[TheForge] Re: Ozark School

Mike Spencer mspencer at tallships.ca
Tue May 30 14:17:27 EDT 2006


> Is any one else having trouble getting into the tools page at the Ozark 
> School of Blacksmithing?

Disable javascript in your browser.  The bad stuff is javascript that
is getting stuck onto the bottom of many Ozarkschool.com pages.



In more technical terms,  the CGI script located at:

   http://www.ozarkschool.com/cgi-bin/shopper.cgi

creates many of these pages on the fly.  It appears that the script
has been corrupted by the intruder so that it adds a few lines of
obfuscated javascript to the end of each page it creates.  If you
disable javascript in your web browser, the malicious code won't get
executed on your home machine and you won't have problems.

DO REMEMBER that if you *save copies* of any of these pages on your
own computer, the malicious javascript will still be there!  If you
later re-enable javascript and subsequently look at the saved copies
of the pages, you'll get hit with the bad code again.



- Mike

-- 
Michael Spencer                  Nova Scotia, Canada       .~. 
                                                           /V\ 
mspencer at tallships.ca                                     /( )\
http://home.tallships.ca/mspencer/                        ^^-^^


More information about the TheForge mailing list