Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Internet Attack Exploits Microsoft Software Flaws ( Internet Explorer vulnerable )
Reuters ^ | Fri Jun 25, 2004 08:25 PM ET | Duncan Martell

Posted on 06/25/2004 10:41:28 PM PDT by Ernest_at_the_Beach

Reuters

 

 
Internet Attack Exploits Microsoft Software Flaws

Fri Jun 25, 2004 08:25 PM ET

By Duncan Martell

SAN FRANCISCO (Reuters) - A potentially dangerous attack on personal computers by a virus designed to steal financial data and passwords from Web users rippled across the Internet on Friday, computer security experts said.

The attack, which surfaced earlier this week and is known as the "Scob" outbreak, exploits a vulnerability in servers using Microsoft Corp.'s IIS software and has been called more dangerous than the recent "Sasser" and "Blaster" infections.

The infected servers in turn exploit another vulnerability in Microsoft's Internet Explorer browser to install a Trojan Horse virus on the PCs of Web surfers who visit the infected Web sites, said Alfred Huger, senior director of engineering at Internet security company Symantec Corp.

"All of this takes place while it looks like you're viewing the same Web page," Huger said. "You don't even know that parts of your browser have been redirected to another Web site."

The U.S. Computer Emergency Readiness team warned on its Web site that "any Web site, even those that may be trusted by the user, may be affected by this activity and thus contain potentially malicious code."

The Trojan Horse places a keystroke logger on users' PCs and is designed to capture credit card numbers and passwords and send them back to a server in Russia, said Michael Murray, director of vulnerability and exposure at computer security firm nCircle Network Security.

By late Friday, however, the threat to users' personal data has been diminished, at least for now.

"The server appears to have been shut down in the last eight hours," Murray said. "We don't know if it was shut down by authorities or whether it was accidental."

The attack is more alarming than most because there are no patches available yet from Microsoft to fix the vulnerability in Internet Explorer that lets the hackers take control of computers, security researchers said.

On its Web site, Microsoft said users could search for the files "Kk32.dll" or "Surf.dat" to see if their PCs were infected. The company also suggested users set their browser security level to "high."

Experts also urged computer users to update their anti-virus software protection software

Most anti-virus software has been updated so that it can prevent the Trojan Horse from being installed, but because there is no patch yet available, there's no way to prevent future attacks to install the virus, Huger said.

"The truly alarming part is there is no patch available for that vulnerability," Huger said.



TOPICS: Extended News; Front Page News; News/Current Events; Technical
KEYWORDS: getamac; ieproblems; internetattacks; internetexploiter; lookoutexpress; lowqualitycrap; securityflaw; techindex; trojan; viruses; whoops; windows
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-80 ... 161-175 next last
To: Ernest_at_the_Beach
What browser are you running?Firefox on both the desktop (98 machine) and the laptop (XP machine).
21 posted on 06/26/2004 12:06:14 AM PDT by BigSkyFreeper (John Kerry: An old creep, with gray hair, trying to look like he's 30 years old.)
[ Post Reply | Private Reply | To 19 | View Replies]

To: BigSkyFreeper
Same complaints about Norton, plus it was always taking over the whole machine it seemed like.

CNET Article on the virus here:

Researchers warn of infectious Web sites

22 posted on 06/26/2004 12:15:55 AM PDT by Ernest_at_the_Beach (The terrorists and their supporters declared war on the United States - and war is what they got!!!!)
[ Post Reply | Private Reply | To 20 | View Replies]

To: Ernest_at_the_Beach
Same complaints about Norton, plus it was always taking over the whole machine it seemed like.

Exactly! When you uninstall it, it wouldn't uninstall everything properly and would give you a list of "cannot find *.exe file" error screens at bootup.

I laughed one time when I was fixing these errors on a computer network at the local insurance agent, and installed Mcafee and that installation package came up with an error box that said "we've detected stray files from Norton Anti-Virus exists on your computer, would you like us to get rid of these files?" and I clicked yes, and McAfee cleaned up Norton and successfully installed itself.

