Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





The coffee shop Drop in and hang around if you wish, just bring
some doughnuts.. Everything from sports whatever.

Reply
 
Thread Tools Display Modes
  #1  
Old 11-23-2004, 12:01 AM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
By Gregg Keizer, TechWeb News

A hacked server in Germany fed malicious code to unsuspecting Internet Explorer users at an unknown number of Web sites for several hours over the weekend, a banner ad-serving company acknowledged Monday.

The affected Web sites included trusted sites in the U.K., the Netherlands, and Sweden, according to the Internet Storm Center of the SANS Institute. Users who visited one of the impacted sites stood a 1-in-30 chance of being infected with a worm that exploits the still-unpatched IFRAME vulnerability in Microsoft's Internet Explorer 6.0.

Recent versions of the MyDoom worm have exploited the IFRAME vulnerability, as has the Bofra worm, which is what security firms which believe the exploit is dissimilar to MyDoom, have dubbed the threat. Whatever the name, the IFRAME exploit can let hackers grab control of infected PCs.

The sequence of events went like this. Early Saturday morning in Germany, a load balancing server run by Falk eSolutions AG was hacked. Load balancing servers sit in front of the actual delivery servers, and parse out ad requests made by Web sites to equalize workloads.

For over six hours, from 5:10 to 11:30 a.m., GMT (12:10 to 6:30 a.m., EST), a virus was "inadvertently redistributed to a small number of users," Falk said in a statement. The hack sent user requests for banner ads -- such requests are invisibly sent by browsers whenever they hit a site with ads -- being redirected from the ad servers to a compromised site. That site, in turn, delivered a Bofra worm to the target computer.

On Sunday, the U.K.-based technology news Web site The Register said that it was one of the affected sites. Although the site suspended ad serving operations from Falk, it warned users that they may have been infected. Unless users were running Windows XP Service Pack 2 (SP2), which is immune to the IFRAME vulnerability, The Register recommended that its readers scan for viruses and install SP2 if possible.

"Consider running an alternative browser," The Register said in a statement, "at least until Microsoft deals with the issue."

According to SANS Institute's Internet Storm Center, sites in the Netherlands and Sweden were also compromised by the Falk hack. "This may indicate a more wide-spread attack across Europe," wrote Marcus Sachs, the center's director, in an alert posted on its Web site.

DoubleClick, the largest ad-serving firm in the U.S., declined to comment on Falk's predicament Monday, but said it was preparing a statement to its customers about what precautions it's taken. "We can't really discuss them because of security concerns," a DoubleClick spokesperson said.

Security analysts, though not alarmed, sounded concerned at the news of the infection.

"Frankly, I'm surprised we haven't seen more of this kind of thing," said Vincent Gullotto, the vice president of McAfee's AVERT virus research group. "One thing it certainly points out is that anything today can be a target [of hackers]."

While Gullotto wasn't willing to call this outbreak a turning point in hacking -- for one thing, this isn't the first time that surfing to a trusted site infected IE users -- he did note that the longer the IFRAME vulnerability remains unpatched, the more likely other attackers will join the fray.

"It doesn't take much for them to notice what's effective and then replicate it," he said.

"We're at the point now where things are almost like a blur," said Gullotto. "It's just not going to be clear cut going forward as to what kind of threats we face. This may be one of the first to exploit a vulnerability and use adware to deliver the tool, but there are bots downloading exploits, mass-mailers to contend with, and worms creating bot networks.

"We face a barrage of threats because hackers are always looking for new and interesting ways to get people infected."
Reply With Quote
Posted


Reply

  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
  • Bookmarks

    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools
    Display Modes

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off
    Forum Jump

    Similar Threads
    Thread Thread Starter Forum Replies Last Post
    Sun Java System Server XSite Scripting Mobo Security Alerts and vulnerabilities 0 03-23-2005 02:00 PM
    Media Player Remote PNG for windows server Mobo Security Alerts and vulnerabilities 0 02-09-2005 02:13 PM
    Microsoft December security update Mobo News & Announcements 0 12-18-2004 08:30 AM
    Web Forums Server Multiple Vulnerabilities Mobo Security Alerts and vulnerabilities 0 11-03-2004 08:23 AM



    All times are GMT -5. The time now is 05:23 PM.


    Firefox 2