Another IE flaw being exploited by online criminals

An undocumented flaw in Microsoft's Internet Explorer is being exploited by unscrupulous hackers to infect computers with malicious programs.
Posted : Wed, 20 Sep 2006 11:32:00 GMT
By : Philip Green
Category : Internet
News Alerts by Email ( click here )
Internet News | Home
NEW YORK: An undocumented flaw in Microsoft's Internet Explorer is being exploited by unscrupulous hackers to infect computers with malicious programs.

According to security experts, a number of pornographic websites, primarily located in Russia, are known to be using this vulnerability and launching attacks on computers using all the versions of IE 6, which has an unpatched error in the way software processes the Vector Markup Language code, basically used for image display.

The flaw and its exploitation by the online criminals were discovered by security experts at Sunbelt Software Inc. last week while carrying out online surveillance of known hacking gangs. Eric Sites, a researcher at the company, said the attacks seem to originate at the moment from hardcore porn sites. But it is a matter of time for other criminals to join the fray.

Sites says users of IE, who visit the sites that launch the attacks, can expect their computers to be infected with the BigBlue keystroke logger, which is capable of capturing data from the compromised computers including screenshots and keystrokes and web cam and microphone data. It can also record instant messaging chat sessions, e-mail information and the websites visited by the user. The malicious program can install the Spybot worm and VXGame Trojan, as well as adware titles such as Virtumondo, SafeSurfing, Avenue Media, WebHancer, Internet Optimizer, SurfSidekick, DollarRevenue and the bogus anti-spyware program SpySheriff.

Sites admits the true potential of the attacks has still not be assessed.

Sunbelt had notified Microsoft about the vulnerability.

An earlier flaw in IE had been exploited by crime groups to attack people who visited a small number of fringe or hardcore porn sites. Several computers were thus infected with spyware.

Security company VeriSign too warned of the flaw. Ken Dunham, director of the rapid response team at VeriSign's iDefense, said this new zero-day attack is trivial to reproduce and has great potential for widespread web-based attacks in the near future.

Microsoft said it is planning to fix the flaw as part of its monthly patching cycle on 10 October.

Sites said as an immediate remedy users can turn off JavaScript.

Copyright, respective author or news agency

Share/Save/Bookmark

Article : Another IE flaw being exploited by online criminals
Print this article
Email this article

Stay Updated
News gadget on your Google homepage
Subscribe to a news feed in Google Reader


Related News

Have your Say
Name
Email
Subject
Your Comment

Enter Verification code
 
  

 

 
Your Comments

Firefox smilling right now
By: Me So HAppy , Wed, 20 Sep 2006 16:37:33 GMT

I actually like microsoft explorer. But I was forced to use firefox and I am complete convert. These type of issues are all too often now that I don't even have faith in IE 7.



More Internet News click here
Follow The Earth Times
Subscribe to RSS Follow Earth Times on TwitterNews by email
Share/Save/Bookmark

 
 



 
Subscribe to free Earthtimes
News Alerts by Email Click here
For RSS Feeds Click here
or Create your own RSS

Add to Google Toolbar
Breaking News
Press Releases

 


The Earth Times
News Category

© 2009 www.earthtimes.org, The Earth Times, All Rights Reserved | Privacy Policy
Earth Times accept no responsibility or liability either directly or indirectly for views or opinions expressed in articles or comments.