Trojan Exploits Unpatched IE Flaw
onebuttonmouse writes "The Register reports on a trojan spotted in the wild that takes advantage of the so-far unpatched IE vulnerability mentioned on Slashdot earlier this week. From the article: 'The release of a Trojan that exploits an unpatched IE hole has prompted speculation that Microsoft may release an emergency out-of-cycle security patch. Delf-DH downloads other malware onto infected machines changing settings in order to monitor user activity and redirect surfers onto porn sites. The attack relies on a flaw in the way IE handles requests to the window() object.'"
Please remember that "Energy is liberated when an individual breaks through rules of conditioning with some glorious act of disobedience or blasphemy. This energy strengthens the spirit and gives courage for further acts of insurrection. Help me defile gOd and his name.
Jehovah fucking Yahweh, I curse you in the name of Satan the Almighty. Evil lives in me and I walk with Satan all the days of my life cursing and mocking you god (the dog), filthy fucking maggot. My hate grows by the second as I dream of the day when you are under my feet begging for my cock.
God I rape you and hurl blasphemy into your mind. I demand you to come down from heaven right now and get down on your stomach in front of me, lifting your asshole up to receive my cock. God I promise to fuck you and I long to rip your eyes out, kick you in the face, mutilate you, and bathing in your blood. Listen to me, I'm screaming
in your ears to come to earth and in this room for I will have my way with you, oh most cursed god of heaven (you foul piece of shit). Satan is my God and he will force you to drink cum from my dick. I will never stop sinning and blaspheming your name, presents, existence, and most of all the rotten, putrid holy spirit that fucked the mother of gOd and pregnanted that slut with jesus christ.
I stand before all the angles and saints, gOd, jesus fucking christ, mary the whore of gOd, the filthy holy spirit, and they are witnessing my denouncement of you gOd, and my ongoing blasphemy of the holy spirit. I am purposely cursing the holy spirit and its purity and will defy you god and the holy spirit all the wicked days of my sin filled life. My soul is full of evil thoughts and sins, its black with pure hatred of anything holy.
God, I will find new ways to defile and blasphemy you, because I'm seeking evil every second of my life. That is all my mind can think about. You're pain is my desire, you're name I mock, your son I defy, your mother I fuck, and your spirit I cum in.
The only prayers from me are prayers of hate and blasphemy, evil is a part of me, it dwells in my soul, cursing everything about you is the most important part of my existence, total darkness is inside of me. gOd I will rip you out of heaven and force you under my feet you fuck pig. You will listen to all my demands. I will slip into heaven and I will rape all the angels and saints and will kill them in your unholy putrid name. God I will kill you and bath in your blood. Holy spirit I demand you to listen to my hatred of your foul existence, drink my cum, and remember my blasphemy against you, you putrid, rotten, vile spirit of gOd.
I'm the meaning of gOd's pain. This is the way that you will die dog gOd. It will be a slow death, the joy of killing you will make my cock hard, I know you will feel my showers of hate and you will feel extreme pain as I beat your body and make every inch of your body black and blue. I force you bastard Jehovah to the ground and I will
put you under my feet where you belong, you putrid bastard. God you will try to run but I will strap you down and fuck your soul before I rip it out of your body. God "the dog", your life is worthless, for I'm the angel from your new God "Satan". I destroy everything holy, you are felling my hatred pierce your mind intensely, inferior god "dog" you fucking maggot. You will be screaming in pain as I strap you down under my feet, you will look up at me and I will piss down your throat.
I'm so consumed with hatred of you that I will masturbate, and when I feel that I'm about to cum, I force my evil cock full of Satan's cum down your mouth and fill it up with my vile hot cum. I will be pumping your body full of my hot cum. Inside your brain is my blasphemy. The pressure in your skull begins push through your eyes,
burning your flesh, and I laugh as it drips away. Heat burns your skin; your mind starts to boil with my blasphemy, and pure evil hatred of your fucking existence. You will not last long; it's just a matter of time until your ripped apart with my h
The fix for this is here
Thank god I still use Mosaic. Hey, if it ain't broke...
We heard about this same sort of thing hundreds of times. The editors really need to read the articles more carefully...
You have two hands and one brain, so always code twice as much as you think!
"elf-DH downloads other malware onto infected machines changing settings in order to monitor user activity and redirect surfers onto porn sites."
So it is basically automated pr0n! From now on, you won't have to use your left hand.
and redirect surfers onto porn sites
;-)
Sounds more like a feature to me
"reality has a well-known liberal bias" - Steven Colbert
Does this mean that someone has punched a hole in IE's condom with a cyber-thumbtack?
