By George Norman - Software News Editor
Added on 16 Dec 2008(1791 Views)
The security vulnerability that until recently only affected Internet Explorer 7 (IE7) has taken on a life of itself and now not only is it being exploited by people with malicious intent, it also affects all Internet Explorer versions (perhaps not IE8 RC1 that has been released only to Microsoft partners). A staggeringly large number of web pages have been infected, and security experts advise IE users to switch to other browsers while the problem is being investigated.

Graham Cluley from Sophos, company that specializes in developing security software and hardware, comments: “On Saturday, Microsoft blogged that a staggering 0.2% of all internet users may have been exposed to the exploit, which has been seen on pornographic websites. Of course, website attackers don’t just target porn sites. We see something like 20,000 new infected webpages every single day (that’s one every 4.5 seconds), and the vast majority of those are legitimate sites that have been compromised by the likes of an SQL injection attack.”


There are a couple of snags that you must be aware of. First of all, even though Microsoft said it is looking into the matter and will issue a fix as soon as possible, who knows how long it will take them to come up with a patch. Switching over to browsers such as Mozilla Firefox, Google Chrome, or Opera 9.63 is not a miracle cure-for-all; these browsers have plenty to offer, but they will not guarantee a 100% online safety percentage.

If you are curious to find out how this security vulnerability is being actively exploited, the Microsoft Malware Protection Center provides an explanation: “First, some legitimate web sites were maliciously modified to include the exploits. For example a popular search engine in Taiwan was found to be hosting the exploit. Luckily, that site was quickly cleaned. Secondly, we’ve noticed some pornography sites have started hosting these exploits too: We recently found a web site in Hong Kong that serves various content including adult entertainment. Users who hoped to watch that content, became target of those attacks: specifically, the exploit dropped Trojans that we detect as Trojan:Win32/VB.IQ.dr and Trojan:Win32/VB.IQ.”

According to Senior Security Advisor with TrendMicro, Rick Ferguson, so far the exploit has been used to steal game passwords, but it is only a matter of time until online criminals will start taking advantage of it.





Don't forget to:

RSS


Tags: Microsoft, Internet Exporer

Link to this article:


Comments

emma - 01 Jun 2009 21:03
hi i was checking through my history on my new laptop and found that pornographic sites were listed when i have not actually visited them! is this what happens in the problem above? i have installed mozilla firefox for now and this has not happened since, what i found so odd was that in the history section, under google search, were some rather explicit searches!! i was wondering if aznyone has experienced this problem. thanks
mark angel - 26 May 2009 22:38
I pretend to give dogs away but I'm really a scam artist, so please sign me up for loads of spam to help me mend my ways!

Add comment:
Name(Required)
Email(Required - Never shown)
Website(Optional)
Comment(Required):

Insert the following code:
Software News
Chromium OS Goes Open-Source
This summer Google let the world know that it is working on a new operating system meant for the user that spends most of his time online. The operating system – aptly named Chrome OS because it is a natural extension...
20 Nov 2009
Office 2010 Beta Downloads Available to the Public
Earlier this week Redmond-based software giant Microsoft announced that Office 2010 became available for download as a Beta. The catch was that only ...
20 Nov 2009
Mozilla Releases: Firefox 3.6 Beta 3
The development process of the Firefox 3.6 browser is moving along rapidly. The first Beta version was released at the start of the month; Beta 2 was released about two weeks after Beta 1. About a week has passed since...
20 Nov 2009
New Labs Feature for Gmail: Green Robot!
The software developers at Google have announced the release of a new Gmail Labs offering called Green Robot! This new offering is meant to improve the Gmail Chat user experience by letting the ...
20 Nov 2009
Opera Mobile 10 Beta for Windows Mobile Is Out Also
Opera Software, the company that we all know for making the innovative and feature rich Opera web browser, has released Opera Mobile 10 Beta for Windows Mobile-powered devices. This release follows in the...
19 Nov 2009
Beta Testing is Over, Stable Version of Trillian for iPhone Released
The focus so far has been on desktop version of this multiprotocol instant messaging software application, Trillian Astra (version 4.1). Today is time to switch focus away from the desktop version and onto something a bit more...
19 Nov 2009
Recommended Tools

Top Downloads