23 posted on 06/26/2004 12:23:29 AM PDT by BigSkyFreeper (John Kerry: An old creep, with gray hair, trying to look like he's 30 years old.)
[ Post Reply | Private Reply | To 22 | View Replies]

To: Ernest_at_the_Beach

Everyone should keep in mind that these vulnerabilities
are designed in, so that Gates and his Hollywood buddies
can spy on you. Over time, these situations can
be exploited by others.


24 posted on 06/26/2004 12:41:17 AM PDT by greasepaint
[ Post Reply | Private Reply | To 1 | View Replies]

To: BigSkyFreeper

ROFL!

Symantec just picked up Powerquest so now I may need to look for a replacement for Partition Magic.

Although disks have really gotten inexpensive so not such a big deal now.


25 posted on 06/26/2004 12:44:27 AM PDT by Ernest_at_the_Beach (The terrorists and their supporters declared war on the United States - and war is what they got!!!!)
[ Post Reply | Private Reply | To 23 | View Replies]

To: Ernest_at_the_Beach
Although disks have really gotten inexpensive so not such a big deal now.

True. I'm going to get a second hard drive and the one I have now will be used as a backup drive.

26 posted on 06/26/2004 12:46:39 AM PDT by BigSkyFreeper (John Kerry: An old creep, with gray hair, trying to look like he's 30 years old.)
[ Post Reply | Private Reply | To 25 | View Replies]

To: greasepaint

Well this little virus thingie may just get me to move over to Linux, since the browser is the big issue and Firefox seems to be working well for most of what I do, and it will run on Linux.


27 posted on 06/26/2004 12:47:21 AM PDT by Ernest_at_the_Beach (The terrorists and their supporters declared war on the United States - and war is what they got!!!!)
[ Post Reply | Private Reply | To 24 | View Replies]

To: BigSkyFreeper

I have a bunch of storage.


28 posted on 06/26/2004 12:49:03 AM PDT by Ernest_at_the_Beach (The terrorists and their supporters declared war on the United States - and war is what they got!!!!)
[ Post Reply | Private Reply | To 26 | View Replies]

To: Ernest_at_the_Beach
"Okily, dokily, neighbor." (Ned Flanders voice off)

Thanks for pointing me in the right direction!
29 posted on 06/26/2004 1:24:19 AM PDT by hummingbird ("If it wasn't for the insomnia, I could have gotten some sleep!")
[ Post Reply | Private Reply | To 18 | View Replies]

To: Ernest_at_the_Beach; TexasTransplant; ShadowAce; martin_fierro; Pit1; delapaz; dyed_in_the_wool; ...
On Friday SEVERAL security experts were recommending people abandon MS Internet Explorer, and most recommended Mozilla/Firefox.
Good advice from the experts...


And even if you are using Compuserve, AOL, or Earthlink etc, from some CD that was sent to you, it MIGHT actually be Internet Explorer with a different 'face' added to it.

I recommend users do NOT install OPERA as an alternative to IE at this time, since that appears to be a SPINOFF from IE. Note a sampling of the HTTP headers from Opera users all say they are compatible with various releases of MSIE (Internet Explorer), so they therefore are ALSO most likely corruptible by these Russian worms/trojans. Most people using Compuserve, AOL, or Earthlink etc, or ANYTHING that came from your ISP can still LOG-IN with THAT software, THEN MINIMIZE it, and then use Firefox.
30 posted on 06/26/2004 9:49:03 AM PDT by Future Useless Eater (FreedomLoving_Engineer)
[ Post Reply | Private Reply | To 1 | View Replies]

To: TexasTransplant; martin_fierro
from another thread... Well its hard to beat Firefox for features or security. I believe Microsoft refused to cooperate with the standards committee that developed javascript, so MS came out instead, with its own lousy javascript version that had lots of extra hooks and bugs and vulnerabilaties.

For all of us home users who are stuck with the Redmond operating system, I'd recommend trying to get ALL other software from SOMEWHERE ELSE for safety, NOT from microsoft.

I like the site nonags.com for very good open sourced software. These people for the most part ONLY recommend, test, and rank free software that does NOT NAG you for money to upgrade to a 'better version'.

If you need anything more commercial than that, I'd say the non-MS versions of software will be as good or better, and less virus-prone, than MS versions.

martin_fierro also had a good list of software for PC protection (except for the part about Opera).

Whichever email system you use.. BE SURE to turn OFF the reading of mail in HTML MODE. Read all messages in 'TEXT ONLY' mode or else you can be infecting your system JUST by reading a message (even without opening attachments).

Another reason to not allow HTML mode in your email reader, is that built-in images in the message (sometimes they're even invisible) will confirm to spammers that your email address is valid.

31 posted on 06/26/2004 9:52:09 AM PDT by Future Useless Eater (FreedomLoving_Engineer)
[ Post Reply | Private Reply | To 30 | View Replies]

To: Ernest_at_the_Beach

BTTT for later.


32 posted on 06/26/2004 9:55:43 AM PDT by Brad’s Gramma (God Bless America)
[ Post Reply | Private Reply | To 25 | View Replies]

To: FL_engineer

Thanks, but I use Apple products only. Safari is my browser. Microsoft is a dirty word in this house.


33 posted on 06/26/2004 9:58:18 AM PDT by mass55th
[ Post Reply | Private Reply | To 30 | View Replies]

To: beckett

Thanks, beckett...I am a computer dunce and don't know how to look for this invasion, but I do have Norton on auto update...Norton has never found a virus when it scans my files.


34 posted on 06/26/2004 10:01:03 AM PDT by MEG33 (John Kerry's been AWOL for two decades on issues of National Security)
[ Post Reply | Private Reply | To 4 | View Replies]

To: FL_engineer

Thank you


35 posted on 06/26/2004 10:05:29 AM PDT by firewalk
[ Post Reply | Private Reply | To 30 | View Replies]

To: FL_engineer

Well I don't what was causing problems on my computer this week

But I did want to beat the heck out of it with a baseball bat


36 posted on 06/26/2004 10:11:24 AM PDT by Mo1 (50 States baby .. I want all 50 States come November !)
[ Post Reply | Private Reply | To 30 | View Replies]

To: Mitchell

Ping


37 posted on 06/26/2004 10:11:57 AM PDT by Allan
[ Post Reply | Private Reply | To 1 | View Replies]

To: MEG33; Brad's Gramma

The move to Firefox is a very easy move, suggest you both look at it.

Shadowace had some good tips on the thread he started , now in the blogger chat area.

Link to it above here somewhere.

I am doing this right now under Firefox.

There are a few things to learn, but not many , use the right click on the mouse a bit more.

Firefox doesn't have the mail capability so is much smaller than IE.

If you are a big user of mail, then Mozilla has that.


38 posted on 06/26/2004 10:13:55 AM PDT by Ernest_at_the_Beach (The terrorists and their supporters declared war on the United States - and war is what they got!!!!)
[ Post Reply | Private Reply | To 34 | View Replies]

To: MEG33; Brad's Gramma

Link at post #2.


39 posted on 06/26/2004 10:16:07 AM PDT by Ernest_at_the_Beach (The terrorists and their supporters declared war on the United States - and war is what they got!!!!)
[ Post Reply | Private Reply | To 38 | View Replies]

To: FL_engineer

Thanks. Is there any way to tell if my computer has the virus? I ran a virus scan yesterday and it appeared that there was no problem(yet.)


40 posted on 06/26/2004 10:17:28 AM PDT by COUNTrecount
[ Post Reply | Private Reply | To 30 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-80 ... 161-175 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson