The Personal Weblog of Akshay Jain
Ok, so the first thing after I saw this was to send an email to the webmaster of this website “iimi-epgp.net” . (Do not visit this site. Or if you are too curious, then visit it after disabling javascript). This is supposedly the “Student Website for Executive Post Graduate Programme in Management”.
I discovered this when I was searching in Google for my own name and the first result came up as the web page of some other “Akshay Jain” at that website and with a Google warning that “This site may harm your computer.”
The exploit appears to be a SQL injection in the database forcing the visitor’s browser to open malicious javascript which can then infect the machine. Moreover, this is not only Google that is showing this. My NOD32 also gave the same error.
Malicious software is hosted on 4 domain(s), including tctcow.com, movaddw.com, crtbond.com. (they have not been linked intentionally)
2 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including crtbond.com, pyttco.com.
If such professional websites in India are not safe and moreover, after the initial exploit, they are “still” infected without any preventive action taking place, then it raises serious concerns about the security / technical capability of India to deal with such issues.
I will keep you updated on how this goes.
I am Akshay Jain a student in Economics and a web enthusiast. Most of my readers would be knowing me by my pseudonym champ_rock/champrock. This is my blog and I know I wont be keeping this updated. For contacting me, please use the contact form!
Please subscribe to the RSS feeds in order to get the latest updates on my blog!
ǝlƃooƃ noʎ ʞɔnɟ
airtel
apple
apple itunes
ascii
benchmark
broadband
browser
confidence motion
converter
ebaumsworld
firefox
fun
galwaysidle
Google
google campus ambassador
google gadget
google trends
google trends hacked
google trends spam
gtalk
hacked
hijack
how to poop at work
idle
iim
iim-i
iim pgp
iim student website
image to ascii
indian government
ipod
itunes
latest browsers
opera
opera functions
politics
ram
ram usage
redirect
swastika
taskmanager
trends hacked
typo
virus Broadband (India) (2)
Code Snippets (6)
Economics (1)
General (16)
Google (3)
Indian Politics (1)
Jainism (1)
Latest Buzz (6)
New Scripts (1)
opera (2)
WP Cumulus Flash tag cloud by Roy Tanck and Luke Morton requires Flash Player 9 or better.
Web Designer
August 7th, 2009 at 8:07 am
Just clear the scripts in the pages first. then take the security measures.