Internet Security VML exploit Flaw causes problems with sites hosted with Host Gator

Host unlimited blogs, websites for $4.95 only with this web host

As reported at Netcraft, HostGator customers report that attackers are redirecting their sites to outside web pages that use the unpatched VML exploit in Internet Explorer to install trojans on computers of users. Site owners said iframe code inserted into their web pages was redirecting users to the malware-laden pages.

HostGator general manager Jason Muni told Security Fix that attackers had “reconfigured an unknown number of Web sites hosted on the company’s servers to redirect visitors to a third-party Web site that tried to load the IE exploit.” Muni said the company reconfigured all of its 200 servers to address the problem. But as of 5:30 pm EST Friday, some HostGator customers were continuing to report that their sites were compromised and redirecting visitors, indicating the problems were ongoing.

A subsequent forum posting by a HostGator staffer confirmed that the company has not yet come up with an effective defense against the attack. “We have everyone working on the situation, even a few CTO’s from other companies we know personally,” said the post from GatorBrent. “We can make the problem disappear for a little while but it keeps coming back on a majority of our servers. We believe this is a 0-day exploit with HostGator being the target. We are being completely overwhelmed currently with chat, phones, tickets, etc. We are working on finding the root of the problem so we can put a stop to it.”

An unofficial patch has been released by a group of veteran security researchers at the Zeroday Emergency Response Team (ZERT), “We think it’s great that there are people out there working to help protect our customers,” Microsoft’s Deacon wrote. “But as we’ve always said, we cannot endorse third party updates.”

This web hosting blog is proudly hosted with reliable Hostgator webhosting for only one cents through this hostgator coupon

Sorry, comments for this entry are closed at this time.