Thousands of sites foist Blackhole exploit after DNS compromise

By
Follow google news

Leverages Java, pdf.

Thousands of websites have redirected users to sites foisting the Blackhole exploit kit after attackers compromised DNS servers  across three Dutch web hosts.

Thousands of sites foist Blackhole exploit after DNS compromise

Attackers Monday modified the domain registration systems from the Netherlands based Foundation with external name servers, Foxit researcher Yonathan Klijnsma (@ydklijnsma) said.

All websites using domain name servers from Digitalus, VDX and Webstekker were compromised in the Blackhole attack.

"Every web site that was being requested responded with a blank 'under construction' page with an iframe ... running the Blackhole exploit kit," Klijnsma said.

The attack leveraged Adobe Reader and Java vectors in different instances and communicates with command and control servers over the Tor network.

The websites have been restored along with DNS caches which continue to serve the malicious content 24 hours after the attack was first rectified. Digitalus, VDX and Webstekker apologised in statements about the incidents.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:

Most Read Articles

US medical device maker Stryker's Microsoft environment attacked

US medical device maker Stryker's Microsoft environment attacked

Poor WA gov M365 security led to $71k theft and children's data breached

Poor WA gov M365 security led to $71k theft and children's data breached

CBA builds two AI agents to boost cyber defences

CBA builds two AI agents to boost cyber defences

CBA chief impersonated in global investment fraud on Facebook

CBA chief impersonated in global investment fraud on Facebook

Log In

  |  Forgot your password?