems to be the www.khamenei.ir site which is “Grand Ayatollah Seyyed Ali Khamenei official website – I.R.R.C.I”. This is one of the links from the site of Ahmadinejad.
Patches for this vulnerability have been out for some time…. MS045-038 is supposed to address the problem.
Some are suggesting that the activity seen was a false positive. Some information on that here. Also there is news that Israeli hackers shut down the site for a time (DoS I suppose).
Related PostsRelated Posts
- How to Remove Anti-Virus Elite | Anti-Virus Elite Removal Guide Anti-Virus Elite is a rogue antivirus application. These rogue antivirus applications pose as a legitimate security application, but in reality is a scam to try to trick you out of money. They will find and claim that there are multiple security problems with your computer. They will claim that you......
- OTHER Sony DRM software has security flaws too. You almost want to bury your head in the sand at this point if you're Sony.... Freedom-to-tinker has some details. The last couple weeks the XCP copy protection that Sony uses has been the center of a Firestorm for rootkit capabilities and massive security problems. Well, it seems the OTHER......
- Protecting yourself from Phishing attacks OK - well if you know what phishing is. You may already be ahead of the game. By now you've probably seen the messages. From:firstname.lastname@example.org to:email@example.com subject:Security breach of your account text: It has come to our attention that there have been numerous ip addresses attempting to access your account......
- Getting Backlinks To Your Site No doubt one of the most important things you can do for yourself if you are buildingÂ network marketing blogs is getting links back to your site. To be honest with you Network Marketing is a very hard keyword phrase to get ranked for.Â If you are just getting started......
- Methods For Optimizing A Blog For Traffic From The Search Engines Bloggers who have an interest in building high traffic to their blog and maintaining a successful blog should pay particular attention to SEO methods which can help to improve the search engine listings of their blogs giving them more traffic. Search sites all employ some type of ranking procedure which......
- SEO Tips for Blog Traffic Generation While it may be true to say content is king when it comes to blog publishing, the truth is that writing your blog content is not by far the only thing that you should be focusing on when it comes to attracting a readership following. Quality SEO, or search engine......
- WMF exploit testing on Windows 98
- Windows 98 and WMF exploit posts
- Virus Warning – Email Subjects – IRS Notice – Important Information from the IRS
- Hexblog (WMF unofficial patch) back up
- More testing on the second WMF exploit