<http://www.infoworld.com/article/07/04/06/HNasusteksitehack_1.html>
Site has been infected with malicious code that exploits the Microsoft
cursor animation flaw that was patched earlier this week.
By Robert McMillan, IDG News Service
April 06, 2007
The Web site for computer parts manufacturer ASUStek Computer has been
hacked and has been serving up attack code that exploited a critical
Windows vulnerability, patched earlier this week.
The exploit is hidden in an HTML element on the front page of
ASUStek's Taiwanese Web site, which then attempts to download the code
from another server, according to Roger Thompson, CTO with Exploit
Prevention Labs.
As of Friday afternoon, the server that downloaded the attack code was
not operational, mitigating the risk of this attack, although
attackers could easily redirect their attacks to a live server, he
said.
|