KBD

Keith Devens .com

Thursday, May 17, 2012 Flag waving
The Lord is my shepherd; I shall not want. – David (Psalm 23)
← I dislike Ron Kuby even more nowDead Like Me →

Daily link icon Friday, June 25, 2004

New Internet virus targets IIS and IE.

There's some new Internet worm/virus spreading around that exploits a few different holes in Microsoft software at the same time.

Web infection may be aimed at stealing financial data

The infection appears to take advantage of three separate flaws with Microsoft Corp. products. Microsoft said software updates to fix two of them had been released in April, but the third flaw was newly discovered and had no patch to fix it yet.

"Users should be aware that any Web site, even those that may be trusted by the user, may be affected by this activity and thus contain potentially malicious code," the U.S. Computer Emergency Readiness Team warned in an Internet alert.

Infectious Web sites attack through Microsoft browser

"The attacker uploaded a small file with (JavaScript) to infected web sites, and altered the web server configuration to append the script to all files served by the web server," according to an explanation posted by the Internet Storm Center in Bethesda, Md.

The JavaScript instructs the user's browser to download and install various malicious programs from a Russian Web site, including a keystroke logger and other software that could give hackers unauthorized access to an infected computer.

"No warning will be displayed," the explanation emphasized." The user does not have to click on any links. Just visiting an infected site will trigger the exploit."

Experts said the attack's effects were unusually broad but weren't substantially interfering with Internet traffic.

So, it exploits holes in IIS that cause it to append some Javascript to all pages served, which then exploits holes in Internet Explorer to install keyloggers and whatever else. Pretty impressive, actually.

This is an example of why I recommend that no one ever use Internet Explorer, ever, for security reasons.

Security experts noted that users can avoid the exploit by using alternative browsers such as Mozilla and Opera. Users could also turn off the "Javascript" feature on their Microsoft browsers, though doing so cripple functions on some sites.

And, of course. The Macintosh is safe:

The infection does not affect Macintosh versions of Internet Explorer.

Update: More at Slashdot, via Julian

Update: As I expected he would, Kayode has a whole bunch more.

← I dislike Ron Kuby even more nowDead Like Me →

Comments XML gif

Revence 27 (http://www.revence27.faithweb.com) wrote:

OK. Now you have beaten me. But I am not the kind of guy to worry about viruses. And I take some very cautious measures. And I use Internet cafes.
Live on, Mozilla. But live on longer, Internet Explorer.

∴ Revence 27 | 26-Jun-2004 9:53am est | http://www.revence27.faithweb.com | #4871

Revence 27 (http://www.revence27.faithweb.com) wrote:

And besides, it is anti-Microsoftists like yourself that punch out these ugly programs. I am going against Mozilla soon.

∴ Revence 27 | 26-Jun-2004 10:00am est | http://www.revence27.faithweb.com | #4872

Jim wrote:

Yeah, Microsoft keeps writing software with security holes, so when viruses take advantage of them, of course it's Mozilla's fault!

Get a clue. Using Microsoft software is like having a "kick me" sign on your back.

∴ Jim | 28-Jun-2004 9:58am est | #4881

Feel free to post a comment below. Please see my comment policy.

Formatting Rules (No HTML):

  • **bold**, *italic*, _underlined_, --strikeout--
  • "text"="url" creates a link, and URLs are auto-highlighted
  • Blockquote: Like e-mail, begin paragraph with > (greater-than sign)
  • Lists: begin paragraph with *,-, or + (unordered), or # (ordered)
  • Code block: ?!code:language=perl|php|sql|javascript|etc.{\n}...{\n}?!/code

:
(will be your IP address if blank)
: (optional)
(Will not be shown on site)

: (optional)
:

May 2012
SunMonTueWedThuFriSat
 12345
6789101112
13141516171819
20212223242526
2728293031 



RSS feed RSS feed for Keith's Weblog
Atom feed Atom feed for Keith's Weblog
Weblog archive
Recent comments
  on 4 posts

Recent comments XML

new⇒Acknowledging the Arrival of Peak Government

In many ways, Peak Oil is​responsible for this new​uselessness of the big g...

Revence: May 16, 6:35am

new⇒Tab EXSPLOSION

Right now, I, too, have too many​tabs open. A rough count says​25.
Right. ...

Revence: May 16, 6:21am

George W. Bush: ‘I’m for Mitt Romney’ - ABC News

A marked difference (departure,​even) from the KBD of eight--yea,​even four...

Revence: May 15, 1:55pm

WebOb — WSGI request and response objects

Google App Engine forces one to​learn these....

Revence: May 15, 1:52pm

Generated in about 0.221s.

(Used 8 db queries)