Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Internet Attack Exploits Microsoft Software Flaws ( Internet Explorer vulnerable )
Reuters ^ | Fri Jun 25, 2004 08:25 PM ET | Duncan Martell

Posted on 06/25/2004 10:41:28 PM PDT by Ernest_at_the_Beach

Reuters

 

 
Internet Attack Exploits Microsoft Software Flaws

Fri Jun 25, 2004 08:25 PM ET

By Duncan Martell

SAN FRANCISCO (Reuters) - A potentially dangerous attack on personal computers by a virus designed to steal financial data and passwords from Web users rippled across the Internet on Friday, computer security experts said.

The attack, which surfaced earlier this week and is known as the "Scob" outbreak, exploits a vulnerability in servers using Microsoft Corp.'s IIS software and has been called more dangerous than the recent "Sasser" and "Blaster" infections.

The infected servers in turn exploit another vulnerability in Microsoft's Internet Explorer browser to install a Trojan Horse virus on the PCs of Web surfers who visit the infected Web sites, said Alfred Huger, senior director of engineering at Internet security company Symantec Corp.

"All of this takes place while it looks like you're viewing the same Web page," Huger said. "You don't even know that parts of your browser have been redirected to another Web site."

The U.S. Computer Emergency Readiness team warned on its Web site that "any Web site, even those that may be trusted by the user, may be affected by this activity and thus contain potentially malicious code."

The Trojan Horse places a keystroke logger on users' PCs and is designed to capture credit card numbers and passwords and send them back to a server in Russia, said Michael Murray, director of vulnerability and exposure at computer security firm nCircle Network Security.

By late Friday, however, the threat to users' personal data has been diminished, at least for now.

"The server appears to have been shut down in the last eight hours," Murray said. "We don't know if it was shut down by authorities or whether it was accidental."

The attack is more alarming than most because there are no patches available yet from Microsoft to fix the vulnerability in Internet Explorer that lets the hackers take control of computers, security researchers said.

On its Web site, Microsoft said users could search for the files "Kk32.dll" or "Surf.dat" to see if their PCs were infected. The company also suggested users set their browser security level to "high."

Experts also urged computer users to update their anti-virus software protection software

Most anti-virus software has been updated so that it can prevent the Trojan Horse from being installed, but because there is no patch yet available, there's no way to prevent future attacks to install the virus, Huger said.

"The truly alarming part is there is no patch available for that vulnerability," Huger said.



TOPICS: Extended News; Front Page News; News/Current Events; Technical
KEYWORDS: getamac; ieproblems; internetattacks; internetexploiter; lookoutexpress; lowqualitycrap; securityflaw; techindex; trojan; viruses; whoops; windows
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-80 ... 161-175 next last
To: COUNTrecount
You may not have a virus. You may have spyware installed on your box. Try running this. It's highly rated:

Spybot

Here's another great tool:

Ad-Aware
41 posted on 06/26/2004 10:22:39 AM PDT by Bush2000
[ Post Reply | Private Reply | To 40 | View Replies]

To: Ernest_at_the_Beach
Yeahhhhhh, quality product /SARCASM

169 Critical Firefox bugs

Where Do You Want To Crash Today(tm)?
42 posted on 06/26/2004 10:23:44 AM PDT by Bush2000
[ Post Reply | Private Reply | To 38 | View Replies]

To: Ernest_at_the_Beach
Get Thunderbird     Click the button to learn about email that's much safer than Outlook. Firefox's companion, Thunderbird.
43 posted on 06/26/2004 10:26:08 AM PDT by Eagle9
[ Post Reply | Private Reply | To 38 | View Replies]

To: FL_engineer
I recommend users do NOT install OPERA as an alternative to IE at this time, since that appears to be a SPINOFF from IE. Note a sampling of the HTTP headers from Opera users all say they are compatible with various releases of MSIE (Internet Explorer), so they therefore are ALSO most likely corruptible by these Russian worms/trojans.

What do the headers have to do with anything? I see no reason to believe they mean that MS software exists behind them.

44 posted on 06/26/2004 10:35:18 AM PDT by supercat (Why is it that the more "gun safety" laws are passed, the less safe my guns seem?)
[ Post Reply | Private Reply | To 30 | View Replies]

To: FL_engineer

Thanks for the information!


