Quick Links: SpywareGuide Greynets Blog | SpywareGuide Product Database | SpywareGuide Company Database | SpywareGuide Categories
SpywareGuide powered by FaceTime Security Labs
Search SpywareGuide Greynets Database & Site
Security Email Alerts & Updates
Search the Blog
 
Recent Posts
Categories
Monthly Blog Archives
Links
Subscribe
Subscribe to this blog's feed
About the Blog
About SpywareGuide Greynets Blog
Link to Us
Link to SpywareGuide.com

« A Timely Reminder For EBay Sellers | Main | Tech Talk Radio: RSA 2008 »

  • An Interesting Development

I came across a number of websites hacked over the last few weeks using an SQL injection - the same exploit used by script-kiddie tearway The Punisher. I quickly realised this person was hanging out on the same forums as our Punishing pal, and quickly traced him back to his main website. Well, it appeared his site had only just launched and did nothing else than serve as a placeholder for whatever material he'd be uploading in future. Note how he attempts to pass the site off as somehow belonging to Network Solutions so as not to attract attention:

http://blog.spywareguide.com/upload/2008/04/russ1-thumb.jpg
Click to Enlarge

Well, a few weeks have passed and now, if you visit his site, you'll notice a very interesting difference:


http://blog.spywareguide.com/upload/2008/04/russ2-thumb.jpg

Click to Enlarge

All of the text has suddenly been switched to Russian, presumably in the hope that casual snoopers will think "nothing to see here, move along". If you click the "leave page" hyperlink (after having refused to agree to their terms), it attempts to play a terrible MP3 - just to confuse the visitor further.

They've also pasted a seemingly endless stream of banner ads on the lower section of the page - casual vistors will think the site is nothing more than a Russian affiliate ring stuffed full of "win it now" iPod deals, commission links and affiliate schemes. Again, it's all lies - none of the banners are clickable, they've just been pasted in randomly onto the page.

russ3.jpg

Finally, click "I accept" and you're taken to a forum (that only appears to have been in existence for a very short time) with the following "go away now" message:

russ4.jpg

Pretty sophisticated for a garden variety script kiddie, especially given the extremely unimaginative website defacements he was previously rolling out. It also begs the question - why is he so cagey, and what is he trying to hide? More importantly, how did he come about the idea of pretending to be a Russian affiliate guy in the first place?

  • TrackBack

TrackBack URL for this entry:
http://blog.spywareguide.com/mt/mt-tb.cgi/302

Listed below are links to weblogs that reference An Interesting Development:

» Klonopin. from Klonopin.
Klonopin. [Read More]


Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)


Site EULA | Site Map | Contact Us | About Us | Site and Spyware FAQ | Advertise | RSS Feeds  | Link To Us | SpywareGuide JapanJapanese

© Copyright 2006, FaceTime Communications, Inc. All rights reserved.