<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>FireBlog &#124; FireHost &#187; Nine-Ball</title>
	<atom:link href="http://www.fireblog.com/tag/nine-ball/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.fireblog.com</link>
	<description>Secure Hosting Blog</description>
	<lastBuildDate>Thu, 29 Jul 2010 14:23:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Nine-Ball Mass Injection Attack has Compromised 40,000 Websites to Date</title>
		<link>http://www.fireblog.com/nine-ball-mass-injection-has-compromised-40000-websites-to-date/</link>
		<comments>http://www.fireblog.com/nine-ball-mass-injection-has-compromised-40000-websites-to-date/#comments</comments>
		<pubDate>Tue, 23 Jun 2009 14:00:58 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Nine-Ball]]></category>
		<category><![CDATA[Secure Web Hosting]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=1523</guid>
		<description><![CDATA[Websense security labs have been tracking the Nine-Ball mass compromise attack since early June. They report to date, that over 40,000 legitimate Web sites have been compromised and are actively infected with an information-stealing trojan.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1538" title="9ball" src="http://www.fireblog.com/wp-content/uploads/2009/06/9ball.jpg" alt="9ball" width="154" height="179" /><a href="http://www.websense.com/content/Home.aspx" target="_blank">Websense</a> security labs have been tracking the <a href="http://securitylabs.websense.com/content/Alerts/3421.aspx" target="_blank">Nine-Ball</a> mass compromise attack since early June. They report to date, that over 40,000 legitimate Web sites have been compromised and are actively infected with an information-stealing trojan.</p>
<p>The Nine-Ball attack is deployed when a user visits a legitimate website that has been infected with the malicious code. From the legitimate website, unsuspecting users are redirected behind the scenes through a series of different sites owned by the Nine-Ball&#8217;s hackers.</p>
<p><span id="more-1523"></span></p>
<p>The diagram below depicts a typical url progression that happens behind the scenes during a Nine-Ball deployment.</p>
<div class="wp-caption aligncenter" style="width: 518px"><img title="Nine-Ball Progression" src="http://www.fireblog.com/wp-content/uploads/2009/06/9balldiagram.jpg" alt="Nine-Ball Progresstion" width="508" height="89" /><p class="wp-caption-text">Nine-Ball Progresstion</p></div>
<p>When an infected site is visited for the first time, the user is directed to the ninetoraq.in exploit payload site where the visitor&#8217;s IP address is recorded and the trojan download is installed.</p>
<dl style="width: 443px;"> </dl>
<p>If a user on the same IP visits the legitimate website again, he or she is directed to the benign site of <em>ask.com</em>. Security experts speculate that the Nine-Ball hackers are using a benign destination url to throw cyber security investigators and cyber crime analysts off track.</p>
<p><span>The scary part is that most antivirus applications will not detect Nine-Ball&#8217;s malicious code. Websense experts report, that &#8220;the exploit is detected by only three of the 41 most commonly used AV programs.&#8221;</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/nine-ball-mass-injection-has-compromised-40000-websites-to-date/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
