July 20, 2006

Ad exploits Internet Explorer vulnerability to explose millions to adware

Windows Metafile image exploit leave MySpace.com users and other Web sites in the lurch

More than one million users of MySpace.com and other Web sites may have been infected with adware spread by a banner advertisement, according to iDefense, a computer security group.

The advertisement, for a site called deckoutyourdeck.com, appeared in user profiles on MySpace, an online community with at least 70 million users, said Ken Dunham, director of the rapid response team at iDefense, which is owned by VeriSign Inc.

The ad exploits a problem in the way Microsoft Corp.'s Internet Explorer browser handles Windows Metafile (WMF) image files.

The browser vulnerability raised alarms in December after hackers distributed a specially crafted WMF image through e-mail, instant messaging links and Web sites. If the image was opened, it could allow a hacker to gain control over a victim's computer.

There are at least 600 Web sites that take advantage of the WMF vulnerability, Dunham said. Microsoft issued a patch for the problem in January, but many consumer computers may not have applied the patch, leaving them unprotected.

Unpatched machines are particularly vulnerable. Merely visiting a page with the deckoutyourdeck.com banner ad causes a download of a Trojan horse program. Those who have installed the patch see a prompt asking to download a file called "exp.wmf" when visiting a page with the advertisement, Dunham said.

Once it starts to run, the Trojan in the banner ad causes infected machines to contact multiple Web sites and download, among other unwanted programs, advertising software from PurityScan. The PurityScan software can cause unwanted pop-up windows to appear, and also tracks a user's online activity.

Adware can be very difficult to remove, even for technically savvy users.

"The problem is hackers are using a variety of exploits -- especially WMF -- to illegally and silently install this [adware] on users' computers," Dunham said.

MySpace has increasingly been targeted by hackers because of its popularity. MySpace officials contacted in London Thursday afternoon had no immediate comment. iDefense's Dunham was not sure whether the banner advertisement has been taken down yet, but said that it could have been active for weeks.

Web sites that distribute adware are paid based on the number of machines that get infected with the software, and hackers have created ways to spread the adware without user consent, increasing their payments.

iDefense estimated the number of infections caused by the deckoutyourdeck.com ad through a server in Turkey hosting the adware. The server appears to track the number of machines infected with the adware, and indicated that 1.07 million computers had downloaded the program, Dunham said.

A Whois search for deckoutyourdeck.com leads to a winding trail of registrants. Dunham said hackers frequently use false credentials when registering a domain name to cloud inquiries.

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.