Afrihost - Possible 'Man in the Middle' attacks?

narf23

Well-Known Member
Joined
Nov 4, 2008
Messages
133
Reaction score
0
Location
Durban. South Africa
I received a call from one of my customer’s letting me know their ESET EndPoint AntiVirus is blocking JS/ScrInject.B Trojan Threats to quite a few websites.

Tested on my side and same thing.

We both running on Afrihost ADSL and changed to Telkom LTE - tested and sites working perfectly and not being blocked.

My question - is it possible for an ISP to be attacked with 'Man in the Middle' attacks?
ESET Support said it is a false positive and run a virus database update this should resolve the issue.
But before I managed run an update, changed back to Afrihost and websites working.

2016-02-29 14_30_47-Alert! - ESET Endpoint Antivirus.png
 
I received a call from one of my customer’s letting me know their ESET EndPoint AntiVirus is blocking JS/ScrInject.B Trojan Threats to quite a few websites.

Tested on my side and same thing.

We both running on Afrihost ADSL and changed to Telkom LTE - tested and sites working perfectly and not being blocked.

My question - is it possible for an ISP to be attacked with 'Man in the Middle' attacks?
ESET Support said it is a false positive and run a virus database update this should resolve the issue.
But before I managed run an update, changed back to Afrihost and websites working.

View attachment 346081

Short answer is YES, most ISP's run transparent cache's using WCCP. If that is compromised the attacker can inject malicious code into the responses.
 
I received a call from one of my customer’s letting me know their ESET EndPoint AntiVirus is blocking JS/ScrInject.B Trojan Threats to quite a few websites.

Tested on my side and same thing.

We both running on Afrihost ADSL and changed to Telkom LTE - tested and sites working perfectly and not being blocked.

My question - is it possible for an ISP to be attacked with 'Man in the Middle' attacks?
ESET Support said it is a false positive and run a virus database update this should resolve the issue.
But before I managed run an update, changed back to Afrihost and websites working.

View attachment 346081

Dude,this is nothing so malicious. Google
Bad ESET update,revert to 6 hours ago or update to absolute latest

https://www.reddit.com/r/sysadmin/comments/489jep/eset_flagging_sites_as_threats/
 
Top
Sign up to the MyBroadband newsletter
X