Poor Web Application Security Leads to Mass Infections Targeting End Users
On Monday June 7, 2010, we witnessed one such attack. Beginning at 3:56am PST, Zscaler’s NanoLog servers began recording requests to ww.robint.us/u.js. Over the next few hours, requests for this Javascript file began to pick up. Why? Because 1,000+ websites had been infected with a simple <script> tag, which pointed to the file.