Trojan Exploits Unpatched IE Flaw
onebuttonmouse writes "The Register reports on a trojan spotted in the wild that takes advantage of the so-far unpatched IE vulnerability mentioned on Slashdot earlier this week. From the article: 'The release of a Trojan that exploits an unpatched IE hole has prompted speculation that Microsoft may release an emergency out-of-cycle security patch. Delf-DH downloads other malware onto infected machines changing settings in order to monitor user activity and redirect surfers onto porn sites. The attack relies on a flaw in the way IE handles requests to the window() object.'"
The fix for this is here
Thank god I still use Mosaic. Hey, if it ain't broke...
We heard about this same sort of thing hundreds of times. The editors really need to read the articles more carefully...
You have two hands and one brain, so always code twice as much as you think!
"elf-DH downloads other malware onto infected machines changing settings in order to monitor user activity and redirect surfers onto porn sites."
So it is basically automated pr0n! From now on, you won't have to use your left hand.
and redirect surfers onto porn sites
;-)
Sounds more like a feature to me
"reality has a well-known liberal bias" - Steven Colbert
Does this mean that someone has punched a hole in IE's condom with a cyber-thumbtack?
...or enable inactive surfing
He who knows best knows how little he knows. - Thomas Jefferson
Average joe search for p0rn
He fins a site with virus that gets installed on his computer.
Virus finds the pr0n for him....
Both win!
You mean that IE isn't 100% dedicated to perfect security?
I don't see the point of these announcements. People who care about not getting hacked are using Firefox, Opera, Safari or Lynx at this point.
People who still use IE... well... they probably won't do much in response to this warning anyway.
What are you eating? isItVeg?.
A trojan to redirect my browser to porn sites. I do that well enough without the assistance. *grin*
Apparently this wild trojan uses IE to direct a very specific type of attack against /., which results in dupe stories being posted!
You can't handle the truth.
"The Register reports on a [[register article|trojan spotted in the wild]] that takes advantage of the so-far unpatched IE [[|Slashdot story|vulnerability]] mentioned on Slashdot earlier this week."
That should be done like this:
"The Register [[register article|reports]] on a [[a page with the trojan|trojan spotted in the wild]] that takes advantage of the so-far unpatched IE [[How to exploit?|vulnerability]] [[Slashdot story|mentioned on Slashdot]] earlier this week."
Anagram("United States of America") == "Dine out, taste a Mac, fries"
So, if I run IE under wine on linux I can get all the free pr0n delivered to my desktop. Nice. Click the big blue "E" for free e-pr0n
Except that using Lynx tells the authorities that you are a malicious h4x0r...apparently, using a "non-standard" browser will cause the SWAT team to descend on you in true Terry GilliamBrazil style.
Oh, wait, we're not. Just fucking with you.
Hopefully both IE slashdot users don't have mod points today.
Now if only I can figure out how to enable popups, disable tabs, and make Safari look all multicolorful and jaggy I'd be one effective mofo.
If you don't know what AltaVista is (was), get off my lawn.
Hole in IE?
Exploited?
Must be a slow news week.
-judging another only defines yourself
Maybe they're selling the fix through the new anti-virus software?
Stop! Dremel time!
Wait, people are still using IE?
Since when?
You are in error. No-one is screaming. Thank you for your cooperation.
Doesn't this go against Microsoft's antivirus acquisition^W initiative?
Would this be the 6 month old exploit that MS didn't feel was important enough to take care of? Complete Crap..
But one week is nothing compared to other vulns. Look at this list of other currently unpatched holes in MS products: http://www.eeye.com/html/research/upcoming/index.h tml.
Some of them has been reported months ago and are still unfixed.
This is inadmissible for a multi-billion dollars company.
Signed, Concerned Fan....
could anyone point me to where I might pickup this gem of a virus? I'm a little bored and was hoping to "research" the auto-pr0n capabilities. Reinstalling IE now...
-Lod
Anyone else find it ironic that the page has ads for Microsoft "secure" network tools and trojan blocking? There was one when I first vied the page. I did a reload and it showed a different one on the same theme.
When will Windows be ready for the desktop?
The Sky is blue!
Bears still crap in the woods!
Amazingly, the Pope is Catholic!
I'm beginning to suspect that all these IE vulnerabilities are a marketing ploy. Let's face it, there's got to be 100 articles a week on IE vulnerabilities, keeping IE in front of everybody, while Firefox & Opera get so little coverage (except for maybe on /.). Of course if this is true, then it just goes to prove how genuinely stupid and useless marketing people really are...
GetOuttaMySpace - The Anti-Social Network
Before everyone gets too worked up bashing IE, as in the previous few articles on this exploit, let's remember that this problem was freezing/crashing FireFox 1.5 also.
Although the security threat isn't existent in FireFox, the browser still fails on these pages.
Now before I get flamed, let it be known that I think IE is a disaster and it's lack of standards compliance is one of the main things holding back proper advancment in web technologies, but we don't want to go and be unfair when our browser crashes too!
Big ones, small ones, some as big as yer 'ead!
Give 'em a twist, a flick o' the wrist...
What the article doesn't tell, is that sometimes, the virus redirects to goatse.
GAHHHH!!!!
Heheh. Just kidding.
