Best of the Week
Secrets to Stock Market Value Investing Profits - 20th Nov 08
Hyperinflation to Follow Deflationary Debt Unwind - 20th Nov 08
Exploding Global Stock Markets Hit by Economic Torpedo - 20th Nov 08
Stock Markets Look Set to Crash Through 2002 Lows - 20th Nov 08
Global Stock Market Crash Alert- Here We Go Again? - 20th Nov 08
Gold and Silver Obvious Price Maniupulation - 20th Nov 08
Falling Consumer Prices Good or Bad News for Consumers? - 20th Nov 08
U.S. Economy Reflation Challenge and LIBOR Deceptive Manipulation - 19th Nov 08
Economic Forecast, Peering into a Debt Ridden Future - 19th Nov 08
Misguided Bets On The Yield Curve Steepening - 19th Nov 08
What's Frightening Saudis and Iranians into Buying Gold? - 19th Nov 08
Stock Market Apocalyptic Crash Soon? S&P at the Tipping Point - 19th Nov 08
The Road to Financial Ruin: Unrestrained Government Spending - 19th Nov 08
Investing in Stocks During Scary Times - 19th Nov 08
US Capital Markets Portfolio Composition - 19th Nov 08
Spreading Global Recession Signals Caution for Investors - 18th Nov 08
G20 Central Banks Unite to Fight Economic Depression - 18th Nov 08
UK Inflation CPI Falls Sharply as Economy Heads for Deflation - 18th Nov 08
U.S. Treasury the Final Bailout - 18th Nov 08
What's ahead for Apple (AAPL), A Stock Worth Shorting? - 18th Nov 08
Worse than the Great Depression? - 18th Nov 08
Stock Market is Not in Uncharted Territory - 18th Nov 08
G20 Meaningless Statement and the Manageable Recession - 18th Nov 08
FINANCIAL PLANNING: My Guess Or Yours? - 17th Nov 08
Critical Week for Global Stock Markets and Economic Recovery - 17th Nov 08
U.S. Dollar Bullish Worlds Reserve Currency Dynamics - 17th Nov 08
The Ascent of Money and Descent of Niall Ferguson - 17th Nov 08
Citigroups Survival in Doubt as 50,000 Jobs Cut - 17th Nov 08
Flawed Central Banking System and Stocks Bear Market Bounce - 17th Nov 08
Gold Needs to Rise Above $838 to Fullfill Annual Minimum Bull Market Target - 17th Nov 08
Current Commodities Price Deflation to be Followed by Massive Inflation Later - 17th Nov 08
Stock, Commodities and Currency Futures Markets Analysis 17th November - 17th Nov 08
More Bailouts Coming, U.S. Automakers, Freddie Mac and Foreign Exporters - 17th Nov 08
The Brutal Truth About the Credit Crisis - 17th Nov 08
Stock Market Showing Signs of a Tradeable Low - 16th Nov 08
Peak Earnings and the Secular Stocks Bear Market - 16th Nov 08
Gold Long-term Bearish Projection Targets $480 - 16th Nov 08
G20 Economic Summit Changes Nothing - 16th Nov 08
Global Stock Market Crash Extended Leg Lower - 16th Nov 08
Extreme Stock Market Volatility as Corporate America Heads Towards Bankruptcy - 16th Nov 08
Stock Market Bear Still in Control - 16th Nov 08
Why the Dollar is Rising and Potential for Large Stock Market Rally - 16th Nov 08
US Dollar Bull Run, Gold, XOI, HUI, CBOE Put/Call Ratio - 16th Nov 08
G-20 Summit Politicians Blame Investors For Credit Crisis - 16th Nov 08
Bailout for GE But not Yet for GM - 15th Nov 08
End of the Era of Big Consumer Spending - 15th Nov 08
Hydrogen Energy, IEA-2008 World Energy, Climate Change and Fossil Fuel Depletion - 15th Nov 08
Hope for a Dismal Economy & Stock Market? - 15th Nov 08
Paulson's Blunders as Debt Securitization Market Remains Frozen - 15th Nov 08
Economic Forecasts and Analysis For U.S. Financial Markets (Nov 17-21) - 15th Nov 08
G7 Banking Systems Continue to Plunge into the Abyss - 14th Nov 08
Goldilocks Economy Turns into the Humpty Dumpty Economy - 14th Nov 08
The G-20's Secret Credit Crash Debt Solution - 14th Nov 08
Are We There Yet? Finding that Elusive Gold Stocks Bottom - 14th Nov 08
New Precedent for America : Financial Irresponsibility Pays - 14th Nov 08
Gold GLD ETF Impact on the Gold Market - 14th Nov 08
Consumer Spending Cutbacks Further Erode Retail Payrolls - 14th Nov 08
Gold Will Rise as Governments Reflate to Resurrect Economies - 14th Nov 08
U.S. Dollar Rallies Due to Global Destruction of Fiat Currencies - 14th Nov 08
Stock, Commodities and Currency Futures Markets Analysis 14th November - 14th Nov 08
Stock Market Rally Against the Primary Trend - 14th Nov 08
Stock Market Crash Count Update and Bullish Gold Stocks Divergence - 14th Nov 08
Japanese Stock Market Could Bounce in the New Year - 14th Nov 08

