On June 28, the popular video service Dailymotion was hacked to redirect its users to the Sweet Orange Exploit Kit. This exploit kit exploits vulnerabilities in Java, Internet Explorer, and Flash Player. If the vulnerabilities in the above applications are successfully exploited, a pay-per-click malware is downloaded to the victim's computer. As of this week, Dailymotion is no longer infected, as security technicians managed to eliminate the threat.
The attackers managed to compromise Dailymotion by injecting an iframe into its website. Let's recall that Dailymotion is at the top of the Alexa list and is in the 100 most popular websites. So the attackers could have potentially infected several computers with malware with this attack. The attack mainly affected Dailymotion visitors from the US and Europe.
How the attack worked
Attackers with the injected iframe on the Dailymotion website were able to redirect users to a different website. This website in turn sent users to a page containing the Sweet Orange Exploit Kit (Symantec has been patching it since 2013).
The Exploit Kit can detect vulnerable plugins on the user's computer and use the necessary exploits. Sweet Orange exploits the following known vulnerabilities:
- Microsoft Internet Explorer Use-After-Free Remote Code Execution Vulnerability (CVE-2013-2551)
- Adobe Flash Player Buffer Overflow Vulnerability (CVE-2014-0515)
- Oracle Java SE Remote Java Runtime Environment Vulnerability (CVE-2013-2460)
If the Exploit Kit successfully exploits any of the above vulnerabilities, it downloads Trojan.Adclicke onto the victim's computer. This malware forces the infected computer to click on pay-per-clicks advertisements in order to generate revenue for the attackers.
Source: secnews.gr