The exploit never worked for me anyway, so I don't think I have anything to worry about ;)
We run eSafe gateway. (Search Google.) This software has had protection against this threat since 11/24/2005. The proof of concept does not work on my test machine, which is protected by eSafe.
Many times eSafe will protect us against 0-day exploits.
I highly recommened it. (I am an end user, not a salesman.)
One could make updating IE a full time job. It's rather annoying that you have to worry about this type of thing while browsing the internet.
[%] Cingular Ringtones
It's not a dupe, we just see so many of these kinds of stories that it SEEMS like a dupe.
"Live Free or Die." Don't like it? Then keep out of the USA
crumpetts and tea are compiled with the GB version ;-)
401 - Attention span not found
That's the temporary fix. I realise we're talking about MS here, but really. When (if) MS gets around to patching this hole, i would imagine it would target the issue with the Window() call.
Oh right. OSX is perfectly safe and invunerable... so long as you patched a few unpatched critical security holes yesterday, and weren't previously infected...
p atches/2100-1002_3-5976718.html
http://news.com.com/Apple+releases+OS+X+security+
Apparently, Microsoft is preparing an emergency patch for this.
I said a prayer for ya bro. You seem quite confused, but the Lord will set ya str8. Just drop to your knees and haller. You'll see...
Yet another teriffic site with exactly 7 lines of article in a one-third screen-width column (would probably be just 2 lines in a full width column).
:-((
The rest of that page, 3 screens high, is filled with all kinds of other crap.
> What exactly is different between en_US and en_GB versions?
When using the en_GB version, you get 404's surfing the internet superhighway with the mouse on the left side of the keyboard...
Some hacker kid got caught by his mom with the pr0n and had to write a virus to blame it on. I would condem his evil actions but I'm more upset I did not think of it first.
The perversity of the Universe tends towards a maximum. - O'Toole's Corollary
You know, if it were any other company than Microsoft, people wouldn't put up with such a thing. Microsoft selling anti-malware software would be like a car company forgetting to put brakes on their cars, and then charging for the fix! But a car company wouldn't be allowed to do that; they'd instead have to do a recall and fix the problem at their own expense. Why is Microsoft allowed to get away with it?!
"[Regarding the 'cloud,'] ownership was what made America different than Russia." -- Woz
It does all the work for you, includes many features that IE already has... Spying on you!
Security is but an illusion of the mind
~M45T3R S4D0W8~
So, the vulnerability is 6 months old, and it never got fixed as a minor risk. It got escalated to a highly critical risk (by almost all security bulletin systems) over 1 week ago, when a proof of concept came out showing that a malicious site could cause take control of PC remotely. Now there is even malicious trojans out on the net exploiting this hole in IE.
So in 1 week, what did MS do? The promoted their new Live product of course. Microsoft released a security advisory stating that no patch exists to fix the problem, but you can visit the Windows Live Safety Center and get the trojan removed by Microsoft. So instead of using some resources to fix the problem, they instead devoted resources to their "anti-virus" software, and promote it as the workaround. Well, one wonders, if this causes them to get significant visibility and traffic to their new product, why bother even fixing the original problem?
"redirect surfers onto porn sites."
This doesn't sound like such a bad trojan afterall.
Amen.
Showing religious people how wrong they really are with constructive methods that helps our society grow would be better.
But i must agree that just blaspheming is funnier, more satisfactory, and will achieve as much as the method described above, since people is blind and stupid.
WTF am I doing replying to an AC at 5 A.M on a Friday night?
That's something i didn't understand. Why would you put copy protection on a CD nobody would copy?
;-)
On certain things sony has released, i would put burning and massive destruction protection
WTF am I doing replying to an AC at 5 A.M on a Friday night?
i really don't know of anyone still using IE besides the retards who run the technology in public areas that assume that anything besides microsoft's standard software setup is incompatible and compltely unusable.
"This is inadmissible for a multi-billion dollars company."
Strike that. This is inadmissible for a multi-billion dollar company who claims security is priority one.
see here. I'm tired of open source zealots who don't even understand that the software they used is not secure.
Vote for Pedro
In Microsoft Internet Explorer, porn finds YOU!
Rather laugh with the sinners than cry with the saints anyway, so there. BTW, why in the hell does anybody still use IE ?
Thanks slashdot, you've now reported this non-story 3 times.
... instead of maybe reporting every 5th problem.
How about we start reporting every little problem with non-MS products 3 times each
It's time for a little balance here!
George Bush + Linux = "I will not let information get in the way of the fight against Windows"
There must be a problem with Slashdot. Every few weeks this same article "Trojan Exploits Unpatched IE Flaw" keeps coming up in amongst all the other tech news for the day.
I think I have seen something like this before.
Somebody did the whole 'Jedi hand wavey thing on me'..."This is not the exploit you are lookin for."
Today's show is brought to you by the number 09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0: 25
maybe my english understanding is a little low today, or those vodka shots made effects, but i don't really understand your post ... please clarify ...
... well, the actual question would be why is people still using windows, but, then again, people still beleive that there is a supreme perfect being ... so, it's not suprising that most of the world still uses IE ...
About IE
WTF am I doing replying to an AC at 5 A.M on a Friday night?