Home > News > Adobe Exploits Compromising Websites • Bookmark   • Newsletters   • Register Search Options

NEWS STORY

Adobe Exploits Compromising Websites

Adobe Exploits Compromising Websites
Get XBIZ News
XBIZ Research
Should governments have the power / ability to stop content piracy? (e.g. SOPA / PROTECT IP)
Yes
  45.45%
No
  45.02%
Undecided
  9.52%
Out of 231 votes. Results based on votes submitted by members of XBIZ.net social network.
Tuesday, Jun 9, 2009    Text size: 
LOS ANGELES — Computer security experts are issuing a warning about Adobe software exploits which are compromising the security of an increasing number of web servers and the sites that they host.

In a recent letter to its clients, adult web hosting provider MojoHost said that it had caught attacks at an early stage, before most of its customers encountered this problem.

"To give this scenario perspective, in the last week we have identified [several] clients where in the final analysis it was determined this exploit of client side software has been the culprit," stated a MojoHost representative.

The United States Computer Emergency Readiness Team is monitoring the situation and according to the US-CERT website, the attack is a drive-by-download exploit with multiple stages and is being referred to as "Gumblar."

"The first stage of this exploit attempts to compromise legitimate websites by injecting malicious code into them," stated a Team report. "Reports indicate that these website infections occur primarily through stolen FTP credentials but may also be compromised through poor configuration settings, vulnerable web applications, etc."

The exploit's second stage occurs when users visit a Gumblar-infected website.

"Users who visit these compromised websites and have not applied updates for known [Adobe] PDF and Flash Player vulnerabilities may become infected with malware," the Team report continued. "This malware may be used by attackers to monitor network traffic and obtain sensitive information, including FTP and login credentials that can be used to conduct further exploits."

"If you are not running the most recently patched versions of Adobe Acrobat and Adobe Flash Player, you are at risk for compromising your websites," the MojoHost rep said. "This poses a significant security risk to your server and websites, leading to attackers using client FTP credentials to deface websites and insert malicious code which can exploit things further."

The Team report also states that Gumblar redirects Google search results for infected users.

As for what to do about the situation, US-CERT "encourages users and administrators to apply software updates in a timely manner and use up-to-date antivirus software to help mitigate the risks."

The agency will provide additional information as it becomes available.

"This unexpected exploit of everyday software is a lesson to everybody about just how fragile things truly can be," the MojoHost rep concluded; recommending that webmasters of affected sites contact their hosting support team to help mitigate any damage and to issue a new FTP password.

Readers are urged to update their software by visiting the publisher's websites: get.adobe.com/flashplayer/ and get.adobe.com/reader/.

More ways to get XBIZ News:  RSS Feeds  |  E-Newsletters  |  Desktop Widget  |  Mobile
Looking for porn star news and behind-the-scene videos? Check out XFANZ.com !

OPINIONS & VIEWS

iPhone Pulse: Will Apple Ever Get It Right?

This article was originally intended to provide a glimpse at an app or two that would allow the “up” volume control button on the side of an iPhone 3GS to fire its camera — similar to... More »

Traffic: Taking a Look at the Stats

Traffic is everything to ecommerce website operators, so it’s vital to understand how the current traffic pie is being sliced, and how adult fits in. The short course is that the once dominant American... More »

Technology and Sex Toys … What’s Next?

JOPEN, the company that brought Vanity by JOPEN to the luxury pleasure products market, is set to release the long awaited Intensity by JOPEN in November. Without a doubt, Intensity will change the way... More »
XBIZ NEWSLETTERS
Stay informed of the latest industry developments. Get XBIZ newsletters delivered to your inbox. Subscribe today!
Enter email address:

* To manage existing subscriptions click here.






POPULAR PRODUCTS & SERVICES
Submit your press release to
multiple news outlets with 1 click.
Subscribe to RSS news feeds or
add free content to your website.
Access XBIZ news and articles
with your mobile device.
XBIZ World™, the industry's leading technology journal, provides in-depth coverage of company news, market trends, growth sectors, and international news in the online, mobile and ancillary sectors - get it today!

UPCOMING EVENTS

XBIZ London Gathering

Feb 23 - Feb 23
Truckles Wine Bar in Holborn

Adult Entertainment Virtual Convention

Feb 24 - Feb 26
World Wide Web

The European Summit

Mar 05 - Mar 08
Barcelona, Spain

International Lingerie Show

Mar 26 - Mar 28
Las Vegas, Nevada
Everyday thousands of business professionals browse XBIZ's industry directory for quality products and services. Not listed yet? Your company could be losing potential new business. Submit your company today!
Use XBIZ RSS feeds to stay informed of the latest industry developments or as a content syndication tool for your website!