Shaun Nichols in California, vnunet.com23 Apr 2008
ADVERTISEMENT
Security researchers have discovered a new web-based attack tool which
exploits up to 14 browser vulnerabilities and installs malware on the user's
system.
Symantec researcher Liam O'Murchu said that 'Tornado' is commonly installed
on a server by a single 'administrator', who then offers accounts on the server
to other attackers.
The attackers then inject code into other web pages to redirect users to the
Tornado server, where the exploit and malware installation is conducted.
"Perhaps this is why the code for this pack has stayed private for so long,"
said O'Murchu.
"Using this model, the creators of the pack can sell it to a few trusted
customers at a higher price, rather than selling it to many untrustworthy
customers and risking the code being released in the underground."
Tornado also offers attackers a full set of traffic statistics and options
for selecting which exploits can be conducted.
The malware features an option to redirect repeat visitors to a phoney
'account suspended' page.
This helps the tool to evade security researchers who will make repeated
visits to infected pages in order to study the exploits and malware in use.
Programs such as Neosploit and MPack offer similar capabilities to set up
servers that can conduct multiple exploits against users.
South West, Darlington, United Kingdom | University College Falmouth
Web Sharepoint Development Manager, £23,692-£26,665 (£29,138) per annum (Grade 5) The creation of a new University for the Arts in the South West has taken a major step forward with the merger of University ... more >
Assistant Forensic Computer Analyst - Police Headquarters, Maidstone, £20,164 - £23,632 Permanent Contract Digital devices and information communication technology are present in almost every investigation the police service undertakes. Kent Police Digital Forensics Unit ... more >
London, United Kingdom | London School of Economics
IT Services -Systems Specialist (Business Continuity), Salary: £38,212 - £44,264 p.a. 2 years fixed-term LSE is a cosmopolitan community in the centre of London focusing on the study of the social sciences. IT Services ... more >
Manchester, United Kingdom | Peel Communications Limited
Business Development Manager (IT & Comms), Manchester, (£35k)with Company Car, Healthcare & Pension. Additional team bonus subject to performance and Manager discretion. A leading property and transport Group with multi-purpose developments throughout the UK ... more >More job opportunities