Friday, July 21, 2006

Hacked Ad Seen on MySpace Served Spyware to a Million

An online banner advertisement that ran on MySpace.com and other sites over the past week used a Windows security flaw to infect more than a million users with spyware when people merely browsed the sites with unpatched versions of Windows, according to data collected by iDefense, a Verisign company.
Michael La Pilla, an iDefense "malcode" analyst, said he first spotted the attack Sunday while browsing MySpace on a Linux-based machine. When he browsed a page headed with an ad for DeckOutYourDeck.com, his browser asked him whether he wanted to open a file called exp.wmf. Microsoft released a patch in January to fix a serious security flaw in the way Windows renders WMF (Windows Metafile) images, and online criminal groups have been using the flaw to install adware, keystroke loggers and all manner of invasive software for the past seven months.
Internet Explorer users who visited a Web page containing this ad and whose IE was not equipped with the WMF patch would not get that warning. Rather, their machines would silently download a Trojan horse program that installs junk software in the PurityScan/ClickSpring family of adware. This stuff bombards the user with pop-up ads and tracks their Web usage. Only a little more than half of the anti-virus programs used at anti-virus testing service AV-Test.org flagged the various programs that the Trojan tried to download as malicious or suspicious.
Using software that captures and analyzes Web traffic, La Pilla found that the installation program contacted a Russian-language Web server in Turkey that tracks how many times the program was installed, presumably because most of this adware is installed by third parties who get paid for each installation. The data there indicate that the adware was installed on 1.07 million computers, La Pilla said, adding that all seven of the Internet addresses contacted by the downloader Trojan appear to be inactive at this time.

9 Comments:

At 4:30 AM, Blogger yasser said...

hmm...interesting - so it was only tracking your web usage and prompting ads?

 
At 5:12 AM, Blogger Molecular Turtle said...

Thanks for the info

 
At 6:48 AM, Blogger Dangerousnerd said...

Wow... scary...

 
At 6:39 PM, Blogger Unknown said...

Nice blog. This is why I use Firefox! It doesn't allow anything to run that you do not want.

Thanks for the warning and keep up the blogging!

 
At 4:26 AM, Blogger bc said...

Myspace is stupid kiddy shit. Maybe the whole site will overload one day and we'll be rid of that shit.

Support Hezb'!! Annul Isra'el!

 
At 6:41 AM, Blogger Big Dave Smith said...

Avoiding spyware:

1> Use Firefox
2> Use Linux
3> Avoid MySpace

Personally, even if MySpace was spyware-free, most of those pages are enough to make a grown man's eyes bleed.

 
At 1:26 PM, Blogger Resonance said...

God, Spyware blows...

Save the world! Visit my blog at murftown.blogspot.com

 
At 5:55 PM, Blogger High Power Rocketry said...

Scary is right...

 
At 8:12 AM, Blogger Me said...

Why am I not suprised.

 

Post a Comment

<< Home