Free Instant Analysis

Free Instant Technical Analysis


RSS Feeds

Most Popular 2008
1. The Great Depression 2008 - It can't happen to us....can it?”
2. The Battle for America Has Begun- Strategic Forecasts
3. UK House Prices Plunge Over the Cliff
4. US Banking System Teetering on the Brink of Collapse
5. US Economy Forecast 2008 - First Recession then Recovery
6. How Safe is My FDIC-Insured Bank Account?
7. Rising Risk of a Systemic Financial Meltdown:The 12 Steps to Financial Disaster By Nouriel Roubini
Most Popular 2007
1. US Housing Market Crash to result in the Second Great Depression
2. Operation FALCON - The USA is turning into a Police State
3. US Housing Bubble Meltdown: "Is it too late to get out"?
4. UK Housing Market Crash of 2007 - 2008 and Steps to Protect Your Wealth
5. Global Liquidity Crisis when the Credit Boom comes to an End
Most Popular 2006
1. Last Warning! Three-Pronged Collapse ... Stocks, Bonds and Real Estate
2. UK Interest Rate forecast for 2007 - Bank of England to do battle with inflation
3. UK Interest Rates Forecast to rise much higher due to rising Inflation and high Money Supply Growth
4. Emerging Markets outlook for 2007 - India, China, Russia, Eastern Europe and Brazil

Market Oracle FREE Newsletter

Best of the Month
November 08
Hope for a Dismal Economy & Stock Market?
Where Stock Market Valuations and Technical Support Intersect
Credit Crisis Worse to Come as Bank Credit Contracts
U.S. Economic Pain Precedes Greatest Investment Opportunity of a Generation
Gloom and Doom Folks Will Soon be Proven Wrong
Agri-Foods Long-term Opportunities Amidst Hedge Funds Deleveraging
Will Fortune Favour the Brave in This Crisis Investment Climate?
After Shocks from the October Financial Markets Crash
Transitions From Stocks Bear Markets To Bull Markets
The Great American Housing Market Nightmare Next Phase
Stock Market Investing Dividend Yields Vs Bond Yields Analysis
U.S. Elections and Performance of Stocks, Dollar and Economy
Emerging Markets Turnaround is Getting Closer—Here's Why
Current Economic Crisis Worse than the Great Depression
FTSE 100 Stock Market Index Forecast Year End Rally
Stock Markets Staring into the Abyss
October 08
Stock Market Price Earnings Reversion Towards the Mean
Comex Gold and Silver Markets Hurtling Towards Default
Crooked Central Bank Plumbing the Depths of Depravity
Wild Crude Oil Markets Long-term Trend
Stock Market Crash Investor Overreaction Value Investing
When Will the Stocks Bear Market End?
Bear Market Deleveraging Producing Incredible Value in Agri-Foods
U.S. Dollar Bull Market Update
U.S. Dollar Driven Gold Price Crash
S&P500 Stock Market Crash Compared to Nikkei Index
Investment Opportunities in Municipal Bonds?
Stocks Bear Market Long-term Investing Strategy
Understanding Derivatives to Understand the Credit Crisis
Zinc Two Year Bear Market Coming to an End?
Stock Market Will Bottom Well Before the Economy
The Mechanism Of Capital Destruction
Fed Fighting to Prevent 1930's Style Financial and Economic Deflation
The Financial and Economic Blue Screen of Death
The U.S. Housing Market Economic Double Negative Feedback Loop
Stocks Bear Market Has NOT Hit Bottom!
Financial Markets Crash Greatest Opportunity in History!
Gold Price Manipulation- Bear Stearns Murdered at the Golden Gates
Central Banks Panic as Bailouts Fail to Halt Stock Market Crash
Financial Crisis 2008 Similar to 1987 Stock Market Crash
UK Interest Rate Forecast 2009
U.S. Economy Rapidly Sinking Into Economic Depression
Manipulation of Gold and Commodity Prices to Prevent Inflation and Higher Interest Rates
Bailout Fixes Nothing, Banking System Collapse Approaches Climax
September 08
Financial Tsunami: The End of the World as we Knew it
Financial Catastrophe Entire Global Financial System in Collapse
End of the Financial World- LIBOR TED Spread Flashes Trouble
America's Financial Apocalypse, What Can YOU Do as an Investor?
Bailout Crisis - What Happens Next
Credit Crisis Analysis and Conclusions
Financial Armageddon and the Re-pricing of Collateralized Debt
Systemic Failure of the United States- Game Over
Is the United States In Recession?
BANKRUPT Banks Wiped Out by Tulip Backed Securities

Links
Money Forums
Certz
TradingTheCharts
Housing Market Forecasts

Iframes Injection Trojan Downloader Virus Hacking Sites and Desktops Protection

sitenews / Strategic News Aug 28, 2008 - 12:11 AM

By: Nadeem_Walayat

sitenews

Best Financial Markets Analysis ArticleThe Market Oracle web site was the victim of being hacked on Saturday the 23rd of August 2008 at 10.42am (CST)

The site was brought down for 5 hours on Saturday, following which we managed to bring the site back online, following which we attempted to determine exactly what had happened to bring the site down.


