By George Norman - Software News Editor
Added on 16 Dec 2008(1747 Views)
The security vulnerability that until recently only affected Internet Explorer 7 (IE7) has taken on a life of itself and now not only is it being exploited by people with malicious intent, it also affects all Internet Explorer versions (perhaps not IE8 RC1 that has been released only to Microsoft partners). A staggeringly large number of web pages have been infected, and security experts advise IE users to switch to other browsers while the problem is being investigated.

Graham Cluley from Sophos, company that specializes in developing security software and hardware, comments: “On Saturday, Microsoft blogged that a staggering 0.2% of all internet users may have been exposed to the exploit, which has been seen on pornographic websites. Of course, website attackers don’t just target porn sites. We see something like 20,000 new infected webpages every single day (that’s one every 4.5 seconds), and the vast majority of those are legitimate sites that have been compromised by the likes of an SQL injection attack.”


There are a couple of snags that you must be aware of. First of all, even though Microsoft said it is looking into the matter and will issue a fix as soon as possible, who knows how long it will take them to come up with a patch. Switching over to browsers such as Mozilla Firefox, Google Chrome, or Opera 9.63 is not a miracle cure-for-all; these browsers have plenty to offer, but they will not guarantee a 100% online safety percentage.

If you are curious to find out how this security vulnerability is being actively exploited, the Microsoft Malware Protection Center provides an explanation: “First, some legitimate web sites were maliciously modified to include the exploits. For example a popular search engine in Taiwan was found to be hosting the exploit. Luckily, that site was quickly cleaned. Secondly, we’ve noticed some pornography sites have started hosting these exploits too: We recently found a web site in Hong Kong that serves various content including adult entertainment. Users who hoped to watch that content, became target of those attacks: specifically, the exploit dropped Trojans that we detect as Trojan:Win32/VB.IQ.dr and Trojan:Win32/VB.IQ.”

According to Senior Security Advisor with TrendMicro, Rick Ferguson, so far the exploit has been used to steal game passwords, but it is only a matter of time until online criminals will start taking advantage of it.





Don't forget to:

RSS


Tags: Microsoft, Internet Exporer

Link to this article:


Comments

emma - 01 Jun 2009 21:03
hi i was checking through my history on my new laptop and found that pornographic sites were listed when i have not actually visited them! is this what happens in the problem above? i have installed mozilla firefox for now and this has not happened since, what i found so odd was that in the history section, under google search, were some rather explicit searches!! i was wondering if aznyone has experienced this problem. thanks
mark angel - 26 May 2009 22:38
I pretend to give dogs away but I'm really a scam artist, so please sign me up for loads of spam to help me mend my ways!

Add comment:
Name(Required)
Email(Required - Never shown)
Website(Optional)
Comment(Required):

Insert the following code:
Software News
Fun Friday Feature: Cry Translator iPhone App
I remember that some obscure school teacher once told me that speech separates man from beast. Now I always found that reasoning to be somewhat flawed. What about parrots? They can speak – sort of. Or...
06 Nov 2009
Chrome 3.0 and 4.0 Updated on the Stable and Dev Channel
The guys over at Google are keeping as busy, of not more so, as the guys over at Mozilla. While the Mozilla Foundation has recently released Firefox 3.6 Beta 1 and Firefox 3.5.5, Mountain View-based search engine giant Google ...
06 Nov 2009
November 09 Patch Tuesday: 6 Security Bulletins, 15 Vulnerabilities
Next week’s first two days are already booked. On Monday, the 9th of November, we will be celebrating Firefox’s 5th anniversary. On Tuesday, we will focus on something less entertaining, mainly patching our...
06 Nov 2009
Firefox 3.5.5 Update Released
The Mozilla Foundation has released another update for its browser, mainly Firefox 3.5.5. The update follows in the footsteps of Firefox 3.5.4, an update that was released about a week back...
06 Nov 2009
iTunes 9.0.2 Update Loves Apple TV 3.0 Software, Breaks Palm Pre Syncing (Again)
Cupertino-based software developer Apple has recently updated its digital media player iTunes to version 9.0.2. The update, which follows in the footsteps of iTunes 9.0.1 and iTunes 9.0, brings forth one significant new change...
05 Nov 2009
Blacksn0w: Unlock Tool for the iPhone 3G and 3GS
Great news for iPhone 3G and iPhone 3GS users that updated the device to baseband version 05.11; or iPhone 3G and iPhone 3GS users that bought the device with an updated baseband. Original iPhone hacker...
05 Nov 2009
Recommended Tools

Top Downloads