45 posted on 06/26/2004 10:46:00 AM PDT by Alamo-Girl
[ Post Reply | Private Reply | To 30 | View Replies]

To: MEG33
Norton will flag you if it detects "download.ject." Otherwise you're OK.

After it was detected on my machine I checked at Symantec and found the names of the two registry keys that "download.ject" writes and searched the registry for them. They were not there. I also searched my hard drives for Kk32.dll and Surf.dat. Again, nada. So it seems Norton successfully slams the door on this thing.

46 posted on 06/26/2004 10:49:49 AM PDT by beckett
[ Post Reply | Private Reply | To 34 | View Replies]

To: COUNTrecount; Bush2000; martin_fierro; Mo1; MEG33; Brad's Gramma; Ernest_at_the_Beach

I cannot verify who owns the website that Bush2000
recommended for getting Spybot (security.kolla.de)

One WHOIS service shows NO REGISTRANT.
Another WHOIS service shows "INVALID"

Spybot Search and Destroy is a VERY good program and I
highly recommend it for cleaning up a system...

The official site, registered by the author of SPYBOT is
http://www.safer-networking.org/index.php?page=spybotsd

I don't know that Spybot will catch this bug yet.
So far, I've only heard that the Symantec tools can find it.
I also see post #46 has some more info



To: Bush2000, you keep trying to bash FIREFOX
on all these threads. You seem to work for microsoft.
Why don't you tell us what you recommend, instead of
just throwing out bombshells.

However, thanks for pointing out that the total list of
known bugs in FIREFOX is MINOR, and does NOT include any
that mention WORMS, TROJAN, or any VIRUS.

Its too bad your company tries to keep all its dirty laundry
secret for as long as possible.



To: martin_fierro

I can't verify who owns that australian site you are
sending people to to get Spybot S&D either.

Something that important should only be obtained from
a known reputable source, IMO

I used DNSSTUFF.COM to look these things up.
FLE


47 posted on 06/26/2004 11:21:36 AM PDT by Future Useless Eater (FreedomLoving_Engineer)
[ Post Reply | Private Reply | To 41 | View Replies]

To: supercat

>>I see no reason to believe they mean that MS software exists behind them.

You 'might' be right. I might have been premature, because
I do not KNOW that Opera is a licensed repackaging of microsoft's IE.

However, their headers indicate they are COMPATIBLE with
IE. Therefore if the security bug is systemic to one of
the javascript commands that is unique to MS's definition
of javascript, then it COULD have the same problem.

I had not heard ANY security experts recommending opera
yesterday, but did hear of some recommending Mozilla/Firefox.
And some specifically said the bug does NOT affect
the later pair.


48 posted on 06/26/2004 11:28:51 AM PDT by Future Useless Eater (FreedomLoving_Engineer)
[ Post Reply | Private Reply | To 44 | View Replies]

To: Ernest_at_the_Beach
I've been using the Mozilla browser for over a year now, which came with e-mail, and html editor. I love it. Yes, it had some bugs dealing with graphic files, but it's otherwise been stable and secure.

Before I switched from IE to mozilla, my weekly ad-aware and spybot scans would turn up an average of 50 spyware cookies.

Since the switch, the weekly scans might turn up 1 or 2 spyware cookies.

Regarding a switch to linux, I've been considering switching too, but still keeping windows as a partition for local work only.

49 posted on 06/26/2004 11:32:09 AM PDT by Vigilantcitizen
[ Post Reply | Private Reply | To 1 | View Replies]

To: FL_engineer

> I recommend users do NOT install OPERA as an
> alternative to IE at this time, since that
> appears to be a SPINOFF from IE.

Unless there is evidence of an actual Opera user
being compromised during the current infection
cycle, I'd tend to dismiss the above as being
unsupported speculation.

> However, their headers indicate they are
> COMPATIBLE with IE.

I'd be more inclined to think that the headers
are spoofed so that Op users have less trouble
with bozo sites that claim to be MSIE-only, not
because they're hard-coded to some MS'ism, but
just because that's all they tested against.


