Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

New Exploit Rocks IE, Downloads Scores Of Spyware, Adware
TechWeb ^ | September 19, 2006 | Gregg Keizer

Posted on 09/19/2006 5:36:00 PM PDT by Eagle9

An unpatched vulnerability in all editions of Microsoft's Internet Explorer browser is being exploited, security researchers said Tuesday, with the attack dumping a broad range of adware, spyware, and Trojans onto PCs whose users simply surf to an infected or malicious site.

First reported by Sunbelt Software -- although rival Internet Security Systems claimed it was the first to discover the bug -- the vulnerability is in how IE renders VML (Vector Mark-up Language), an extension of XML that defines on-the-Web images in vector graphics format. The previously unknown -- and thus unpatched -- bug inside IE is already being used by attackers.

So far, said Eric Sites, vice president of research and development at Sunbelt, the exploit has shown up on hardcore porn sites, which are serving a buffet of badware to users who visit those sites.

"First they were pushing Virtumondo adware," said Sites, "but by late afternoon yesterday, these sites were distributing more than 40 different types of malware, including keyloggers, adware, and backdoors."

The new exploit seems to have a connection to WebAttacker, an multi-exploit attack "kit" created by a Russian group that sells for as little as $15 to $20. "We think that this new exploit is inside a new [version of the] kit," said Sites. "If that's true, then it will end up all over the place."

Sites said he expects that the exploit will migrate to one of the so-called "iframe cash" sites -- the term comes from the iframecash.biz site -- which use affiliates to push unpatched exploits to a large number of other Web sites, some of which are legitimate addresses whose servers have been previously compromised.

"This could end up being in lots

(Excerpt) Read more at techweb.com ...


TOPICS: Technical
KEYWORDS: browser; embracethepenguin; exploit; getamac; godiamtiredofthis; ie; lowqualitycrap; malware; microsoft; microsoftsecurity; ocrap; pr0nware; spyware; windows
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-8081-95 next last
To: bitt

Perhaps it does explain something for me. I run Webroot Spy Sweeper a couple times a week because spyware seems to show up with regularity. Once, a back door trojan showed up. I do use IE occasionally, now I wonder if it has been the source of a lot of the crap that I have to get rid of with the Spy Sweeper.


61 posted on 09/19/2006 8:14:30 PM PDT by Enterprise (Let's not enforce laws that are already on the books, let's just write new laws we won't enforce.)
[ Post Reply | Private Reply | To 40 | View Replies]

To: Eagle9

III. Solution:XPLite


62 posted on 09/19/2006 8:16:04 PM PDT by philetus (Keep doing what you always do and you'll keep getting what you always get.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9

"I choose to use an alternative solution: Firefox or Opera as my browser."

Ditto, at least for anything other than a bank site. I hope the financial industry starts supporting Firefox better. The handwriting is on the wall.


63 posted on 09/19/2006 8:30:52 PM PDT by FastCoyote
[ Post Reply | Private Reply | To 1 | View Replies]

To: Echo Talon

"stop looking at porn and you dont have anything to worry about. :)"

Or, I could scoop my eyeballs out with a hot spoon. That and not looking at porn both have about the same probability of happening, though they are both a cure.


64 posted on 09/19/2006 8:38:27 PM PDT by FastCoyote
[ Post Reply | Private Reply | To 36 | View Replies]

To: Enterprise

try the free

http://www.ewido.com
.

you won't believe what it finds!

also, keep using your pop-up blocker....

and I STILL like spybot search and destroy.


65 posted on 09/19/2006 8:40:42 PM PDT by bitt ("And an angel still rides in the whirlwind and directs this storm.")
[ Post Reply | Private Reply | To 61 | View Replies]

To: FastCoyote

lol :)


66 posted on 09/19/2006 8:43:50 PM PDT by Echo Talon
[ Post Reply | Private Reply | To 64 | View Replies]

To: KoRn
To really make these alerts effective they should post very detailed information on how to use the exploits.
That would really light a fire under their asses!

Ha ha! Yeah, that would do it. But even then, could MS issue a patch as quickly as Firefox?

Secunia has rated this vulnerability rated Extremely Critical and says that eight versions of MS Windows Server are unpatched. Does this mean that the key loggers and trojans can spread very quickly across the Internet and infect anyone using IE6, even though they have not visited a porn site? It also says that the solution for IE users is to deactivate support for Active Scripting. IE should have a NoScript extension -- easily turned off and on. :)

Secunia
http://secunia.com/advisories/21989

67 posted on 09/19/2006 8:46:18 PM PDT by Eagle9
[ Post Reply | Private Reply | To 54 | View Replies]

To: HAL9000; IncPen; Bush2000

I just checked and Bush2000 hasn't posted since February 2006. Hope he's okay. He hasn't been banned. Anyone know anything? I always enjoyed the friendly banter.


68 posted on 09/19/2006 8:51:16 PM PDT by Richard Kimball (The most important thing is sincerity. Once you can fake that, everything else is easy.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: Eagle9
"It also says that the solution for IE users is to deactivate support for Active Scripting.

LOL! They should not even use it in that case.

69 posted on 09/19/2006 8:53:15 PM PDT by KoRn
[ Post Reply | Private Reply | To 67 | View Replies]

To: KoRn

You're quick!


70 posted on 09/19/2006 8:56:37 PM PDT by Eagle9
[ Post Reply | Private Reply | To 69 | View Replies]

To: Richard Kimball

The banter as I saw it was not always friendly, but I don't wish him any ill


71 posted on 09/19/2006 8:58:11 PM PDT by IncPen (Bush Iraq Truth WMD http://freedomkeys.com/whyiraq.htm)
[ Post Reply | Private Reply | To 68 | View Replies]

To: devolve

BTTT


72 posted on 09/19/2006 9:00:32 PM PDT by 185JHP ( "The thing thou purposest shall come to pass: And over all thy ways the light shall shine.")
[ Post Reply | Private Reply | To 50 | View Replies]

To: Eagle9

bookmark


73 posted on 09/19/2006 9:47:07 PM PDT by DocRock
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9

OK, I'm getting Firefox tomorrow. Freakin Microsoft.


74 posted on 09/19/2006 9:52:55 PM PDT by Mr. Silverback ("Now they will know better than to fight a martial arts master who is also made of gelatin!")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9

Hmmm...I posted that before I noticed that most of the users encountering this problem are getting it at porn sites. I WILL NOT have that problem...but i'm still changing to firefox.


75 posted on 09/19/2006 10:00:33 PM PDT by Mr. Silverback ("Now they will know better than to fight a martial arts master who is also made of gelatin!")
[ Post Reply | Private Reply | To 1 | View Replies]

To: potlatch

That's what I feel like, LOL.
I dread another black screen experience.


76 posted on 09/19/2006 10:05:25 PM PDT by ntnychik
[ Post Reply | Private Reply | To 44 | View Replies]

To: Eagle9
The joys of computer ownership/use BUMP.

thanks for info. I use mozilla 99% of time. The other day I could NOT open a weboage w/mozilla for some reason.. went to IE & no problem.

well, yes there was, The problem was that it bothered me that IE could do something Moz could not! (well, perhaps MS has loaded some "little treasures" to make Mozilla less than perfect?
77 posted on 09/19/2006 10:15:13 PM PDT by DollyCali (Don't tell GOD how big your storm is -- Tell the storm how B-I-G your God is!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: bitt
Firefox
78 posted on 09/19/2006 10:17:22 PM PDT by ForGod'sSake (ABCNNBCBS: An enemy at the gates is less formidable, for he is known and carries his banner openly.)
[ Post Reply | Private Reply | To 40 | View Replies]

To: ntnychik; devolve

Hmmm, don't know if you got to experience a bunch of black screens, lol. Blackout time!! Then they started dancing...


79 posted on 09/19/2006 10:19:10 PM PDT by potlatch (Does a clean house indicate that there is a broken computer in it?)
[ Post Reply | Private Reply | To 76 | View Replies]

To: Mr. Silverback
"We think that this new exploit is inside a new [version of the] kit," said Sites. "If that's true, then it will end up all over the place."

Microsoft is often relatively slow with their patches to vulnerabilities in IE. If they are this time, changing to Firefox would be a wise move. I don't go to porn sites either.

80 posted on 09/19/2006 10:22:58 PM PDT by Eagle9
[ Post Reply | Private Reply | To 75 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-8081-95 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson