Home / General / ARP Cache Poisoning Incident
digWin is a community news sharing site for Microsoft Techies. Share interesting news/links and rate them!

ARP Cache Poisoning Incident

I recently worked on an interesting incident response with several of my colleagues.  The problem, as defined by the customer, is that the following code is being injected into some websites (both external and internal to his environment) that his users are surfing:

<iframe src=http://<redacted>/ 123.htm width=0 height=0></iframe> 


The page referenced (123.htm) includes a link to a .jpg file that exploits the animated cursor vulnerability in MS07-017 and some additional obfuscated javascript.  The effect of this is that








Microsoft news, tips and tricks search

Comments


Post voted by 1 digWinners


Featured Links

User

Login | Register




Forgot Password?

Sponsor

Anti spam filter for mail servers
Anti spam, anti phishing and email management software for Exchange/SMTP/Lotus. Download a FREE trial!

Featured

Download Free Exchange Ebook

Categories

Upcoming NEW

Recent comments

Related Sites