No more hiding in the server room
First off a fair warning. The websites I'm going to mention below, as of this writing, WILL cause re-directs to various random malware sites if you perform the steps I'm going to mention below.
If this happens, just immediately Task Manager and close your browser and nothing will happen to your pc.
Maybe some of you more experienced SysAdmin sorts have seen this before and know how they did it but I haven't, so here goes.
I had a User accidentally find a malicious website while searching for a specific neighborhood bar. The name of the bar is Bleachers Bar, so he typed that into Bing.
The first link he got was www.bleachersbar.net and when he clicked the hyper-linked url from the search, it re-directed him to a fake anti-virus malware site.
Here's where it gets weird. If you manually just type www.bleachersbar.net into your browser's address bar, it goes to their legitimate website. It's only the hyper-link from either a Bing or Google search that goes to malware sites. Now the next funny part. The same issue happens with their domain registrant.
I did a Who Is on www.bleachersbar.net and got Technology Enrichment Group - Grashaw & Co as their registrant. If you Google Technology Enrichment Group - Grashaw & Co
you'll get www.grashaw.com and if you click the hyper-link search result, same thing happens. However, typing www.grashaw.com into the browser bar works fine.
As of this writing, this still happens. However, I've since contacted both of these sites to let them know of the issue so they might fix it before you get the chance to see it.
How the hell does this work? Manually go to site, fine, click hyper-link search result, malware. O_o ???
Tags:
Permalink Reply by Adam Ruth on April 22, 2011 at 11:27pm
Permalink Reply by Mike Rigsby on April 23, 2011 at 12:08am
© 2012 Created by Elizabeth Ayer and Michael Francis.
Powered by