More Than 2K Sites Now Exploit .ANI Security Vulnerability
The motivation of the Eastern European group appears to be collecting banking details using form-grabbing software or keyloggers, Websense said. The group has also been known to try to use exploits to install bogus antispyware programs.
One technique used by the hackers is to find a vulnerable Web server and cause its viewers to be redirected to another website that will exploit their machine using the .ani problem, Paul said.
The hackers are also planting iframeshidden windows that can allow code such as JavaScript to runto activate an exploit. Paul predicts there may be more to come: "I don't think we've seen the last of this."
Microsoft



