About InfoWorld : Advertise : Subscribe : Contact Us : Awards : Events : Store
InfoWorld HomeNewsTest CenterOpinionsProduct GuideTechIndex
 
 

NEWS

 
 
New attack hitting Web users through major sites
Internet users may unwittingly be downloading malicious code
 

 
By James Niccolai, IDG News Service June 24, 2004 

 Internet users visiting some of the most popular sites on the Web may unwittingly be downloading malicious code that compromises their computers and sets up a relay network for a future onslaught of spam, a security services company warned Thursday.

   ADVERTISEMENT
  

Free IT resource

Hear how top CIOs turn change into a competitive advantage.

Sponsored by HP

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

IDG ENTERPRISE NETWORK
More App Development News...  (ComputerWorld)
Netscape laid wide open by security flaw  (TechWorld)
Apple in denial over security  (TechWorld)

GOVERNMENT IT & POLICY
Security Concerns Boosted VeriSign's Dot-Net Bid
Congress Moving to Tackle Spyware Problem
Nortel to Buy PEC Solutions For $448 Million

NetSec Inc., which provides managed security services for large businesses and government agencies, began detecting suspicious traffic on several of its customers' networks on Thursday morning, said Chief Technology Officer Brent Houlahan.

Examining firewall logs and other data points on those networks, NetSec found that when users visit certain popular Web sites -- including an online auction, a search engine and a comparison shopping site -- they unwittingly download a piece of malicious JavaScript code attached to an image or graphics file on the site.

Without the user's knowledge, the code connects their PC to one of two IP (Internet Protocol) addresses in North America and Russia. From those systems they unknowingly download a piece of malicious code that appears to install a keystroke reader and probably some other malicious code on the computer, Houlahan said.

The code may be gathering the addresses of Web sites visited by affected users and the passwords used to access them. In addition, the IP address in Russia is a known source of spam, and the code may be creating a network of infected machines that could be used to relay spam across the Internet at some later date, he said.

He stressed that NetSec is still examining the code and has yet to determine the exact payload or the intent of the attack. The SANS Institute is also studying the outbreak, he said.

NetSec declined to name the affected Web sites for liability reasons but said they are "big, big sites." It is probably the Web hosting facilities that cache content for those sites that are infected, rather than the "origin servers" at the Internet service providers themselves, Houlahan said.

"The tricks used in this particular attack method are nothing new. What's significant about this is the fact that it impacts major Web hosting facilities," said Dan Frasnelli, who manages NetSec's technical assistance center.

The attack affects only users running Microsoft Corp.'s Windows operating system and Internet Explorer browser, he said. It was unclear Thursday how the attack originated, but it may exploit a known vulnerability in Microsoft's IIS (Internet Information Services) Web Server software at the Web hosting facilities, Frasnelli said.

It was also unclear Thursday afternoon how many systems had been compromised and how widespread was the problem. NetSec said it had protected its own customers by writing custom intrusion detection signatures and blocking its customers' PCs from visiting the IP addresses involved in the attack.

"There's a potential for widespread impact because currently the (antivirus) vendors don't have a signature for it," Frasnelli said.






Virtualization: A Step by Step Approach to Success
Your virtual machines can be up and running in a matter of minutes. HP and Citrix have integrated XenServer with HP ProLiant servers and management tools, powered by hardware-assisted Intel Virtualization Technology to enable high- performance, cost-savings solutions for server consolidation and disaster recovery. Sponsor: HP

»  Click here to view this Webcast
  Planning For A Disaster
This new, comprehensive Solutions Guide is your one stop source for Disaster Recovery. In it you'll learn how to reduce the likelihood of a disaster and to create a rock solid business continuity plan should you face a disaster situation. Sponsored by Equallogic

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 
 HOME  NEWS  TEST CENTER  OPINIONS  PRODUCT GUIDE  TECHINDEX   About : Advertise : Subscribe : Contact Us : Awards : Events 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy

All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses, phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

Computerworld :: Network World :: CIO :: PC World :: Darwin :: CMO :: CSO
IT Careers :: JavaWorld :: Macworld :: Mac Central :: Playlist :: GamePro :: GameStar :: Gamerhelp
ITWorld Canada :: Computerwoche :: Techworld UK :: tecChannel :: IDG.se :: IDG.no