Server Glitch or Hack ?

Our initial reaction was that some of the sites system files on the server had become corrupted due to a server error as the server has one of the best anti-virus packages installed (Kaspersky) , and additional mod security and protection against brute force hacking attempts that have thus far prevented any successful hacking of the web site for several years.

On investigation of what had happened we found that the site was definitely brought down as a consequence of malicious action rather than a server glitch as we found code had been injected into some of the sites pages the aim of which was to redirect visitors to the hackers own site via iframes.

On the realization of this we immediately suspended the site whilst we worked on how to cleanse the site of injected code and ascertain who hacked us and how.

The Market Oracle site system files were replaced from a clean back up which enabled us to bring the site back online during the 27th of August 08.

Desktops Compromised Not Server

After extensive analysis, we managed to ascertain that the most probable route for the successful hack was via a compromised desktop that enabled ftp access onto the server, therefore this implies that the server itself was not directly hacked. The most probable route of the virus was via one of the three desktop systems that we use to maintain the web site, and that despite anti-virus software installed the route was probably via visiting a compromised web site that was unaware of the fact that they had been compromised.

We took the action to wipe all three computers which has disrupted our ability to maintain the Market Oracle web site with new content for 4 full days.

Additionally content update during 27th of August was limited as we suspended ftp access to the server.

Who hacked us and Why ?

Initially we thought that the hacking was a consequence of our recent articles on the New Cold War brewing over the Russia / Georgia conflict. However we tracked the source of the virus down to South Korea and further to the Chung-Ang University.

The aim of the attack appears to be to spread a trojan dowloader virus that attempts to infect more desktops with the aim to eventually infect more web sites via ftp access and therefore propagating itself. Furthermore the Chung-Ang University source of the virus attempts to download numerous additional viruses via the trojan downloader onto desktops.

Research has revealed that thousands of web sites are being compromised on a daily basis including government web sites, with many of the web sites unaware that they have been compromised. A search for iframe injection reveals the extent of the problem.

Defence Against Iframes compromised Websites

Immediate action can be taken to prevent iframes code compromised websites from executing the code within iframes by the following procedure -

In internet explorer navigate to - Tools - Internet Options - Security Tab - Custom Level

Under Miscellaneous

Launching programs and files in an IFRAME - DISABLE

Navigate sub-frames across different domains - DISABLE

Defence against Hacking / Virus attacks in General

The defence for servers is to ensure ftp access is highly restricted, as well as maintaining up to date anti-virus, mod security and secure permissions as well as server script monitoring that flags any changes to site system files.

The defence for desktops is to ensure that good anti-virus and anti-malware software is installed such Kaspersky. Additionally AVG offer a free version of their anti-virus that does not expire. Purchasing an good anti-virus package for $30 to $60 is probably the best investment you will make.

Regular Backups

This experience also illustrates the importance of making regular backups of system files and data. In this age of cheap removable storage this is no longer a time consuming exercise when a monthly backup can be completed within a matter of minutes.

What if you are already infected ?

Then its probably too late to install an anti-virus package after your system has become infected.

The best course of action is usually to wipe the desktop and restore from a backup. If you do not backup then you should copy your documents / data before performing a fresh install, and ensure you run a full anti-virus scan on your data before you access it.

By Nadeem Walayat
http://www.marketoracle.co.uk

Copyright © 2005-08 Marketoracle.co.uk (Market Oracle Ltd). All rights reserved.

Nadeem Walayat has over 20 years experience of trading, analysing and forecasting the financial markets, including one of few who both anticipated and Beat the 1987 Crash. Nadeem is the Editor of The Market Oracle, a FREE Daily Financial Markets Analysis & Forecasting online publication. We present in-depth analysis from over 150 experienced analysts on a range of views of the probable direction of the financial markets. Thus enabling our readers to arrive at an informed opinion on future market direction. http://www.marketoracle.co.uk

Disclaimer: The above is a matter of opinion provided for general information purposes only and is not intended as investment advice. Information and analysis above are derived from sources and utilising methods believed to be reliable, but we cannot accept responsibility for any trading losses you may incur as a result of this analysis. Individuals should consult with their personal financial advisors before engaging in any trading activities.

Nadeem Walayat Archive


Comments

Simon Lawrence
29.08.08, 03:05
Checking your desktop

Hi,

I run AVG on both my home computers. One of them did block an attempt to download a Trojan through javascript from your sight while it was compromised. The other did not report anything at all and i probably visited your site during the same day with that machine. AVG on both machines now report clean scans. In your opinion are both computers likely to be clean? If not what specifically should i look out for.

Also how is the book coming along? I look forward to reading on its completion.

Simon Lawrence


Nadeem_Walayat
29.08.08, 11:12
AVG

Hi

Reboot into safemode and run a full scan.

The book is on hold, I literally have a mountain of work to get through, no time for the luxury of finishing a book, maybe sometime next year.

Best.

NW



Post Comment (Moderated)




Market Oracle Readership 2008 Awards Ballot