Author Topic: Blog: Opera's web portal (reportedly) deployed online banking trojan  (Read 109 times)

Offline menotu

  • PCLinuxOS Tester
  • Super Villain
  • *******
  • Posts: 15279
  • ┌∩┐(◕_◕)┌∩┐
From heise Security 16 November 2012,

For a brief time, at least a "few hours", users visiting Opera's online portal at portal.opera.com were exposed to malware, according to a report from anti-virus specialist Bitdefender. In older versions of Opera, this portal page is set as the default start page, while in recent versions it is easily accessible from the Speed Dial menu that appears when a new tab is opened.

The report says that the exploit code was injected into the Opera page via a third-party ad server. Apparently, the advertisement code created an iFrame in which the criminals embedded an attack page from the Blackhole exploit kit. The injected page then attempted to use a specially crafted PDF document to exploit an old hole in Adobe Reader and infect the system with the ZeuS banking trojan. The malware was hosted on a – probably also hacked – web server in Russia.

An Opera spokesperson told The Register that there is no indication of any user infections. Opera has temporarily suspended its advertising system.

http://www.h-online.com/security/news/item/Opera-s-web-portal-reportedly-deployed-online-banking-trojan-1751410.html
PCLinuxOS 32bit KDE 4.10.1; kernel-3.4.11-pclos1.bfs & 64bit 3.2.18bfs; NVidia GeForce 8400GS 1GB 310.19 driver

Sony Vaio SVE1513A4ESI Laptop, Intel Core i5, 2.6GHz, 6GB RAM, 750GB, 15.6" Intel HD Graphics 4000