Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Mysterious Attack Hits Web Servers
The WGALchannel.com ^ | June 25, 2004 | Internet Broadcasting System, API

Posted on 06/25/2004 9:12:00 AM PDT by all4one

Government and industry experts are reporting a mysterious, large-scale Internet attack against thousands of popular Web sites.

The virus-like infection tries to implant hacker software onto the computers of all Web site visitors.

Industry experts and the Homeland Security Department are studying the infection to determine how it spreads across Web sites and find adequate defenses against it.

A government warning says even Web sites trusted by users may contain the potentially malicious code. The infection appears to target at least one recent version of Microsoft's Internet Information Server, which is popular among businesses and organizations.

The United States Computer Emergency Readiness Team says the problem adds a piece of JavaScript to the bottom of Web pages that accesses another server.

US-CERT says disabling JavaScript will prevent this activity from affecting a user's system, but it could make some sites that use JavaScript appear incorrectly. The attack's effects are said to be unusually broad, but are not substantially interfering with Internet traffic.


TOPICS: Business/Economy; Crime/Corruption; Extended News; Government; News/Current Events
KEYWORDS: attack; catholiclist; computer; crime; cyber; cybersecurity; hackers; internet; java; mysterious; server; software; web; websites
Careful surfing everyone....pass this information on.
1 posted on 06/25/2004 9:12:01 AM PDT by all4one
[ Post Reply | Private Reply | View Replies]

To: all4one

How do we disable java for awhile? My Norton expired yesterday and I am waiting for my new norton to arrive snailmail, so I can't update right now.


2 posted on 06/25/2004 9:16:23 AM PDT by I still care
[ Post Reply | Private Reply | To 1 | View Replies]

To: I still care

Go to your Control Panel and choose your Internet Options icon. There should be a file tab labeled "Advanced", click on this tab and then scroll down and hit the check box to disable the Java Script.

If you are working in a corporate environment, check with your IT coodinator.


3 posted on 06/25/2004 9:19:25 AM PDT by all4one (Psalm 27:1-6)
[ Post Reply | Private Reply | To 2 | View Replies]

To: all4one

I got hit by "something" yesterday. It was very weird. Don't know if it was connected to the site I was surfing, but it happened when I was sent to an Acrobat Reader site. I sort of "lost control" of the computer for about three minutes, and when I got control back, the computer had reverted to original defaults, and my browser page looks different now. Think I'll go do a virus hunt. Thanks for the heads-up!


4 posted on 06/25/2004 9:19:28 AM PDT by EggsAckley (........"John Kerry changes positions more often than a Nevada prostitute".........)
[ Post Reply | Private Reply | To 1 | View Replies]

To: all4one

Anyone seen the addresses their being directed to? I'd like to blackhole those at the intenet router.


5 posted on 06/25/2004 9:21:19 AM PDT by tacticalogic (I Controlled application of force is the sincerest form of communication.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: I still care
Not to be overly picky, but javascript is not actually java. My memory is fuzzy, but javascript is a script language used in web pages with syntax a little like that of java. But java is an entirely different animal.
6 posted on 06/25/2004 9:21:22 AM PDT by stubb
[ Post Reply | Private Reply | To 2 | View Replies]

To: EggsAckley
Don't know if it was connected to the site I was surfing, but it happened when I was sent to an Acrobat Reader site.

It might've been innocuous, Eggsie. Were you trying to view a .PDF file at the time? Acrobat will automatically try to update itself if you're using an older version.

7 posted on 06/25/2004 9:22:11 AM PDT by martin_fierro (I transcend you.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: all4one

...and I repeat...everyone purchase a second HD - and a copy of 'Ghost'. All this needless fretting....


8 posted on 06/25/2004 9:25:58 AM PDT by TomServo ("I'm so upset that I'll binge on a Saltine.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: tacticalogic

The way this article reads, the attachment is a stealth that is not being detected.


9 posted on 06/25/2004 9:26:16 AM PDT by all4one (Psalm 27:1-6)
[ Post Reply | Private Reply | To 5 | View Replies]

To: all4one

so that’s what’s going on I was a bit suspicious


10 posted on 06/25/2004 9:31:09 AM PDT by ezoeni
[ Post Reply | Private Reply | To 1 | View Replies]

To: all4one

They seem to know it's accessing another server. Gotta be an IP address to go with it.


11 posted on 06/25/2004 9:31:14 AM PDT by tacticalogic (I Controlled application of force is the sincerest form of communication.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: I still care

Also Control Panel....Internet Options.....Security tab...Custom Level

For the Active X and Java controls, choose either Disable or Prompt.


12 posted on 06/25/2004 9:35:11 AM PDT by all4one (Psalm 27:1-6)
[ Post Reply | Private Reply | To 2 | View Replies]

To: all4one
YIKES! FR falls into the POPULAR website category! Careful all!!
13 posted on 06/25/2004 9:35:32 AM PDT by RoseofTexas
[ Post Reply | Private Reply | To 1 | View Replies]

To: tacticalogic

I haven't run across this problem yet, but I have ZoneAlarm which would probably prompt me with the IP address. Without decent virus software, most people would probably never know.


14 posted on 06/25/2004 9:37:30 AM PDT by all4one (Psalm 27:1-6)
[ Post Reply | Private Reply | To 11 | View Replies]

To: martin_fierro

I don't really know what was going on. I was searching for sites on log cabin homes, and one that I clicked on sent me into this three-minute "no-zone." I DO recall seeing Acrobat Reader somewhere in the miasma during the stall.


15 posted on 06/25/2004 9:44:06 AM PDT by EggsAckley (........"John Kerry changes positions more often than a Nevada prostitute".........)
[ Post Reply | Private Reply | To 7 | View Replies]

To: all4one

I think there's a good probablility this is installing a back-door remote access trojan to be used later, either for sending spam or for DDOS attacks. We need an anti-virus that finds it, and leaves it there, but modifies it so that all it does is log and report the IP address of anyone attempting to access that back door.


16 posted on 06/25/2004 9:49:02 AM PDT by tacticalogic (I Controlled application of force is the sincerest form of communication.)
[ Post Reply | Private Reply | To 14 | View Replies]

To: RoseofTexas

FR does not run on Windows IIS.


17 posted on 06/25/2004 9:55:19 AM PDT by RedWing9 (No tag here... Just want to stay vague...)
[ Post Reply | Private Reply | To 13 | View Replies]

To: all4one; *Catholic_list; american colleen; sinkspur; Lady In Blue; Salvation; Polycarp IV; ...
Just breaking on the AP Wire ...

NEW YORK (AP) _ A mysterious Internet virus being spread Friday by hundreds and possibly thousands of infected Web sites may be aimed at stealing credit card and other valuable information, security experts warned.

The infection appears to take advantage of three separate flaws with Microsoft Corp. products. Microsoft said software updates to fix two of them had been released in April, but the third flaw was newly discovered and had no patch to fix it yet.

Experts said the infection, detected by Microsoft on Thursday, was unusually broad but wasn't substantially interfering with Internet traffic. Security experts at Microsoft and elsewhere worked Friday to pin down how the infection spreads across Web sites. It appears to target at least one recent version of Microsoft software for operating Web sites _ called Internet Information Server.

The infection makes subtle changes to the Web site so visitors get a piece of code that's designed to retrieve from a Russian Web site software that records a person's keystrokes and can send data back, experts say. Such software ``Trojan horses'' are routinely used to fish for credit card numbers, bank accounts, passwords and the like.

Now that the code is out, other hackers are likely to adapt it to distribute software for spamming and for launching broad Internet attacks against popular Web sites, said Alfred Huger, senior director of engineering at security company Symantec Corp. ``Users should be aware that any Web site, even those that may be trusted by the user, may be affected by this activity and thus contain potentially malicious code,'' the U.S. Computer Emergency Readiness Team warned in an Internet alert.

Stephen Toulouse, a security program manager at Microsoft, recommended that computer owners obtain the latest security updates for Microsoft products and their anti-virus and firewall programs.

Because one flaw has yet to be fixed, he said, users should also turn up security settings on Microsoft's Internet Explorer browsers to the highest levels. Security experts noted that users can avoid the exploit by using alternative browsers such as Mozilla and Opera. Users could also turn off the ``Javascript'' feature on their Microsoft browsers, though doing so cripple functions on some sites. The infection does not affect Macintosh versions of Internet Explorer.

18 posted on 06/25/2004 9:56:26 AM PDT by NYer ("Do not neglect to show hospitality to strangers, for by doing that some have entertained angels.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: NYer

Wow....thanks for the update..


19 posted on 06/25/2004 10:00:35 AM PDT by all4one (Psalm 27:1-6)
[ Post Reply | Private Reply | To 18 | View Replies]

To: WestCoastGal; Indie; Cindy; JustPiper; milkncookies; Quix; KylaStarr; thecabal; Jill St Claire; ...

Update from NYer on today's Internet Virus.....Careful browsing!!!


20 posted on 06/25/2004 10:04:45 AM PDT by all4one (Psalm 27:1-6)
[ Post Reply | Private Reply | To 18 | View Replies]

To: all4one

Thanks for the heads up. I run my settings on high security all the time. Have two firewalls and anti virus.........probably never enough.....and spyhunter as well.

Anything else I should go shopping for?


21 posted on 06/25/2004 10:13:24 AM PDT by WestCoastGal (Freeping & Nascar >>>>>>>>>>>>>>>>>>>>>>>>>>> How Bad Have You Got It????)
[ Post Reply | Private Reply | To 20 | View Replies]

To: all4one

Mac OSX and the web browser Safari are not affected by this.
Just sitting back and laughing.


22 posted on 06/25/2004 10:15:39 AM PDT by Wacka
[ Post Reply | Private Reply | To 1 | View Replies]

To: WestCoastGal

A Mac?


23 posted on 06/25/2004 10:16:12 AM PDT by Wacka
[ Post Reply | Private Reply | To 21 | View Replies]

To: all4one

Thanks for the reminder, all4one...It is a treacherous world here on the global Internet highway.


24 posted on 06/25/2004 10:16:45 AM PDT by Donna Lee Nardo
[ Post Reply | Private Reply | To 20 | View Replies]

To: Wacka

"Mac OSX and the web browser Safari are not affected by this.
Just sitting back and laughing."

They still sell those?!

Seriously, why is it that Mac users feel compelled to come across as smug and obnoxious. I can appreciate the technical value of a Mac, but the zealot nature of the users makes me ill.


25 posted on 06/25/2004 10:31:50 AM PDT by brownsfan (Build a man a fire, he'll be warm for a day. Set a man on fire, he'll be warm the rest of his life.)
[ Post Reply | Private Reply | To 22 | View Replies]

To: all4one

check back


26 posted on 06/25/2004 10:33:01 AM PDT by mlbford2 (Sorry for spelling errors, I'm a product of a state university)
[ Post Reply | Private Reply | To 1 | View Replies]

To: all4one

It came up on the New York Horse Racing homepage the other night on my friends computer..took him hours to get rid of it.


27 posted on 06/25/2004 10:35:24 AM PDT by My Favorite Headache (Rush 30th Anniversary Tour Tickets On Sale Now!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: brownsfan

I agree as well even though Im on a mac right now. :o)


28 posted on 06/25/2004 10:37:52 AM PDT by ezoeni
[ Post Reply | Private Reply | To 25 | View Replies]

To: TomServo

RE: #8

Good Call.


29 posted on 06/25/2004 10:44:56 AM PDT by 50 Cal
[ Post Reply | Private Reply | To 8 | View Replies]

To: all4one

Thanks for the heads up


30 posted on 06/25/2004 10:47:13 AM PDT by freeperfromnj
[ Post Reply | Private Reply | To 1 | View Replies]

To: All

Or per this article dump IE

The last sentence is pretty amusing.

http://news.com.com/Researchers+warn+of+infectious+Web+sites/2100-7349_3-5247187.html?tag=nefd.lede



This time, however, the flaws affect every user of Internet Explorer, because Microsoft has not yet released a patch. Moreover, the infectious Web sites are not just those of minor companies inhabiting the backwaters of the Web, but major companies, including some banks, said Brent Houlahan, chief technology officer of NetSec.

Meanwhile, the average Internet surfer is left with few options. Windows users could download an alternate browser, such as Mozilla or Opera, and Mac users are not in danger.

NetSec's Houlahan advocated drastic action.

"I told my wife, unless it is absolutely necessary and unless you are going to a site like our banking site, stay off the Internet right now," he said.


31 posted on 06/25/2004 10:51:39 AM PDT by mpreston
[ Post Reply | Private Reply | To 29 | View Replies]

To: 50 Cal

lol - thanks. It's really just common sense. Easy, cheap, relatively painless. I could get everything thrown at me and in 15 minutes have a clean install.


32 posted on 06/25/2004 10:53:15 AM PDT by TomServo ("I'm so upset that I'll binge on a Saltine.")
[ Post Reply | Private Reply | To 29 | View Replies]

To: TomServo

I'm not questioning your suggestion, just asking an honest (somewhat computer ignorant) question. If you only have a laptop what good will a second hard drive do?


33 posted on 06/25/2004 11:13:51 AM PDT by Oorang ( Those who trade liberty for security have neither)
[ Post Reply | Private Reply | To 8 | View Replies]

To: all4one

Many thanks for the ping a4o


34 posted on 06/25/2004 11:18:52 AM PDT by Oorang ( Those who trade liberty for security have neither)
[ Post Reply | Private Reply | To 20 | View Replies]

To: Oorang
You don't necessarily have to copy the image to HD, it'll also burn to a CD and span the CD's, too. I also use a second drive to store my files/docs on. Those aren't imaged. And I'll bet you can purchase an external USB drive for your laptop. Now that could be pricey.
35 posted on 06/25/2004 11:22:25 AM PDT by TomServo ("I'm so upset that I'll binge on a Saltine.")
[ Post Reply | Private Reply | To 33 | View Replies]

To: TomServo
Thanks. Interesting timing. My hard drive died a couple of weeks ago. Older laptop, no read/write CD. Quote from local computer shop to recover all data from the hard drive - $1500.00 !!! Think I'll pass. New laptop has read/write CD so I can back up all data.

span the CD's
What does that mean?

Regarding your saltine binges, have you tried the new cheddar cheese saltines? Might up the quality of your binges :-)

36 posted on 06/25/2004 11:42:38 AM PDT by Oorang ( Those who trade liberty for security have neither)
[ Post Reply | Private Reply | To 35 | View Replies]

To: brownsfan

The PC people always say that the reason they buy them are that PCs are cheaper. But then they write they have to buy Norton, Zone Alarm, download Spybot, AdAware, etc, etc, and have to spend so much time updating all these. In the long run, it comes out about the same $. And us Maccies don't have the aggrivation of fighting all those viruses.


37 posted on 06/25/2004 12:07:45 PM PDT by Wacka
[ Post Reply | Private Reply | To 25 | View Replies]

To: WestCoastGal
Anything else I should go shopping for?

A cruise missile that can do a traceroute would be nice.

38 posted on 06/25/2004 12:21:15 PM PDT by tacticalogic (I Controlled application of force is the sincerest form of communication.)
[ Post Reply | Private Reply | To 21 | View Replies]

To: Wacka

"And us Maccies "

Yeah, but with that attitude, I'd guess that you "Maccies" are the same kids I used to beat up in school.

Enjoy your computing experience, educate those that need it and WANT it. But, drop tha attitude. I know people who wouldn't consider a Mac purely because of the attitude of Mac users. It helps to have a user base, look at the shareware. Not to mention, Linux runs on Intel, and I know Mac OS X is BSD based, but how many Linux distos support Mac?


39 posted on 06/25/2004 1:00:13 PM PDT by brownsfan (Build a man a fire, he'll be warm for a day. Set a man on fire, he'll be warm the rest of his life.)
[ Post Reply | Private Reply | To 37 | View Replies]

To: all4one

What's so mysterious about another Windows flaw?


40 posted on 06/25/2004 1:02:10 PM PDT by Redcloak (My tagline reminds John Kerry of Vietnam. Did you know that John Kerry was in Vietnam?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Oorang

Spanning the CD's simply means that the image will burn to multiple CD's. And I promise - It'll take multiple CD's. In addition to keeping my data on a separate drive - I also burn my files to DVD's, Just in case the HD's fail.


41 posted on 06/25/2004 1:33:11 PM PDT by TomServo ("I'm so upset that I'll binge on a Saltine.")
[ Post Reply | Private Reply | To 36 | View Replies]

To: tacticalogic

It's Russian stuff.

Go to: www.incidents.org, which is a neat little website that I've bookmarked, run by IS pros for the benefit of IS administrators.

You may have to scroll through a bit of stuff. The memos/updates of 6/24 were quite informative.

Although they published the 'go-to-' numbers (217 prefixes) they STRONGLY advised that one should play carefully...


42 posted on 06/25/2004 2:08:37 PM PDT by ninenot (Minister of Membership, TomasTorquemadaGentlemen'sClub)
[ Post Reply | Private Reply | To 5 | View Replies]

To: ninenot

Thanks. I'd read it was a Russian network, but hadn't seen a specific IP or range.


43 posted on 06/25/2004 2:16:00 PM PDT by tacticalogic (I Controlled application of force is the sincerest form of communication.)
[ Post Reply | Private Reply | To 42 | View Replies]

To: ninenot

Looks like they've located and shut down the Russian server, so the current attack is pretty well disabled. All that's left now is the cleanup.


44 posted on 06/25/2004 2:44:22 PM PDT by tacticalogic (I Controlled application of force is the sincerest form of communication.)
[ Post Reply | Private Reply | To 42 | View Replies]

To: all4one

Thanks for the update all4one.


45 posted on 06/25/2004 3:17:45 PM PDT by milkncookies (There is in all of us a strong disposition to believe that anything lawful is also legitimate.)
[ Post Reply | Private Reply | To 20 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson