Monday, March 10, 2008

Danchev: and Getting RBN-ed

Dancho Danchev:

Monitoring last week's IFRAME injection attack at high page rank-ed sites, reveals a simple truth, that persistent simplicity seems to work.

The attack is still ongoing, this time successfully injecting a multitude of new domains into Wired Magazine, and's search engines, which are again caching anything submitted, particularly not validated input to have the malicious parties in the face of the RBN introducing a new malware, in between the pharmaceutical scams that they serve on the basis of an affiliation model.

So, after "CNET stops IFRAME site attacks - who's next?" in terms of high-profile sites, that is and

Much more here.


