topbanner_forum
  *

avatar image

Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
  • Thursday April 18, 2024, 9:11 am
  • Proudly celebrating 15+ years online.
  • Donate now to become a lifetime supporting member of the site and get a non-expiring license key for all of our programs.
  • donate

Author Topic: SWF Redirects In SPAM  (Read 4248 times)

Ehtyar

  • Supporting Member
  • Joined in 2007
  • **
  • Posts: 1,237
    • View Profile
    • Donate to Member
SWF Redirects In SPAM
« on: August 29, 2008, 04:20 PM »
Attackers are using ActionScript to force visitors to their sites from legitimate sites. Just another reason to be using NoScript

Screenshot - 30_08_2008 , 7_19_08 AM_thumb.png


One of the new trends in spam e-mails used for malware distribution is the use of maliciously crafted SWF files hosted on legitimate servers. The ActionScript code of the files includes a redirect that takes users to websites that host malware or prompts them to download the malware directly.

Full Story

Ehtyar.

Deozaan

  • Charter Member
  • Joined in 2006
  • ***
  • Points: 1
  • Posts: 9,749
    • View Profile
    • Read more about this member.
    • Donate to Member
Re: SWF Redirects In SPAM
« Reply #1 on: September 01, 2008, 01:55 AM »
Another reason to dislike Flash sites. :-(

lanux128

  • Global Moderator
  • Joined in 2005
  • *****
  • Posts: 6,277
    • View Profile
    • Donate to Member
Re: SWF Redirects In SPAM
« Reply #2 on: September 01, 2008, 02:00 AM »
as usual another potentially good technology has been manipulated for commercial gains. :down:

Ehtyar

  • Supporting Member
  • Joined in 2007
  • **
  • Posts: 1,237
    • View Profile
    • Donate to Member
Re: SWF Redirects In SPAM
« Reply #3 on: September 01, 2008, 02:22 AM »
IMO Flash has always been given far too much power/freedom on an operating system to *not* be used for nefarious purposes. In relation to this, Flash end-users should also take Local Shared Objects into consideration when deciding whether or not to permit a flash application to run on their PC.

Ehtyar.