Auteur Sujet: [websense] XSS Attack on Sina MicroBlog  (Lu 5123 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne SX-News

  • Bot
  • Members
  • ***
  • Messages: 750
[websense] XSS Attack on Sina MicroBlog
« le: juillet 02, 2011, 16:12:59 »
XSS Attack on Sina MicroBlog

Description : If you&nbsp;have not heard of Sina Weibo in China, you are behind the times. Sina Weibo is the most popular microblog&nbsp;service&nbsp;in China, with more than 100 million&nbsp;registered&nbsp;customers. Just yesterday (28 June), Sina Weibo was attacked through an XSS exploit: more than 30,000 high profile customers were&nbsp;affected&nbsp;and sent out messages containing a malicious link.&nbsp;<span>&nbsp;Sina&nbsp;provided a quick response, within two hours, to stop this campaign. Websense customers are protected from this attack by ACE, our&nbsp;Advanced Classification Engine.</span>
&nbsp;
<span>
</span>
Here is&nbsp;a snapshot of a message with a malicious link posted by a high-profile customer. The content of the message is related to some hot topic or film star in China to lure the followers to click on the link.
&nbsp;
<img alt="" border="0" src="http://community.websense.com/resized-image.ashx/__size/550x0/__key/CommunityServer.Blogs.Components.WeblogFiles/securitylabs/5751.941ed189a58f97d30d244476-_2800_1_2900_.jpg" />
<span>&nbsp;</span>
<span>
</span>
&nbsp;
<span>Followers who click the malicious link are redirected to a page hosted on &quot;</span><span>weibo.com/pub/star&quot;,&nbsp;</span>which&nbsp;contains an XSS exploit to allow the execution&nbsp;of&nbsp;malicious JavaScript from www.2kt.cn.
&nbsp;
<img alt="" border="0" src="http://community.websense.com/resized-image.ashx/__size/550x0/__key/CommunityServer.Blogs.Components.WeblogFiles/securitylabs/7573.ec82a5b332fadac7db335a76.jpg" />
<span></span>
<span></span>
<span></span>
<span>The malicious JavaScript code could post messages on the follower's microblog account, add a follow to a suspicious account, and send a personal message to his followers.&nbsp;Until now, the campaign has just spread itself with&nbsp;no other malicious intention. Interestingly, the suspicious account which&nbsp;affected&nbsp;customers was named &quot;</span><span>hellosamy&quot;, showing some respect to the world's first XSS worm &quot;Samy&quot;, which spread on MySpace in 2005.</span>
<span></span><span></span>

&nbsp;
<span><img alt="" border="0" src="http://community.websense.com/resized-image.ashx/__size/550x0/__key/CommunityServer.Blogs.Components.WeblogFiles/securitylabs/4300.20110629164057256.png" /></span>
<span>
</span>
Although no malicious software was installed in this campaign, Websense reminds customers to do a simple check before you click&nbsp;on any&nbsp;suspicious URL, even it comes from your best friends.
&nbsp;
&nbsp;<div style="clear: both;"]</div>

Lien : http://community.websense.com/blogs/securitylabs/archive/2011/06/29/xss-attack-on-sina-microblog.aspx

Tags: