The goal of this project is to make virtual world a safer and better place without child pornography, major computer crime and RIAA.

Login As
You can log in if you are registered at one of these services:

Security Bulletins

[ GLSA 201205-02 ] ConnMan: Multiple vulnerabilities

Gentoo Linux Security Advisory ConnMan: Multiple vulnerabilities

05/16/2012

[ GLSA 201205-01 ] Chromium: Multiple vulnerabilities

Gentoo Linux Security Advisory Chromium: Multiple vulnerabilities

05/15/2012

[ GLSA 201204-08 ] Perl DBD-Pg Module: Arbitrary code execution

Gentoo Linux Security Advisory Perl DBD-Pg Module: Arbitrary code execution

04/18/2012

[ GLSA 201204-07 ] Adobe Flash Player: Multiple vulnerabilities

Gentoo Linux Security Advisory Adobe Flash Player: Multiple vulnerabilities

04/18/2012

[ GLSA 201204-06 ] PolicyKit: Multiple vulnerabilities

Gentoo Linux Security Advisory PolicyKit: Multiple vulnerabilities

04/18/2012

Latest Malware Updates

Trojan.Ransomlock.O

05/18/2012

Packed.Generic.368

05/17/2012

W32.Stekct

05/17/2012

W32.Wergimog.B

05/16/2012

VirusDoctor!gen12

05/16/2012

Android.Acnetdoor

05/16/2012

Android.Acnetsteal

05/16/2012

Packed.Generic.367

05/16/2012

Backdoor.Vasport

05/15/2012
06/24/2004

JS.Scob.Trojan

Type:  Other
Discovered:  24.06.2004
Updated:  13.02.2007
Affected systems:  Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
AV Vendor:  Symantec

Description:


The JS.Scob.Trojan dropper is detected as Trojan.Scob!dr. When it is executed, the dropper performs the following actions on the IIS Web server:
  • Drops ads.vbs into the current folder.

    Note: This file is a legitimate file and is not detected.
  • Drops three files, named %System%\inetsrv\iisXXX.dll, where XXX are three hexidecimal digits.

    Notes:
    • %System% is a variable. The trojan locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
    • These files contain Javascript and are detected as JS.Scob.Trojan.
  • Modifies the configuration of IIS Web sites on the infected computer to make one of the iisXXX.dll files the document footer.

    An infected computer will have Document Footer settings like this:



    This causes IIS to append JS.Scob.Trojan to pages served by the Web server, such as .html, .jpeg, and .gif files.

    Note: These files are detected as JS.Scob.Trojan!inf.
    The Javascript, JS.Scob.Trojan and JS.Scob.Trojan!inf do the following on the client side:
  • If the file is not accessed through HTTPS and the Trojan has not set a currently valid cookie on the computer, it launches a JavaScript file located at 217.107.218.147.

    Note: At the time of this writing, the remote file is not available.
  • The Trojan then sets a cookie which expires in one week. The cookie begins with the characters "trk716".

    Once the Trojan is triggered, it will not be triggered again until a week later.


  • Security Advisories Database

    Cross-site Scripting Vulnerability in IBM Rational Change

    A cross-site scripting (XSS) vulnerability has been discovered in IBM Rational Change.

    05/18/2012

    Cross-site Scripting Vulnerability in WordPress WassUp Plugin

    A cross-site scripting vulnerability was reported in WordPress WassUp Plugin.

    05/18/2012

    Cross-site Scripting Vulnerability in Drupal Aberdeen Theme

    A cross-site scripting vulnerability was found in Drupal Aberdeen Theme.

    05/17/2012

    Cross-site Scripting Vulnerability in JW Player

    A cross-site scripting (XSS) vulnerability has been discovered in JW Player.

    05/16/2012

    Cross-site Scripting Vulnerability in WordPress Track That Stat Plugin

    A cross-site scripting (XSS) vulnerability has been discovered in WordPress Track That Stat Plugin.

    05/16/2012

    Buffer Overflow Vulnerability in PAC-Designer File Processing

    A remote code execution vulnerability was discovered in PAC-Designer File Processing.

    05/16/2012

    Buffer Overflow Vulnerability in ispLEVER Classic Project File Processing

    A remote code execution vulnerability was found in ispLEVER Classic Project File Processing.

    05/16/2012

    Cross-site Scripting Vulnerability in WordPress Newsletter Manager Plugin

    A cross-site scripting vulnerability was found in WordPress Newsletter Manager Plugin.

    05/15/2012

    Cross-site Scripting Vulnerability in WordPress SoundCloud Is Gold Plugin

    A cross-site scripting vulnerability was discovered in WordPress SoundCloud Is Gold Plugin.

    05/15/2012

    Cross-site Scripting Vulnerability in WordPress GRAND Flash Album Gallery Plugin

    A cross-site scripting vulnerability was reported in WordPress GRAND Flash Album Gallery Plugin.

    05/15/2012