50 posted on 06/26/2004 11:52:05 AM PDT by Boundless
[ Post Reply | Private Reply | To 30 | View Replies]

To: FL_engineer

Might as well go all the way to freedom and security with Linux!


51 posted on 06/26/2004 12:03:21 PM PDT by LibertyAndJusticeForAll
[ Post Reply | Private Reply | To 30 | View Replies]

To: FL_engineer

Thanks. I use Opera, personally. Rather nice and you can block pop-ups, animations, whatever ticks you off.


52 posted on 06/26/2004 12:06:25 PM PDT by phenn (http://www.terrisfight.org)
[ Post Reply | Private Reply | To 30 | View Replies]

To: Bush2000

Thank you. I ran Spybot yesterday and got rid of everything that was flagged.


53 posted on 06/26/2004 12:08:52 PM PDT by COUNTrecount
[ Post Reply | Private Reply | To 41 | View Replies]

To: Ernest_at_the_Beach
Well this little virus thingie may just get me to move over to Linux, since the browser is the big issue and Firefox seems to be working well for most of what I do, and it will run on Linux.

Good idea! Depending on what other Windows software you typically use, you can usually either find an acceptable substitute or run the actual Windows program under WINE.

I haven't used Windows in many years. The only thing I miss is MS Flight Simulator. There is a Linux/UNIX flight sim, but it's not as good.

54 posted on 06/26/2004 12:14:28 PM PDT by B Knotts
[ Post Reply | Private Reply | To 27 | View Replies]

To: FL_engineer
On Friday SEVERAL security experts were recommending people abandon MS Internet Explorer, and most recommended Mozilla/Firefox.

Yesterday, I deleted dozens of trojans/malware, and consequently, I recommended Firefox to myself. The bad programs tired me out.

"Fully patched Explorer users are attacked at will, silently,

I can testify to that. It took a few minutes to find what was spawning the bad programs and the 'parent process' always pointed to Internet Explorer. I came to the obvious conclusion as these experts did, an IE security leak.

55 posted on 06/26/2004 12:39:29 PM PDT by demlosers
[ Post Reply | Private Reply | To 30 | View Replies]

To: FL_engineer
Thanks for the link - sweating on the porch with a new laptop and have just read of the latest MicroSoft "bug".

From FireFox (with love),

Charlie

56 posted on 06/26/2004 12:41:22 PM PDT by Tunehead54 (Have a nice day or else!)
[ Post Reply | Private Reply | To 30 | View Replies]

To: Ernest_at_the_Beach

BTTT!

Everyone needs to read this!


57 posted on 06/26/2004 1:18:19 PM PDT by Salvation (†With God all things are possible.†)
[ Post Reply | Private Reply | To 1 | View Replies]

To: FL_engineer

Thanks for the ping! I'll check out these links.


58 posted on 06/26/2004 2:04:10 PM PDT by NRA2BFree (Life is not about how fast you run, or how high you climb, but how well you bounce.)
[ Post Reply | Private Reply | To 30 | View Replies]

To: FL_engineer

Firefox and Thunderbird are now installed, everything went smooth except for maintaining my website (with Homestead), which wanted me to Install Netscape Plugins, I sent off a message to tech support and will maintain the website w/ IE until I hear back.

Painless, easy

Thank you


59 posted on 06/26/2004 3:45:30 PM PDT by TexasTransplant ("You know, I think the best possible social program is a job" Ronald W. Reagan)
[ Post Reply | Private Reply | To 31 | View Replies]

To: FL_engineer
Thanks.

But I honestly don't know what to do next. My version of Norton Anti Virus isn't supported, my yearly subscription is almost up, I have a trojan in quarrantine, and I was wondering if I can install new Norton disks. I'm sure I have adware on my computer, maybe spyware (who knows?), and my search button has been hijacked by a different search engine - I had MSN - with no way to switch it back. I've been invaded, but the computer's still working. And I don't like the look of the Firefox Browser (too busy).

I know enough to know I don't know what to do! Yikes!

Time for a new CPU, I think.

60 posted on 06/26/2004 6:16:07 PM PDT by Lauren BaRecall (Just give the kid a pack of cigarettes - you know he's only gonna go out and smoke anyway!)
[ Post Reply | Private Reply | To 30 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-80 ... 161-175 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson