-->
Shadows In The Dark 24hr Anniversary Broadcast


Page 1 of 14 12345>Last »
Topic Options
Rate This Topic
#208856 - 06/25/04 09:54 PM Warning Issued To all Internet Explorer users !
phobos Offline
Member


Registered: 07/06/01
Posts: 431
Loc: Watford, England
Web browser flaw prompts warning

quote:
Users are being told to avoid using Internet Explorer until Microsoft patches a serious security hole in it.
The loophole is being exploited to open a backdoor on a PC that could let criminals take control of a machine.

The threat of infection is so high because the code created to exploit the loophole has somehow been placed on many popular websites.

Experts say the list of compromised sites involves banks, auction and price comparison firms and is growing fast.

Serious problem

The net watchdog, the US Computer Emergency Reponse Center (Cert), and the net security monitor, the Internet Storm Center, have both issued warnings about the combined threat of compromised websites and browser loophole.

Cert said: "Users should be aware that any website, even those that may be trusted by the user, may be affected by this activity and thus contain potentially malicious code."

In its round-up of the threat the Internet Storm Center bluntly stated that users should if possible "use a browser other then MS Internet Explorer until the current vulnerabilities in MSIE are patched."

CHECKING FOR INFECTION
Click the Start button and then click on Search
Make sure you choose the option to look through all files and folders
Search for files called Kk32.dll and Surf.dat
If infected use up to date anti-virus software to remove the malicious code

Security programme manager at Microsoft's security response centre, Stephen Toulouse, told BBC News Online: "When threats happen, we mobilise instantly.

"We post warnings, which we did last night, and tell customers what the issue is, whether they are affected, what steps they can take to prevent it."

He said Microsoft was aware that operating systems had vulnerabilities, but added that it was an industry-wide problem.

Mr Toulouse advised users to set their internet security zone to high and to run good anti-virus software.

It is unclear how the malicious code that exploits the weakness in Microsoft's Internet Explorer has been inserted on popular websites.

What is known is that any Windows 2000 Server that does not have the MS04-011 security update installed and is running Internet Information Server could be at risk.

The virulent Sasser worm exploited loopholes closed by this update so many servers are likely to be patched against the problem.

Infected servers are adding a malicious chunk of Javascript to all the web, gif and jpg files served up to anyone browsing the sites they host.

When loading on a browsing PC, this chunk of code might trigger a Windows error message.

Once downloaded the code redirects a browser to a Russian website which tries to install a program that opens a backdoor into the PC.

Some net service firms have started blocking access to this Russian site.

Check for infection

Anti-virus firms are now working on putting detectors for the chunk of code in to their scanning software.


A Russian website is spreading the malicious code
Security firm Symantec said the malicious code was not widespread and did little damage.

The reason that the server/browser combination has been created remains a mystery.

Some speculate that it is the work of spammers looking to create yet another network of compliant PCs that can be used as proxies to spread junk mail.

Microsoft has issued advice to consumers and web administrators about dealing with the problem.

So far the server/browser combination has not been given a single name. In its warning about the problem Microsoft calls it download.ject but others, such as F-Secure, are calling it Scob.

_________________________


If you are a farmer outstanding in your field, don't lie down on the job or you will get a pat on the back!

Top
#208857 - 06/25/04 10:06 PM Re: Warning Issued To all Internet Explorer users !
phobos Offline
Member


Registered: 07/06/01
Posts: 431
Loc: Watford, England
This is a serious threat and I thought you should all be made aware of it.

It seems there is a flaw in internet explorer that can be exploited simply going to a website that is inadvertantly hosting some javascript.

Personally I would suggest that for now either use netscape, or turn off javascript from within your browser and ensure your computer has the latest bugfixes from Microsoft.

OK that's the general warning over with but there is an anomalies issue here too.

Microsoft are already in a dominant position in the marketplace and things like this make it ever more likely that people will set up their machine to take automatic updates.

There are a couple of problems here - one is that it we don't always know that the update will be good for us, and the other is it opens up the possibility that the update process itself could be targeted in a computer hijack.

Imagine the damage that could be caused if the microsoft update server was infected.

Something else I find odd with this story is the mention of trusted websites unknowingly carrying the javascript. I get the impression that someone wrote a trojan script that has been used by webdesigners.

