Quantcast
Channel: BOT24
Viewing all articles
Browse latest Browse all 8064

Popular Site Speedtest.net Compromised by Exploit…Drive-By STOPPED by Invincea

$
0
0

Cisco recently reported that the highest concentration of online security threats are in fact legitimate destinations visited by mass audiences.  As if to underscore that point, we accidentally discovered an exploit on Speedtest.net, a site used by mass audiences to test their connection speed to the Internet. Now to be clear, Speedtest.net did not put this exploit up. Rather, speedtest.net is a victim of being exploited; but in turn their website was used to exploit countless others. As of this writing, Speedtest.net has rectified the issue, so they are safe to visit.

In this blog Invincea security expert Eddie Mitchell dissects the attack against speedtest.net and shows the sophistication in how the attack uses polymorphism, uses standard encoding to evade detection of binaries it downloads, and was largely unknown to anti-virus vendors at the time of the analysis. The exploit highlights the dangers of browsing without protection even to legitimate sites.

read more......http://www.invincea.com/2013/02/popular-site-speedtest-net-compromised-by-exploitdrive-by-stopped-by-invincea/

Viewing all articles
Browse latest Browse all 8064

Trending Articles