Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 TGV.com.my SQL injection!, Malicious javascript call on the site~

views
     
TSmanutdotcom
post Jun 25 2008, 01:17 AM, updated 18y ago

Getting Started
**
Junior Member
84 posts

Joined: Oct 2005


Another case of Malaysia's website get injected by SQL injection.
Currently hosting malicious javascript command at http://www.tgv.com.my

The code is only inserted at the movie's synopsis page. I was looking at the synopsis for the movie "Wanted".
Luckily Kaspersky was able to detect it. Does your anti-virus software able to detect it (although not recommended that you try this at home)? tongue.gif

Little bit more info at my blog post at http://www.drsafemode.com/2008/06/25/tgv-m...-sql-injection/

This post has been edited by manutdotcom: Jun 25 2008, 01:18 AM
xXAaronXx
post Jun 25 2008, 09:36 AM

My Love for AppleJack
******
Senior Member
1,172 posts

Joined: May 2006
From: Puchong
Wow another malaysia site kenna again.

FarCry3r
post Jun 26 2008, 10:05 AM

Where did my ♥ go?
*******
Senior Member
6,543 posts

Joined: Dec 2004
From: Miri



my Kaspersky didn't show anything or horny-horse-screaming when I visit Wanted synopsis page? hmm.gif
TSmanutdotcom
post Jun 26 2008, 11:26 AM

Getting Started
**
Junior Member
84 posts

Joined: Oct 2005


perhaps you're using no-script firefox add-on?

otherwise it should detect as Trojan-Downloader.JS.Agent.cs by Kaspersky v7 and Trojan-Downloader.JS.Agent.ccu by Kaspersky 2009
FarCry3r
post Jun 26 2008, 12:18 PM

Where did my ♥ go?
*******
Senior Member
6,543 posts

Joined: Dec 2004
From: Miri



QUOTE(manutdotcom @ Jun 26 2008, 11:26 AM)
perhaps you're using no-script firefox add-on?

otherwise it should detect as Trojan-Downloader.JS.Agent.cs by Kaspersky v7 and Trojan-Downloader.JS.Agent.ccu by Kaspersky 2009
*
my Firefox doesn't have any addon except Glasser addon, neither does Internet Explorer... and I have fully updated system and antivirus definitions...
foongchinboon
post Jun 26 2008, 02:30 PM

Casual
***
Junior Member
395 posts

Joined: Apr 2008
From: Klang-Banting


im using nod32 but no didnt alert me
bean_man
post Jun 26 2008, 05:31 PM

Casual
***
Junior Member
371 posts

Joined: Aug 2006


It has been fixed by now.... I believe. However Avira is flagging an FP in that website. KIS and NOD32 on that website is clean.
eXPeri3nc3
post Jun 26 2008, 08:18 PM

It's coming! 3ɔu3ıɹǝdxǝ ♥
*******
Senior Member
9,257 posts

Joined: Aug 2005
From: Not so sure myself Status: 1+3+3=7



Link to that page please? I can't find it.
TSmanutdotcom
post Jun 26 2008, 08:29 PM

Getting Started
**
Junior Member
84 posts

Joined: Oct 2005


yup, fixed already.

Smooth surfing on that site now..
tommyfai
post Jul 1 2008, 11:37 PM

Casual
***
Junior Member
408 posts

Joined: Feb 2008
From: puchong



hey any1 can access now? it says reported attack site..
nujikabane
post Jul 2 2008, 12:21 AM

United We Stand
*******
Senior Member
3,212 posts

Joined: Jun 2007
From: atas bawah kiri kanan

Just checked, I can access the site with no problem smile.gif
TSmanutdotcom
post Jul 2 2008, 01:51 AM

Getting Started
**
Junior Member
84 posts

Joined: Oct 2005


if u use firefox, google blocks automatically when u type in the address bar
tommyfai
post Jul 2 2008, 09:45 AM

Casual
***
Junior Member
408 posts

Joined: Feb 2008
From: puchong



hmm.. even i use ie7, its say internet explorer cannot display the webpage.. still cant use it.. some of my frens cant access either..
equustel
post Jul 3 2008, 09:44 PM

Getting Started
**
Junior Member
111 posts

Joined: Dec 2006


I can't visit the TGV website on my laptop either. Firefox reports it as an "attack website". Odd.
punkyswat
post Jul 3 2008, 10:13 PM

Regular
******
Senior Member
1,519 posts

Joined: Jan 2007
QUOTE(equustel @ Jul 3 2008, 09:44 PM)
I can't visit the TGV website on my laptop either. Firefox reports it as an "attack website". Odd.
*
No problem for me in Avira av.i use firefox too maybe they hav fixed the problem already.so do u?
eXPeri3nc3
post Jul 3 2008, 10:28 PM

It's coming! 3ɔu3ıɹǝdxǝ ♥
*******
Senior Member
9,257 posts

Joined: Aug 2005
From: Not so sure myself Status: 1+3+3=7



QUOTE(punkyswat @ Jul 3 2008, 10:13 PM)
No problem for me in Avira av.i use firefox too maybe they hav fixed the problem already.so do u?
*
Firefox now blocks it.
mfaiz89
post Jul 4 2008, 09:27 AM

Getting Started
**
Junior Member
227 posts

Joined: Mar 2008
From: KL



QUOTE(eXPeri3nc3 @ Jul 3 2008, 10:28 PM)
Firefox now blocks it.
*
yap, thats right...

user posted image

http://safebrowsing.clients.google.com/saf...www.tgv.com.my/
punkyswat
post Jul 4 2008, 02:08 PM

Regular
******
Senior Member
1,519 posts

Joined: Jan 2007
i didn't hav this problem.take a look
mfaiz89
post Jul 4 2008, 03:27 PM

Getting Started
**
Junior Member
227 posts

Joined: Mar 2008
From: KL



QUOTE(punkyswat @ Jul 4 2008, 02:08 PM)
i didn't hav this problem.take a look
*
you need more carefully...
darenong
post Jul 4 2008, 03:34 PM

Getting Started
**
Junior Member
50 posts

Joined: May 2006
From: Klang


QUOTE(mfaiz89 @ Jul 4 2008, 09:27 AM)
wat av is that ? looks good rclxms.gif

2 Pages  1 2 >Top
 

Change to:
| Lo-Fi Version
0.0718sec    0.21    5 queries    GZIP Disabled
Time is now: 24th December 2025 - 02:12 AM