HomeSecurityHackers exploited a flaw in the Krpano framework for Spam Ads

Hackers exploited flaw in Krpano framework for Spam Ads

A cross-site scripting (XSS) vulnerability in the Krpano virtual browser system is being used by hackers to inject malicious scripts into hundreds of websites, aiming to corrupt search results and support a spam ads campaign.

See also: iMessage: Hackers trick you into disabling phishing protection

Krpano Spam Ads

Security researcher Oleg Zaytsev, in a report published on The Hacker News, revealed that the campaign, dubbed 360XSS, affected over 350 websites. These include government portals, US state government websites, American universities, major hotel chains, news agencies, car dealerships, and several Fortune 500 companies.

All of these sites have one thing in common: They use Krpano, a popular integration framework, to create interactive virtual tours and VR experiences with 360° images and videos.

Zaytsev discovered Krpano's spam ads campaign when he came across an ad related to pornographic content appearing on Google Search, but accompanied by a domain that appeared to be associated with Yale University (“virtualtour.quantuminstitute.yale[.]edu”).

An important element of these URLs is an XML parameter that is intended to direct the website visitor to another URL, which belongs to another trusted website. This process is used to execute a Base64 through an XML document. Once decoded, the payload retrieves the pre-defined URL (such as an advertisement) from another equally legitimate website.

See also: WordPress: Critical vulnerabilities in Spam protection, Anti-Spam, FireWall plugin

The XML parameter included in the original URL, as displayed in search results, is part of a larger setting known as “passQueryParameters“. This is used when embedding a Krpano viewer in an HTML page. Its purpose is to pass HTTP parameters from the URL directly to the viewer.

Hackers exploited flaw in Krpano framework for Spam Ads

When this option is enabled, there is a risk that a malicious user could run a malicious script in your browser using a specially crafted URL when you visit a vulnerable website. 

The campaign exploits the Krpano framework, and has exploited this vulnerability to infiltrate over 350 websites, serving spam ads related to pornography, dietary supplements, online casinos, and disinformation sites. Some of these pages were also used to boost views on YouTube videos.

See also: Black Friday 2024: 77% of spam emails are scams

Cross-site scripting (XSS) is one of the most common vulnerabilities on the web. It occurs when an attacker exploits a system weakness to inject malicious code into a website, and that code is executed by the visitor's browser. 

How can you protect yourself? To protect yourself from such attacks, it is important to be careful about the links you follow online. Keep your software up to date and use anti-malware tools. In addition, website developers must ensure that user data is not processed without proper sterilization and verification. It is important to keep your browser up to date and use add-ons that offer additional layers of security, such as uBlock Origin to block suspicious scripts.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS