Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Trojan exploits unpatched IE flaw
The Register ^ | 1 December 2005 | John Leyden

Posted on 12/01/2005 7:41:41 AM PST by ShadowAce

The release of a Trojan that exploits an unpatched IE hole has prompted speculation that Microsoft may release an emergency out-of-cycle security patch. The Delf-DH Trojan downloader uses an Internet Explorer vulnerability to infect unprotected Windows users who stray onto maliciously constructed websites. Delf-DH downloads other malware onto infected machines changing settings in order to monitor user activity and redirect surfers onto porn sites.

The attack relies on a flaw in the way IE handles requests to the window() object, highlighted by proof-of-concept code last week and now used in anger by VXers. Even fully patched Windows 2000 and Windows XP systems are vulnerable. Until a patch is available to address this vulnerability, US-CERT strongly encourages Windows users to disable Active Scripting.

Security experts at the SANS Institute Internet Storm Centre speculate that the attack, though not widespread, is serious enough for Microsoft to release an out of cycle patch rather than waiting for its scheduled monthly patching day, which this month falls on 13 December. Microsoft isn't commenting on when a patch might be available but the smart money is on Redmond following a June 2004 precedent and releasing an emergency security fix outside its regular Patch Tuesday updates. ®


TOPICS: Crime/Corruption; Technical
KEYWORDS: ie; microsoft; reggiebush; trojan; yetanothermblunder
Navigation: use the links below to view more comments.
first 1-2021-29 next last
Beware of where you surf.
1 posted on 12/01/2005 7:41:41 AM PST by ShadowAce
[ Post Reply | Private Reply | View Replies]

To: rdb3; chance33_98; Calvinist_Dark_Lord; Bush2000; PenguinWry; GodGunsandGuts; CyberCowboy777; ...

2 posted on 12/01/2005 7:42:10 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

How do you disable active scripting?


3 posted on 12/01/2005 7:45:58 AM PST by GermanBusiness
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce
... infect unprotected Windows users who stray onto maliciously constructed websites

Porn at your own Risk!

4 posted on 12/01/2005 7:48:33 AM PST by TexasCajun
[ Post Reply | Private Reply | To 1 | View Replies]

To: GermanBusiness

Use Firefox


5 posted on 12/01/2005 7:48:50 AM PST by Xenophobic Alien (Kerry lost. Please take that stupid bumper sticker off your car!)
[ Post Reply | Private Reply | To 3 | View Replies]

To: GermanBusiness

Use Mozilla Firefox.


6 posted on 12/01/2005 7:49:53 AM PST by Danae (Anál nathrach, orth' bháis's bethad, do chél dénmha)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Xenophobic Alien

YOU BEAT ME!!!

KAAAAAAAAAAAAHHHNNNNNNNNNNNNN!!!!!!!!!!!


7 posted on 12/01/2005 7:50:16 AM PST by Danae (Anál nathrach, orth' bháis's bethad, do chél dénmha)
[ Post Reply | Private Reply | To 5 | View Replies]

To: GermanBusiness

;)

8 posted on 12/01/2005 7:51:25 AM PST by N3WBI3 (If SCO wants to go fishing they should buy a permit and find a lake like the rest of us..)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Xenophobic Alien

Agreed. IE sucks when compared to Firefox.


9 posted on 12/01/2005 7:56:37 AM PST by frankiep
[ Post Reply | Private Reply | To 5 | View Replies]

To: GermanBusiness

How to Disable Active Content in Internet Explorer:

http://support.microsoft.com/kb/q154036/

I'm not sure if I would do this, as it will affect your ability to use some sites. Also, if you decide to disable scripting, make a note of what you do so you can undo it after installing the patch.


