E60, E61 Parts, Accessories and Mods Discussion about both stock and aftermarket parts for the E60. Accessories and modifications too!

Beware bmwwheels.com infected with malicous script!!

Thread Tools
 
Search this Thread
 
Old 08-01-2008, 02:21 PM
  #1  
Members
Thread Starter
 
marcw's Avatar
 
Join Date: Jul 2008
Posts: 12
Likes: 0
Received 0 Likes on 0 Posts
Default

I'm just sending this out to warn everybody that the website www.bmwwheels.com is infected with a malicous javascript! I would not recommend visiting the site unless you use proper precautions such as the NoScript plugin available for Firefox.

Against my better judgement I browsed bmwwheels.com ealier today with IE 6 instead of Firefox. All was fine until I hit the details page for Style 124 wheels. All of a sudden my Anti-Virus program was alerting me that it had blocked a trojan that was attempting to install itself onto my system. The details page for the 124 wheels contains various references to a script called ngg.js all located on servers in Russia.

Ngg.js uses a familiar iframe attack to load additional content. I have contacted bmwwheels via email to alert them about this situation.

Here are two screenshots of my Anti-Virus ringing the alarm bells...


Old 08-01-2008, 06:12 PM
  #2  
Contributors
 
mrfva's Avatar
 
Join Date: Sep 2007
Location: .
Posts: 8,199
Likes: 0
Received 0 Likes on 0 Posts
My Ride: .
Model Year: .
Default

Originally Posted by marcw' post='637778' date='Aug 1 2008, 05:21 PM
I'm just sending this out to warn everybody that the website www.bmwwheels.com is infected with a malicous javascript! I would not recommend visiting the site unless you use proper precautions such as the NoScript plugin available for Firefox.

Against my better judgement I browsed bmwwheels.com ealier today with IE 6 instead of Firefox. All was fine until I hit the details page for Style 124 wheels. All of a sudden my Anti-Virus program was alerting me that it had blocked a trojan that was attempting to install itself onto my system. The details page for the 124 wheels contains various references to a script called ngg.js all located on servers in Russia.

Ngg.js uses a familiar iframe attack to load additional content. I have contacted bmwwheels via email to alert them about this situation.

Here are two screenshots of my Anti-Virus ringing the alarm bells...


I'll second that... Avast picked it up as well. Interesting
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
stream
Lounge
24
01-06-2006 11:59 PM
jakethesnake
Lounge
2
09-08-2005 09:47 AM
Rudy
Bluetooth & Cell Phone Forum
11
05-10-2005 06:18 AM
rduncan
Bluetooth & Cell Phone Forum
4
02-09-2005 10:07 AM
paasan
E60 Discussion
2
12-06-2003 08:17 AM



Quick Reply: Beware bmwwheels.com infected with malicous script!!



All times are GMT -8. The time now is 06:33 PM.