ID: IRCNE2013122045
Date: 2013-12-17
According to "techworld", attackers exploited a vulnerability in Adobe ColdFusion to install data-stealing malware that works as a module for Microsoft's Internet Information Services (IIS) Web server software.
Researchers from security firm Trustwave recently reported they've identified IIS (Internet Information Server) Web servers infected with malicious IIS modules designed to steal information submitted by users on websites hosted on those servers.
The modules are rogue DLL (dynamic link library) files and were installed by a malware program the Trustwave researchers dubbed ISN that infects both 32-bit and 64-bit versions of IIS6 and IIS7+.
ISN detects the IIS version and installs the corresponding DLL module, which then monitors POST requests -- data submissions -- to specific URLs and saves the information to a log file.
This method allows the data to be collected even if the connection between the user and the server is protected by SSL (Secure Sockets Layer).
In a new blog post Friday, the researchers revealed that ISN is being installed on the compromised IIS servers by exploiting a remote authentication bypass vulnerability in Adobe ColdFusion, a Web application platform.
Adobe warned customers two times this year about ColdFusion vulnerabilities that had no patches and were already being actively exploited by attackers.
- 2