All in all there is something very fishy about this story.
_________________________


If you are a farmer outstanding in your field, don't lie down on the job or you will get a pat on the back!

Top
#208858 - 06/25/04 10:28 PM Re: Warning Issued To all Internet Explorer users !
Batty Offline
Member


Registered: 06/22/04
Posts: 75
Loc: Australia
its definitely a legit story. I opened a webpage recently, got redireceted, then my antivirus proggie went nuts, virus warning window opened all over the place and my computer tried to dialout. No Joke.
Top
#208859 - 06/25/04 10:29 PM Re: Warning Issued To all Internet Explorer users !
Anonymous
Unregistered



This is precisely why I use Mozilla Firefox. It's not perfect, especially on sites (like this one!) designed for IE only. However, it's about 1000% safer.
Top
#208860 - 06/25/04 10:46 PM Re: Warning Issued To all Internet Explorer users !
itdincor Offline
Member


Registered: 10/11/01
Posts: 1742
Loc: Sand Point, Alaska
One more reason to be glad I use Opera 7 as a browser, and Eudora as an EMail client. I recommend them both to everyone. Microsoft truly seems a bit more shakey with each passing week, doesn't it?. John Dvorak as always has a good news/bad news opinion on MS vs open source, where he feels that eventually all this will be to our benefit. Eventually. We'll see.

http://www.pcmag.com/article2/0,1759,1615422,00.asp
_________________________
http://anysoldier.com
I am what I am and that's all what I am - Popeye the Sailor Man
From simplicity make not complexity without necessity - John of Ockham
Proven liquid water and fossilized life on Mars are SERIOUS BUSINESS

Top
#208861 - 06/26/04 08:21 AM Re: Warning Issued To all Internet Explorer users !
Tripp Offline
Member


Registered: 05/11/04
Posts: 670
Loc: Valley Forge, PA
There is also a pernicious hijack going about that makes use of MS's Java VM (virtual machine) (not javascript); this one can typically reset your IE home page and search pages and varieties locking these and making it impossible to reset these IE pages back, even with programs such as "Hijack This", "CWshredder" and "spybot". Some versions have trojans that send your vital info elsewhere.

These varieties of hijacks typically reinstall themselves on reboot. One version infects the software for the Google search toolbar and can be recognized by setting your start page to "about:blank" and a search page comes up with no title and only "Search for..." being an identifying characteristic. Many sites are infected with this hijack through the popup advertising such as is seen here on this anomalies page (they love the popup Advert that polls you with questions) often with the advertiser itself being unaware of the compromise.

One fix already available is to remove MS's Java VM and replace it with Sun's VM. There are procudures for this available and various sites on the web. In the meantime turning off the Java VM is recommmended.

Top
#208862 - 06/26/04 08:39 AM Re: Warning Issued To all Internet Explorer users !
CaryP Offline
Member


Registered: 01/04/04
Posts: 743
Loc: Louisiana
Just had our system consultant out at the office yesterday. We put mozilla browser software on every machine, and I put it on at the house. No more Microsoft IE. It's got this huge target on it that screams, "YOU WANT A PIECE OF ME!!!???" And damned if hackers don't keep getting a big piece of Microsoft. The problem, per our system consultant, is that Microsoft is so predominant in the use of IE that it has become a hackers dream to attack. Especially in light of Mr. Softy's long term approach of patching everything rather than just doing things correctly. I'm no computer whiz, but if I was using Microsoft IE, I'd been going over to the mozilla.org web site for a free down load of at least the browser software. They also have email and lots of other stuff - all free.

Cary
_________________________



Top
#208863 - 06/26/04 10:14 AM Re: Warning Issued To all Internet Explorer users !
LRae Offline
Member


Registered: 11/09/01
Posts: 1286
Loc: Kosmik Kindergarten
Although most of the posters herein are sincere and concerned about your safety, just remember: consider the source.

For those of you still [tounge-in-cheek]brave[/tounge-in-cheek] enough to use any of the Microsoft products, please go to the source for information regarding your product(s):

http://www.microsoft.com

Make it a routine to check as frequently as possible. At minimum, check for update on a weekly basis.

quote:


What You Should Know About Download.Ject

What You Should Know About Download.Ject
Published: June 24, 2004 | Updated June 25, 2004 8:35 P.M. Pacific Time

Get this information in additional languages

Microsoft teams are investigating a report of a security issue known as Download.Ject affecting customers using Microsoft Internet Information Services 5.0 (IIS) and Microsoft Internet Explorer, components of Windows. (Download.Ject is also known as: JS.Scob.Trojan, Scob, and JS.Toofeer.)

Important Customers who have deployed Windows XP Service Pack 2 RC2 are not at risk.

Reports indicate that Web servers running Windows 2000 Server and IIS that have not applied update 835732, which was addressed by Microsoft Security Bulletin MS04-011, are possibly being compromised and being used to attempt to infect users of Internet Explorer with malicious code.

How to Help Protect Your Systems

System administrators. System administrators should follow the steps outlined in Knowledge Base Article 871277 to apply update 835732 and take any recovery steps that may be necessary.

Enterprise customers. Enterprise customers can minimize risk by increasing the security of the Local Machine Zone in Internet Explorer.

Home users. Use the following steps to update your computer, remove any infection, and increase your browsing and e-mail safety settings.


Actions for Home Users


1.
Install Critical Updates

Visit the Windows Update Web site to install all critical updates.

2.
Check for Infection

To determine if the malicious code is on your computer, search for the following files:

Kk32.dll
Surf.dat

Steps for Windows XP users:

On the taskbar at the bottom of your screen, click Start, and then click Search.
Under What do you want to search for? click All files and folders.
Under All or part of the file name:
type: Kk32.dll
and then click the Search button.
Under All or part of the file name:
type: Surf.dat
and then click the Search button.

If either of these files is present, your computer may be infected. You can find tools to clean your computer and obtain up-to-date antivirus protection from the following software vendors participating in the Microsoft Virus Information Alliance:

Symantec
F-Secure
Computer Associates


3.
Increase Your Browsing and E-Mail Safety

Follow the steps outlined on the page to Increase Your Browsing and E-Mail Safety.






Learn How to Protect Your PC

To help protect your computer against a wide variety of security threats, see Protect Your PC.


Later,

LRae
_________________________
"Seeing consists of the grasping of structural features rather than the indiscriminate recording of detail"
-Rudolf Arnheim

"To go and learn is reason enough."

Top
#208864 - 06/26/04 02:58 PM Re: Warning Issued To all Internet Explorer users !
TheObserver Offline
Member


Registered: 07/05/01
Posts: 2060
Loc: Hawaii
quote:
Originally posted by itdincor:
One more reason to be glad I use Opera 7 as a browser, and Eudora as an EMail client. I recommend them both to everyone. Microsoft truly seems a bit more shakey with each passing week, doesn't it?. John Dvorak as always has a good news/bad news opinion on MS vs open source, where he feels that eventually all this will be to our benefit. Eventually. We'll see.

http://www.pcmag.com/article2/0,1759,1615422,00.asp

I agree and use both Opera and Eudora and really can't see how anyone would want to use anything else to web browse and send/receive email.

Granted the world is pretty much written for IE (for example THIS website in order to preview your posts) as it is, I still use it but only for those web pages that aren't written to be compatible with anything else.

Just keep in mind that the features that make Microsoft internet products so "web-friendly" are the same things that make it very vulnerable to hackers.
_________________________

"The new can only be found in the unknown..."-Anon
"Fingunt simul creduntque."-Tacitus

Top
#208865 - 06/26/04 09:36 PM Re: Warning Issued To all Internet Explorer users !
Anonymous
Unregistered



This site does look fairly crappy with Mozilla Firefox, because this site isn't designed with standards in mind. It's designed to look pretty with IE, all other browsers be damned.

Speaking of Mozilla--I was just over at their forums site and saw that they're now getting so much traffic that their servers can't handle the load. If you are a Mozilla user, they are accepting donations if you're feeling benevolent.

http://forums.mozillazine.org

Top
Page 1 of 14 12345>Last »


Moderator:  Phil Fiord 
Hop to:
Search
Who's Online
0 registered and 5 anonymous users online.
January
Su M Tu W Th F Sa
1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Shout Box

Forum Stats
3859 Members
61 Forums
15760 Topics
246552 Posts

Max Online: 327 @ 08/09/07 03:54 PM

Generated in 0.126 seconds in which 0.019 seconds were spent on a total of 14 queries. Zlib compression enabled.