KBD

Keith Devens .com

Friday, March 12, 2010 Flag waving
Cause she's a better fighter than you are, that's why. She's younger, she's stronger, and she'... – "Frankie Dunn" (Million Dollar Baby)
← I dislike Ron Kuby even more nowDead Like Me →

Daily link icon Friday, June 25, 2004

New Internet virus targets IIS and IE.

There's some new Internet worm/virus spreading around that exploits a few different holes in Microsoft software at the same time.

Web infection may be aimed at stealing financial data

The infection appears to take advantage of three separate flaws with Microsoft Corp. products. Microsoft said software updates to fix two of them had been released in April, but the third flaw was newly discovered and had no patch to fix it yet.

"Users should be aware that any Web site, even those that may be trusted by the user, may be affected by this activity and thus contain potentially malicious code," the U.S. Computer Emergency Readiness Team warned in an Internet alert.

Infectious Web sites attack through Microsoft browser

"The attacker uploaded a small file with (JavaScript) to infected web sites, and altered the web server configuration to append the script to all files served by the web server," according to an explanation posted by the Internet Storm Center in Bethesda, Md.

The JavaScript instructs the user's browser to download and install various malicious programs from a Russian Web site, including a keystroke logger and other software that could give hackers unauthorized access to an infected computer.

"No warning will be displayed," the explanation emphasized." The user does not have to click on any links. Just visiting an infected site will trigger the exploit."

Experts said the attack's effects were unusually broad but weren't substantially interfering with Internet traffic.

So, it exploits holes in IIS that cause it to append some Javascript to all pages served, which then exploits holes in Internet Explorer to install keyloggers and whatever else. Pretty impressive, actually.

This is an example of why I recommend that no one ever use Internet Explorer, ever, for security reasons.

Security experts noted that users can avoid the exploit by using alternative browsers such as Mozilla and Opera. Users could also turn off the "Javascript" feature on their Microsoft browsers, though doing so cripple functions on some sites.

And, of course. The Macintosh is safe:

The infection does not affect Macintosh versions of Internet Explorer.

Update: More at Slashdot, via Julian

Update: As I expected he would, Kayode has a whole bunch more.

← I dislike Ron Kuby even more nowDead Like Me →

Comments XML gif

Revence 27 (http://www.revence27.faithweb.com) wrote:

OK. Now you have beaten me. But I am not the kind of guy to worry about viruses. And I take some very cautious measures. And I use Internet cafes.
Live on, Mozilla. But live on longer, Internet Explorer.

∴ Revence 27 | 26-Jun-2004 9:53am est | http://www.revence27.faithweb.com | #4871

Revence 27 (http://www.revence27.faithweb.com) wrote:

And besides, it is anti-Microsoftists like yourself that punch out these ugly programs. I am going against Mozilla soon.

∴ Revence 27 | 26-Jun-2004 10:00am est | http://www.revence27.faithweb.com | #4872

Jim wrote:

Yeah, Microsoft keeps writing software with security holes, so when viruses take advantage of them, of course it's Mozilla's fault!

Get a clue. Using Microsoft software is like having a "kick me" sign on your back.

∴ Jim | 28-Jun-2004 9:58am est | #4881

Feel free to post a comment below. Please see my comment policy.

Formatting Rules (No HTML):

  • **bold**, *italic*, _underlined_, --strikeout--
  • "text"="url" creates a link, and URLs are auto-highlighted
  • Blockquote: Like e-mail, begin paragraph with > (greater-than sign)
  • Lists: begin paragraph with *,-, or + (unordered), or # (ordered)
  • Code block: ?!code:language=perl|php|sql|javascript|etc.{\n}...{\n}?!/code

:
(will be your IP address if blank)
: (optional)
(Will not be shown on site)

: (optional)
:

March 2010
SunMonTueWedThuFriSat
 123456
78910111213
14151617181920
21222324252627
28293031 



RSS feed RSS feed for Keith's Weblog
Atom feed Atom feed for Keith's Weblog
Weblog archive

Generated in about 0.179s.

(Used 8 db queries)