Showing posts with label Porn Sites. Show all posts
Showing posts with label Porn Sites. Show all posts

Tuesday, 27 October 2015

Ads On Porn Sites Spread Browser Ransomware


Visitors to porn sites have been warned of rogue ads that users of Internet Explorer forwarded to a page with browser ransomware. This ransomware encrypts files but locks the browser and that the user has committed a crime.

Also, the claims that the page of the user's files are encrypted, while this is not the case. Then there must be an amount of between 100 and 500 euros paid to regain access to the system. The criminals behind this ransomware use a vulnerability in Internet Explorer to determine whether it is a genuine user and not a sandbox or honeypot researchers.

The page locks the browser uses JavaScript to prevent the closing of the page. Even if users pay will not close the page.Using Task Manager browser lock can however be undone. The ads that direct visitors since August this year already active on porn sites and have the features, reports anti-virus company BitDefender.

Wednesday, 30 September 2015

Student Makes Website That Identifies Porn Viewers


A Belgian student has created a website that identifies porn viewers to see as to make the risk of the data recorded by the browser. "Whenever we visit a website, there are always small bits of information stored in the local cache," explains Inti The Ceukelaire out.

"On a subsequent visit this data is re-addressed and do you get a faster loading time. If the files significantly faster loading, this indicates that the site has already been visited," the multimedia student at the Erasmus University College Brussels. With the website he wants to show that privacy is not as obvious as users often think. "Some think that the removal of the browsing history is sufficient. Bad luck," he warns (pdf).

Currently supports the test benjijeenpornomens.be five porn sites. "But the possibilities are endless and are limited not only to pornography. Thus political parties may also consider what competitors you have visited," says De Ceukelaire."Hackers can exploit this information to blackmail unwitting visitors. Then they do not do that with an explicit test, but without the victims knowing it."

According student Aaron Thijs, which last year a similar vulnerability discovered, correcting the problem is not easy. "The functionality is abused, provides a better browsing experience. Efficiency and speed go often to the detriment of safety. It is not just possible to fix this leak completely. Sensitive sites will be unavoidable and necessary." The Ceukelaire advises Internet users to use the incognito or privacy mode browser only access websites that are fully trusted. It should be closed after each browser sessions and require users to regularly empty the cache.

Saturday, 26 September 2015

Porn XHamster Spread Malware Weather


For the third time in a year there are again infected ads on the most popular porn xHamster published that attempted to infect visitors with malware. XHamster receives nearly half a billion monthly visitors and is on the 71st place of most visited websites on the internet.

The infected ads first carried out various checks. Thus, it ensures that the visitor Internet Explorer and certain security tools such as Wireshark and Fiddler active, said anti-malware company Malwarebytes. In case it IE users without said security tools went unnoticed was a page loaded with the Nuclear-exploitkit. This exploitkit uses known vulnerabilities include Adobe Flash Player and Internet Explorer users have not patched.

In the case the attack was successful was ransomware and other malware installed. After being informed removed the ad network TrafficHaus infected ads. A few days later appeared again malicious ads on xHamster. This time the browser was based Brow lock ransomware spread. This ransomware is not on the computer, but locks the browser via a special JavaScript and states that the user must pay to get access again.

Again TrafficHaus was informed. Malwarebytes but does not know if the second round with malicious ads has been removed. In January and April also appeared already contaminated ads on xHamster.

Thursday, 23 July 2015

Dozens Of Apps On Google Play Quietly Visit Porn Sites



Researchers have discovered in recent months, dozens of apps on Google Play that Android devices unnoticed kinds of porn sites allow visits. It involves a total of 60 apps posing as popular games, such Dubmash, Clash of Clans and Subway Surfers.

The apps are in the last period downloaded at least 210,000 times. Once active try the apps to hide from the user and then visit various porn sites in the background. Presumably the author get paid for the clicks generated by the apps. Clicks that advertisers think they are performed by people. According to anti-virus company ESET, there is a cat-and-mouse game between Google and the authors of the fraudulent apps. Once Google remove an app is a new upload.

Most of the fraudulent apps have no or a few tens of downloads before they are found and removed. A single app falls on, like Subway Surfers 2, which was downloaded at least 50,000 times. According to ESET caused the click fraud apps no direct harm to users, such as steal passwords, but they generate a lot of traffic that users with data limit on cost can hunt.

Saturday, 30 May 2015

Android Phone App Lets Look Unnoticed Porn


Google Play researchers again several malicious Android apps encountered after installing the device unnoticed kinds of porn sites and make visits to these sites to open multiple links and advertisements. In late April discovered anti-virus company Avast called "Dubsmash 2 app" on Google Play that was downloaded between 100,000 and 500,000 times before Google removed these.

Once the app actively trying to hide from the user and then visited several pornography sites in the background. Presumably the creator got paid for clicks that generated the app. Clicks that advertisers think they are carried out by people. Although Google removed the app there are recent days several variants of the app on Google Play appeared as late as anti-virus company ESET know.

Apps that should keep Google actually, say the researchers from the company. In a period of several days, several variants of the Trojan Dubsmash 2 uploaded and removed by Google. Yet one variant in two days would have been downloaded about 5,000 times. A total of nine discovered called Dubsmash 2 apps which were in reality "porn clickers". Once active every minute is charged a porn site, followed by a random click pattern.

"Although click fraud causes no direct harm to victims, such as to steal passwords, generates a lot of traffic and thereby generating additional costs for victims who have a data limit, so they remain at the end of the month with a high phone bill" , the researchers note. Which argue that Google Play has some weaknesses, given that the same malicious app could be placed several times on the app store before they intervened.

Friday, 8 May 2015

Infected Ads On Dozens Of Porn Sites Discovered


The past week has been on dozens of porn sites infectious ad appeared that visitors via a known vulnerability in Adobe Flash Player tries to infect with malware. Among the stricken porn sites, which together have 250 million visitors are drtuber and nuvid the largest.

Unlike many infectious ads that visitors unnoticed forward to another site, the ad used to contain pornography directly exploitable, which makes abuse of the vulnerability in Adobe Flash Player, as reported anti-virus company Malwarebytes.The ad would be distributed through an advertiser on the AdXpansion ad network. In case the attack success are different infected files placed on your computer. Visitors to porn sites whose Adobe Flash Player up-to-date are not at risk.

Wednesday, 29 April 2015

Weather Infected Ads On Porn xHamster


On the popular porn xHamster again infected ads have appeared that attempt to infect visitors with malware. In late January it was even hit on the porn site, which according to Alexa is on the 68th place of most visited sites on the Internet and gets 514 million visitors monthly.

The ads direct visitors unnoticed to another page where the Angler Exploitkit runs. This page checks to see if the visitor uses the virus from Kaspersky Lab or Norton. If this is not the case, then it is decided to attack the user further. The Angler Exploitkit makes abuse of vulnerabilities in Internet Explorer, Java, Silverlight and Adobe Flash Player. Anti-virus firm Malwarebytes suggests that only an old vulnerability in Internet Explorer is used in the attack.

Is the attack successful, is the Bedep malware installed. The same malware that also the end of January on the website was spread via infected ads. Bedep making computers part of a botnet and can then install additional malware. Once active Bedep used infected computers to commit fraud advertisement. Additionally silently loads the Magnitude Exploitkit, which also makes abuse of vulnerabilities, provide users with additional malware can become infected.

Friday, 27 March 2015

Xtube Porn Spreading Malware Via Flash Attack


Visitors to the porn xtube are now warned cyber criminals have hacked the website and use it for distributing malware. Xtube 780 ranked of most visited websites in the United States and would have to deal with 25 million visitors every month.

Unlike other recent attacks are widely used in the case of infectious xtube no ads, but the attackers have malicious code placed directly on the website itself. Something which is possible only if the attackers have access to the website. The code sends users unnoticed through to another website which then tries to put through a known vulnerability in Adobe Flash Player malware on the computer.

It is a vulnerability that already has a security update has been released. Users who have the latest Flash Player version available are therefore not at risk. In case the attack was successfully placed a Trojan horse on the computer. The malware was detected at the time of the attack by 12 of the 57 scanners on VirusTotal, says anti-virus company Malwarebytes .

It is not just porn sites that are victims of these attacks. This week, the Dutch security researcher warned Yonathan Klijnsma that the website nummeriban.nl where users can convert to an IBAN account number, also malicious code was detected. The malicious code sent by visitors to a website that users via known vulnerabilities in Adobe Flash Player, Java and Adobe Reader tried to attack.

Thursday, 29 January 2015

Infected Ads on xHamster Spread Malware


Researchers have discovered the popular porn site xHamster infected ads that try to infect visitors through a recently patched flaw in Flash Player. According to anti-virus company Malwarebytes is the number of infections from xHamster recent days has increased by 1500%.

The porn is according to measurement agency Alexa on the 64th spot of most visited websites on the internet. In case the attack is successful the Bedep malware is installed. Bedep making computers part of a botnet and can then install additional malware. Meanwhile, there is an update to the attacked Flash Player leak released, but may still not be installed anywhere.

"Although malvertising on xHamster is nothing new, this particular campaign is very active. Given that this porn site generates a lot of traffic, the number of infections are gigantic," says Malwarebytes. Previously had security FireEye already know that had infected ads on porn sites found , including a porn site in the Alexa Top 1000. However, it seems to go a different attack. As was pointed infected computers installed Reveton-ransomware.

Wednesday, 28 January 2015

Visitors Porn Sites Attacked By Flash Player Leak


Visitors from different porn sites, including one that is on the Internet in the Top 1000 most visited sites are attacked by a leak in Adobe Flash Player which published an update until recent days. The attack took place through ads displayed on porn sites.

That says security firm FireEye. Once the ads were shown malware could be installed on the system in a vulnerable browser.To which websites are just the IT security officer does not know. However, the advertisements used a variant of the attack which was observed in the first instance. That first attack was carried out by the Angler Exploitkit while the new attack does not use this exploitkit.

The original Angler attack used some JavaScript and try to detect the presence of virtual machines and scanners, while the new variant no obfuscation used or analyzes the environment. The exploit for Flash Player in this case is loaded via normal JavaScript. The attack is successful then a variant of the Reveton ransomware-installed. Reveton locks the computer and that the user has committed a crime. In order to prevent criminal prosecution and to regain access to the system must be an amount of money to be paid.

Meanwhile, there is for all users released an update that fixes the leak. Through this page can be checked which version of Flash Player installed on your computer. The Finnish F-Secure let know that the Angler Exploitkit last week was the most popular exploitkit among cybercriminals. The virus fighter advises Internet users in addition to installing the update also to set click-to-play. In this case, the user must first click on a Flash object before it is loaded. In this way it can automatically be prevented infecting the computer via browser plug-ins.