MPack – The Movie
The following video shows the MPac Penetration Kit which is used to inject hidden iframes into compromised websites that make visitors land on a malicious content, which attacks their machine with the latest browser vulnerabilities. The technique that is employed to compromise the legitimate sites is quite lame although it proves that the simplest things work really well all the time. I suspect we are going to see more of these in the future, although attackers technical abilities will get better.
I think I am actually going to write something about this soon as I keep hearing it over and over. There isn’t really an “iframe” exploit. Someone might make a virtually-invisible iframe reference to another page that houses exploit code, however, this is not an exploit with iframes. If you’re running unpatched software (and usually as an administrator) , that is why you got owned. Te iframe is simply how they pulled in the exploit code from the third party site.