10 posted on 12/01/2005 7:59:44 AM PST by Cicero (Marcus Tullius)
[ Post Reply | Private Reply | To 3 | View Replies]

To: ShadowAce

bump


11 posted on 12/01/2005 8:03:49 AM PST by VOA
[ Post Reply | Private Reply | To 1 | View Replies]

To: TexasCajun

"... infect unprotected Windows users who stray onto maliciously constructed websites

Porn at your own Risk!"

Not just porn. Warez sites tend to be buggy, some newsgroups(age showing), and chat programs can be vectors for the malware.

Opera, Mozilla, Flock (beta), Firefox, and others may not be a bad idea till proprietary Internet Explorer hole (PIEHOLE) gets closed.

Top sends


12 posted on 12/01/2005 8:14:11 AM PST by petro45acp (SUPPORT/BE YOUR LOCAL SHEEPDOG! ("On Sheep, Wolves, and Sheepdogs" by Dave Grossman))
[ Post Reply | Private Reply | To 4 | View Replies]

To: Danae

"One needs to be careful when one calls the dragon!..."


13 posted on 12/01/2005 8:15:27 AM PST by petro45acp (SUPPORT/BE YOUR LOCAL SHEEPDOG! ("On Sheep, Wolves, and Sheepdogs" by Dave Grossman))
[ Post Reply | Private Reply | To 7 | View Replies]

To: petro45acp
Not just porn. Warez sites tend to be buggy, some newsgroups(age showing), and chat programs can be vectors for the malware.

This type of attack isn't very effective against most people who don't go to such sites. It could be extremely dangerous though, if someone incorporated it into a hack of a legitimate site. I'd asses the danger of this defect to be low risk, but MS should put out a patch promptly to protect their customers.

14 posted on 12/01/2005 8:28:08 AM PST by zeugma (Warning: Self-referential object does not reference itself.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: zeugma
This type of attack isn't very effective against most people who don't go to such sites.

True, but it still affects those of us who don't go to those sites, by zombifying those who do. Those zombies then send out attacks/spam/etc to everyone else.

15 posted on 12/01/2005 8:37:30 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 14 | View Replies]

To: ShadowAce
True, but it still affects those of us who don't go to those sites, by zombifying those who do. Those zombies then send out attacks/spam/etc to everyone else.

Good point. This is really the only reason I care about windows viruses/worms. If it couldn't affect me, I would just let folks suffer in ingnorance of alternatives. Well... maybe not, but I'd think about it.;-)

16 posted on 12/01/2005 8:42:08 AM PST by zeugma (Warning: Self-referential object does not reference itself.)
[ Post Reply | Private Reply | To 15 | View Replies]

To: zeugma; N3WBI3
Check out Explorer Destroyer
17 posted on 12/01/2005 9:36:05 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 16 | View Replies]

To: ShadowAce
FIREFOX is causing me a problem when I go to the NewsMax site and link on a story I get a giant Pop Up of many thumbnails. It doesn't get it in Safari or Netscape...
18 posted on 12/01/2005 10:19:38 AM PST by tubebender (Why is it we never have time to visit family when they are alive but can always make their funerals)
[ Post Reply | Private Reply | To 1 | View Replies]

To: tubebender
Hmm. I don't get that. I went to NewsMax and clicked on the first story listed. No pop-ups. Just the story.

So--Have you checked your preferences for pop-ups in Firefox?
Tools-->Options-->Content and there is a checkbox for "Block pop-up windows" or something similar. Be sure that it is checked.

If it is checked, click on the "Allowed Sites" button ext to it, and see if you have any entries in there. If not, then my next step would be to run Spybot, Ad-aware, etc to clean up your system.

Let me know if that works or not. I'm interested to see what happens.

19 posted on 12/01/2005 10:26:33 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 18 | View Replies]

To: ShadowAce

Pop Ups are blocked with no exceptions. I cleared Cookies and Cache while I was there...


20 posted on 12/01/2005 10:37:24 AM PST by tubebender (Why is it we never have time to visit family when they are alive but can always make their funerals)
[ Post Reply | Private Reply | To 19 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-29 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson