It seems there is a widespread attack around s/w missing MS07-004
From WebSense:
"This mass injection is remarkably similar to the attack we saw earlier this month. ... Once loaded, the file attempts 8 different exploits (the attack last April utilised 12). The exploits target Microsoft applications, specifically browsers not patched against the VML exploit MS07-004 as well as other applications"
From News.com "Javascript injection claims UN and UK government sites"
Comments