How Much Harm Can One Web Site Do?
Ben Edelman has written extensively on issues including censorship and spyware. He's got a very interesting piece on his site now about who profits from spyware, and how much spyware can be installed on a Windows XP machine when the user simply visits a single Web site using Internet Explorer.
if you use another browser like Firefox?
Here's what he types into the browser:
http://xpire.info/fa/?d=get Entering this in Mozilla 1.8a4 gives me an authentication dialog. Hitting Cancel pops up a Moz file save dialog for a file containing an authentication error message.
He used xpire.info/fa?d=get which then redirects to a series of other pages on the same site, eventually landing at www.sp2fucked.biz/user28/2DimensionOfExploitsEnc.p hp which in turn prompts him with an error and a dialoge box asking if he wants to continue executing scripts, to which he clicks "yes" after which all hell breaks loose.
Why not use somthing like Ad-Watch, which comes bundled in the Plus and Professional versions of Ad-Aware? That would certainly save a lot of heartache.
I don't use it on my machine only because when windows pop up out of nowhere telling me I absolutely need to download something, I know I don't. But I wouldn't trust hundreds to thousands of employees of a company to know the same.
Web Design Tips
Your right. If you did download the video you likely would not have been able to play it. It uses a non-standard codec and every player I have, including MS Media Player for Mac, could not play it...
Who are you? The new #2 Who is #1? You are #617565. I am not a number, I am a free man! Muhahaha.
...may I point out that it is NOT worksafe? Thanks, Ben! Appreciate that.
Glad I didn't have the boss watch it with me in an attempt to convince her of the need to take better anti-spyware measures.
Silly AC, the goatse site just displays a domain registry TOS page now.
wait...
- Part 1
- Part 2
- Part 3
Part 4 is coming Real Soon Now (tm). The ISC handler's diary is required daily reading; always a lot of good stuff to be found. (And every now and then, there's a tale that'll make your blood run cold...)Carousel is a lie!
Comment removed based on user account deletion
Before you start whining about how the machine was unpatched, and going on about how we're picking on MS, realize that just maybe, Microsoft isn't the target here. If you would read the fucking article, you would see that Ben is attacking propagators of spyware; not MS.
Oh, probably the same reason I have to, all the corporate web sites that won't work with Firefox (still, yes, I have the updates). When Firefox gets plugins down we'll be able to nix IE, but till then we're stuck.
It doesn't matter what you wrap your emotions around, Reality is a brick wall specifically designed to scramble eggs
IE runs under a user with administrator privileges
No, IE runs under whatever user you are logged in as. One should definately learn to manage users. No argument there.
, but I am of the opinion that users have every right to be stupid,
Yet we all own cars... If you are too stupid to add oil to your car and you burn out your engine... It's not the manufacturers fault. There's a certain level of responsibility the users should bear as well. Users have a right to be stupid, but should pay up when they screw their computers up the same way car owners should pay if they don't maintain their vehicle or use it correctly.
. If XP needs all of these security patches just to keep going, where a mac or linux box could stand like a column of basalt for years
Again, Bullshit! There's security holes in Linux and FreeBSD. That's why we have utilities in Fedora like up2date, portupgrade, etc. So you can automate the patching of those security holes.
09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0
I spent about an hour trying to figure out all the hacks that website was doing but after all was said and done it was frightening the lengths people go to in order to hack your browser, set your home page then get ad impressions and make revenue.... embeded java code with encrypted javascript with encrypted java code which printed out encrypted HTML which when decrypted had the browser load java code that used a browse helper object to set your homepage.
2 years and no mod points. Join reddit. Because openness is good.
You do not get it. Sic is something an author inserts into a quote when the quote is incorrect in some way. Here, the author says "s.i.c" instead of "sic". This is the error. This error has nothing to do with the grammar error in the wallpaper.
Here's what's happening:
Wallpaper: Your computer is broked.
Author: The wallpaper says, "Your computer is broked." [s.i.c.]
The author should have written: "Your computer is broked [sic]"
See the difference and where the mistake is?
My other car is first.
regsvr32 /u C:\DIRECTORY\twaintec.dll
Outdated products like Windows 2000 Professional?
Microsoft's own product lifecycle chart indicates "Mainstream Support" through June 30, 2005, and "Extended Support" through June 30, 2010.
Wouldn't that be "in the world of grammer [sic]"?
The word is spelled 'grammar'. Also, check the MLA Handbook (you do know what that is, Mr. English Major?), and you will see that you are wrong about 'sic' being an acronym.
I suppose it's a good thing you changed majors. Remember that spelling and grammar are helpful in computer languages also.
just saw it... the best video in ages... i cried... i laughed... never seen anything so funny and scary... maybe because i don't use window$ and ie for net anymore :-)
btw video stream is Windows Media Video 9 Screen
and audio is Windows Media Audio 9
Howdy folks. Sorry to take so long to respond -- was in airports and planes all afternoon. Day before Thanksgiving...
Browsing to the site I showed in my video is one way to get infected. But that's not the most typical infection method. Instead, other sites can and do point to this site (and other similar sites), typically via IFRAMES. I was recently looking at a post in a web-based threaded messaging site, which used a 1x1 pixel IFRAME (basically, hidden) to reference the site shown in my video. When a user loads the infected post in the threaded messaging site, the user's PC will be infected via the exploits shown (if the user's PC is vulnerable to such exploits), and the user will receive spyware like that shown in the video.
As to video format: I apologize for the WMV format. There's a lot to be said for this format, from the reliable free creator to the wide deployment of the player software (present in all W2K and WXP systems). But clearly it's an imperfect solution, and not great for viewers on other platforms. I'm working on finding a better alternative and/or offering the same content in other formats.