Latest MyDoom worm exploits Web site guestbooks
The worm that brought down Google strikes again, with a new variant that links to Web sites compromised by their use of standard scripts
A new variant of the MyDoom worm discovered on Tuesday downloads malware from an MP3-downloading site and a personal Web site, according to security experts, who claim that hackers have compromised these sites by exploiting scripting vulnerabilities in their guestbooks.
Security company F-secure is trying to close down the hacked sites but has not yet managed to contact the US-based site administrators or ISPs hosting the threat. Mikko Hypponen, director of antivirus research at F-Secure, warned that until the sites are brought down and the security holes closed, the worm, MyDoom.S, will continue to cause problems.
"As long as the sites are up and running we have to keep monitoring them," says Hypponen. "The hackers can keep changing what is on the sites -- if we block a data-stealing Trojan, they can simply replace that with a different application."