...or enable inactive surfing
He who knows best knows how little he knows. - Thomas Jefferson
Average joe search for p0rn
He fins a site with virus that gets installed on his computer.
Virus finds the pr0n for him....
Both win!
You mean that IE isn't 100% dedicated to perfect security?
I don't see the point of these announcements. People who care about not getting hacked are using Firefox, Opera, Safari or Lynx at this point.
People who still use IE... well... they probably won't do much in response to this warning anyway.
What are you eating? isItVeg?.
A trojan to redirect my browser to porn sites. I do that well enough without the assistance. *grin*
Apparently this wild trojan uses IE to direct a very specific type of attack against /., which results in dupe stories being posted!
You can't handle the truth.
"The Register reports on a [[register article|trojan spotted in the wild]] that takes advantage of the so-far unpatched IE [[|Slashdot story|vulnerability]] mentioned on Slashdot earlier this week."
That should be done like this:
"The Register [[register article|reports]] on a [[a page with the trojan|trojan spotted in the wild]] that takes advantage of the so-far unpatched IE [[How to exploit?|vulnerability]] [[Slashdot story|mentioned on Slashdot]] earlier this week."
Anagram("United States of America") == "Dine out, taste a Mac, fries"
So, if I run IE under wine on linux I can get all the free pr0n delivered to my desktop. Nice. Click the big blue "E" for free e-pr0n
Except that using Lynx tells the authorities that you are a malicious h4x0r...apparently, using a "non-standard" browser will cause the SWAT team to descend on you in true Terry GilliamBrazil style.
Oh, wait, we're not. Just fucking with you.
Hopefully both IE slashdot users don't have mod points today.
Now if only I can figure out how to enable popups, disable tabs, and make Safari look all multicolorful and jaggy I'd be one effective mofo.
If you don't know what AltaVista is (was), get off my lawn.
Hole in IE?
Exploited?
Must be a slow news week.
-judging another only defines yourself
Maybe they're selling the fix through the new anti-virus software?
Stop! Dremel time!
Wait, people are still using IE?
Since when?
You are in error. No-one is screaming. Thank you for your cooperation.
Doesn't this go against Microsoft's antivirus acquisition^W initiative?
Would this be the 6 month old exploit that MS didn't feel was important enough to take care of? Complete Crap..
But one week is nothing compared to other vulns. Look at this list of other currently unpatched holes in MS products: http://www.eeye.com/html/research/upcoming/index.h tml.
Some of them has been reported months ago and are still unfixed.
This is inadmissible for a multi-billion dollars company.
Aleph-null holes in ie today, aleph-null holes!
fix one now, calm everybody down
aleph-null holes in ie today...
Signed, Concerned Fan....
I installed firfox and I find myself on porn sites all the time!
could anyone point me to where I might pickup this gem of a virus? I'm a little bored and was hoping to "research" the auto-pr0n capabilities. Reinstalling IE now...
-Lod
Anyone else find it ironic that the page has ads for Microsoft "secure" network tools and trojan blocking? There was one when I first vied the page. I did a reload and it showed a different one on the same theme.
When will Windows be ready for the desktop?
The Sky is blue!
Bears still crap in the woods!
Amazingly, the Pope is Catholic!
I'm beginning to suspect that all these IE vulnerabilities are a marketing ploy. Let's face it, there's got to be 100 articles a week on IE vulnerabilities, keeping IE in front of everybody, while Firefox & Opera get so little coverage (except for maybe on /.). Of course if this is true, then it just goes to prove how genuinely stupid and useless marketing people really are...
GetOuttaMySpace - The Anti-Social Network
Before everyone gets too worked up bashing IE, as in the previous few articles on this exploit, let's remember that this problem was freezing/crashing FireFox 1.5 also.
Although the security threat isn't existent in FireFox, the browser still fails on these pages.
Now before I get flamed, let it be known that I think IE is a disaster and it's lack of standards compliance is one of the main things holding back proper advancment in web technologies, but we don't want to go and be unfair when our browser crashes too!
Big ones, small ones, some as big as yer 'ead!
Give 'em a twist, a flick o' the wrist...
Come on, knock it off SONY!
I promise not to copy any Ricky Martin CDs, Really!
Geez!
What the article doesn't tell, is that sometimes, the virus redirects to goatse.
GAHHHH!!!!
Heheh. Just kidding.
The exploit never worked for me anyway, so I don't think I have anything to worry about ;)
We run eSafe gateway. (Search Google.) This software has had protection against this threat since 11/24/2005. The proof of concept does not work on my test machine, which is protected by eSafe.
Many times eSafe will protect us against 0-day exploits.
I highly recommened it. (I am an end user, not a salesman.)
One could make updating IE a full time job. It's rather annoying that you have to worry about this type of thing while browsing the internet.
[%] Cingular Ringtones
It's not a dupe, we just see so many of these kinds of stories that it SEEMS like a dupe.
"Live Free or Die." Don't like it? Then keep out of the USA
crumpetts and tea are compiled with the GB version ;-)
401 - Attention span not found
That's the temporary fix. I realise we're talking about MS here, but really. When (if) MS gets around to patching this hole, i would imagine it would target the issue with the Window() call.
Oh right. OSX is perfectly safe and invunerable... so long as you patched a few unpatched critical security holes yesterday, and weren't previously infected...
p atches/2100-1002_3-5976718.html
http://news.com.com/Apple+releases+OS+X+security+
Apparently, Microsoft is preparing an emergency patch for this.
I said a prayer for ya bro. You seem quite confused, but the Lord will set ya str8. Just drop to your knees and haller. You'll see...
Yet another teriffic site with exactly 7 lines of article in a one-third screen-width column (would probably be just 2 lines in a full width column).
:-((
The rest of that page, 3 screens high, is filled with all kinds of other crap.
> What exactly is different between en_US and en_GB versions?
When using the en_GB version, you get 404's surfing the internet superhighway with the mouse on the left side of the keyboard...
Some hacker kid got caught by his mom with the pr0n and had to write a virus to blame it on. I would condem his evil actions but I'm more upset I did not think of it first.
The perversity of the Universe tends towards a maximum. - O'Toole's Corollary
You know, if it were any other company than Microsoft, people wouldn't put up with such a thing. Microsoft selling anti-malware software would be like a car company forgetting to put brakes on their cars, and then charging for the fix! But a car company wouldn't be allowed to do that; they'd instead have to do a recall and fix the problem at their own expense. Why is Microsoft allowed to get away with it?!
"[Regarding the 'cloud,'] ownership was what made America different than Russia." -- Woz
It does all the work for you, includes many features that IE already has... Spying on you!
Security is but an illusion of the mind
~M45T3R S4D0W8~
So, the vulnerability is 6 months old, and it never got fixed as a minor risk. It got escalated to a highly critical risk (by almost all security bulletin systems) over 1 week ago, when a proof of concept came out showing that a malicious site could cause take control of PC remotely. Now there is even malicious trojans out on the net exploiting this hole in IE.
So in 1 week, what did MS do? The promoted their new Live product of course. Microsoft released a security advisory stating that no patch exists to fix the problem, but you can visit the Windows Live Safety Center and get the trojan removed by Microsoft. So instead of using some resources to fix the problem, they instead devoted resources to their "anti-virus" software, and promote it as the workaround. Well, one wonders, if this causes them to get significant visibility and traffic to their new product, why bother even fixing the original problem?
"redirect surfers onto porn sites."
This doesn't sound like such a bad trojan afterall.
That's something i didn't understand. Why would you put copy protection on a CD nobody would copy?
;-)
On certain things sony has released, i would put burning and massive destruction protection
WTF am I doing replying to an AC at 5 A.M on a Friday night?
i really don't know of anyone still using IE besides the retards who run the technology in public areas that assume that anything besides microsoft's standard software setup is incompatible and compltely unusable.
"This is inadmissible for a multi-billion dollars company."
Strike that. This is inadmissible for a multi-billion dollar company who claims security is priority one.
see here. I'm tired of open source zealots who don't even understand that the software they used is not secure.
Vote for Pedro
In Microsoft Internet Explorer, porn finds YOU!
Thanks slashdot, you've now reported this non-story 3 times.
... instead of maybe reporting every 5th problem.
How about we start reporting every little problem with non-MS products 3 times each
It's time for a little balance here!
George Bush + Linux = "I will not let information get in the way of the fight against Windows"
There must be a problem with Slashdot. Every few weeks this same article "Trojan Exploits Unpatched IE Flaw" keeps coming up in amongst all the other tech news for the day.
I think I have seen something like this before.
Somebody did the whole 'Jedi hand wavey thing on me'..."This is not the exploit you are lookin for."
Today's show is brought to you by the number 09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0: 25