Outline ·
[ Standard ] ·
Linear+
TGV.com.my SQL injection!, Malicious javascript call on the site~
|
TSmanutdotcom
|
Jun 25 2008, 01:17 AM, updated 18y ago
|
Getting Started

|
Another case of Malaysia's website get injected by SQL injection. Currently hosting malicious javascript command at http://www.tgv.com.my The code is only inserted at the movie's synopsis page. I was looking at the synopsis for the movie "Wanted". Luckily Kaspersky was able to detect it. Does your anti-virus software able to detect it (although not recommended that you try this at home)? Little bit more info at my blog post at http://www.drsafemode.com/2008/06/25/tgv-m...-sql-injection/This post has been edited by manutdotcom: Jun 25 2008, 01:18 AM
|
|
|
|
|
|
xXAaronXx
|
Jun 25 2008, 09:36 AM
|
|
Wow another malaysia site kenna again.
|
|
|
|
|
|
FarCry3r
|
Jun 26 2008, 10:05 AM
|
|
my Kaspersky didn't show anything or horny-horse-screaming when I visit Wanted synopsis page?
|
|
|
|
|
|
TSmanutdotcom
|
Jun 26 2008, 11:26 AM
|
Getting Started

|
perhaps you're using no-script firefox add-on?
otherwise it should detect as Trojan-Downloader.JS.Agent.cs by Kaspersky v7 and Trojan-Downloader.JS.Agent.ccu by Kaspersky 2009
|
|
|
|
|
|
FarCry3r
|
Jun 26 2008, 12:18 PM
|
|
QUOTE(manutdotcom @ Jun 26 2008, 11:26 AM) perhaps you're using no-script firefox add-on? otherwise it should detect as Trojan-Downloader.JS.Agent.cs by Kaspersky v7 and Trojan-Downloader.JS.Agent.ccu by Kaspersky 2009 my Firefox doesn't have any addon except Glasser addon, neither does Internet Explorer... and I have fully updated system and antivirus definitions...
|
|
|
|
|
|
foongchinboon
|
Jun 26 2008, 02:30 PM
|
|
im using nod32 but no didnt alert me
|
|
|
|
|
|
bean_man
|
Jun 26 2008, 05:31 PM
|
|
It has been fixed by now.... I believe. However Avira is flagging an FP in that website. KIS and NOD32 on that website is clean.
|
|
|
|
|
|
eXPeri3nc3
|
Jun 26 2008, 08:18 PM
|
|
Link to that page please? I can't find it.
|
|
|
|
|
|
TSmanutdotcom
|
Jun 26 2008, 08:29 PM
|
Getting Started

|
yup, fixed already.
Smooth surfing on that site now..
|
|
|
|
|
|
tommyfai
|
Jul 1 2008, 11:37 PM
|
|
hey any1 can access now? it says reported attack site..
|
|
|
|
|
|
nujikabane
|
Jul 2 2008, 12:21 AM
|
|
Just checked, I can access the site with no problem
|
|
|
|
|
|
TSmanutdotcom
|
Jul 2 2008, 01:51 AM
|
Getting Started

|
if u use firefox, google blocks automatically when u type in the address bar
|
|
|
|
|
|
tommyfai
|
Jul 2 2008, 09:45 AM
|
|
hmm.. even i use ie7, its say internet explorer cannot display the webpage.. still cant use it.. some of my frens cant access either..
|
|
|
|
|
|
equustel
|
Jul 3 2008, 09:44 PM
|
Getting Started

|
I can't visit the TGV website on my laptop either. Firefox reports it as an "attack website". Odd.
|
|
|
|
|
|
punkyswat
|
Jul 3 2008, 10:13 PM
|
|
QUOTE(equustel @ Jul 3 2008, 09:44 PM) I can't visit the TGV website on my laptop either. Firefox reports it as an "attack website". Odd. No problem for me in Avira av.i use firefox too maybe they hav fixed the problem already.so do u?
|
|
|
|
|
|
eXPeri3nc3
|
Jul 3 2008, 10:28 PM
|
|
QUOTE(punkyswat @ Jul 3 2008, 10:13 PM) No problem for me in Avira av.i use firefox too maybe they hav fixed the problem already.so do u? Firefox now blocks it.
|
|
|
|
|
|
punkyswat
|
Jul 4 2008, 02:08 PM
|
|
i didn't hav this problem.take a look
|
|
|
|
|
|
mfaiz89
|
Jul 4 2008, 03:27 PM
|
Getting Started

|
QUOTE(punkyswat @ Jul 4 2008, 02:08 PM) i didn't hav this problem.take a look you need more carefully...
|
|
|
|
|
|
darenong
|
Jul 4 2008, 03:34 PM
|
Getting Started

|
QUOTE(mfaiz89 @ Jul 4 2008, 09:27 AM) wat av is that ? looks good
|
|
|
|
|