Free Newsletter
Register for our Free Newsletters
Access Control
Deutsche Zone (German Zone)
Education, Training and Professional Services
Government Programmes
Guarding, Equipment and Enforcement
Industrial Computing Security
IT Security
Physical Security
View All
Other Carouselweb publications
Carousel Web
Defense File
New Materials
Pro Health Zone
Pro Manufacturing Zone
Pro Security Zone
Web Lec

FTP server access parameters discovered in hacking database.

Finjan Software : 28 February, 2008  (Technical Article)
The means to access thousands of FTP databases has been discovered by Finjan, putting user data at risk.
Finjan has uncovered a database containing more than 8,700 harvested FTP account credentials, including username, password and server address - in the hands of hackers. These stolen credentials enable criminals to compromise servers and automatically inject crimeware to infect users visiting them. Among those stolen accounts are those of Fortune-level global companies in a wide range of industries including manufacturing, telecom, media, online retail, IT, as well as government agencies. The stolen FTP accounts include some of the world's top 100 domains as ranked by

Finjan's Malicious Code Research Center (MCRC) has detailed the workings of an insidious new application, especially designed to abuse and trade stolen FTP account credentials of legitimate companies around the world. A trading interface is used to qualify the stolen accounts in terms of country of residence of the FTP server and Google page ranking of the compromised server. This information enables the cybercriminals to devise cost for the compromised FTP credentials for resale to other cybercriminals or to adjust the attack on more prominent sites. The trading application also allows the cybercriminal to manage FTP credential information to automatically inject IFRAME tags to web pages on the compromised server.

"Software-as-a-Service has been evolving for sometime, but until now, it has been applied only to legitimate applications. With this new trading application, cybercriminals have an instant 'solution' to their 'problem' of gaining access to FTP credentials and thus infecting both the legitimate websites and its unsuspecting visitors. All of this can be easily achieved with just one push of a button," said Yuval Ben-Itzhak, CTO of Finjan.

Finjan invites IT security personnel from legitimate organisations to inquire if their FTP servers' credentials are among those identified as stolen.

According to Finjan, the NeoSploit 2 toolkit marks a serious escalation of Crimeware potential, since it uses the Software-as-a-Service business model.

Both the NeoSploit Version 2 toolkit and the application were detected using Finjan's patented real-time code inspection technology while diagnosing users' web traffic. The attack is described in detail in Finjan's latest "Malicious Page of the Month" report released today.
Bookmark and Share
Home I Editor's Blog I News by Zone I News by Date I News by Category I Special Reports I Directory I Events I Advertise I Submit Your News I About Us I Guides
   © 2012
Netgains Logo