Thursday, February 19, 2004
Something else to worry about...
[See Previous]
This article on E-card hijack spam is written by a person who got a piece of spam email. When he clicked on the link in the email he found that the web page he arrived at is malicious. What this points out is that it is now possible to build ordinary web pages that have destructive intent.
In his analysis, the author found that the web page he arrived at tries to do several different things to his machine:
Now we are seeing malicious Web pages. You arrive at an innocent-sounding URL and find it able to cause bad things to happen on your computer. If the trend spreads, it could put a big damper on random surfing.
I wonder if Google has technology in place to detect malicious pages in its index? It would also be nice if Google flagged the pages that link to malicious pages.
Here's the author's advice: "If you're still using Outlook and Internet Explorer, this is a good time to find alternatives (I suggest FireFox and Thunderbird). Crackers and spammers are getting more and more sophisticated, and are finding ways to fool even experienced and skilled computer users."
ARCHIVES
This article on E-card hijack spam is written by a person who got a piece of spam email. When he clicked on the link in the email he found that the web page he arrived at is malicious. What this points out is that it is now possible to build ordinary web pages that have destructive intent.
In his analysis, the author found that the web page he arrived at tries to do several different things to his machine:
- It attempts to download a file called a.exe and run it. According to the article, the page "includes a hidden textarea which contains ActiveX to download a certain a.exe, and overwrite the Windows Media Player wmplayer.exe with it. Once the file has been replaced, IE is redirected to the mms://, which causes the invocation of wmplayer.exe. The code in this textarea is processed by some javascript after a 5 second timeout, and is run in Internet Explorer's 'Media Sidebar'. Before this 5 second timeout, however, a fake url, error.jsp, is opened in the media sidebar to throw off the user."
- It then "tries yet another IE exploit to run a.exe remotely."
- It then tries a third way to run a.exe using vbscript. "The vbscript code contains strings which represent, in hex, the binary contents of a certain executable which is saved as x.exe. Once saved, this executable is launched with the url to a.exe as an argument."
Now we are seeing malicious Web pages. You arrive at an innocent-sounding URL and find it able to cause bad things to happen on your computer. If the trend spreads, it could put a big damper on random surfing.
I wonder if Google has technology in place to detect malicious pages in its index? It would also be nice if Google flagged the pages that link to malicious pages.
Here's the author's advice: "If you're still using Outlook and Internet Explorer, this is a good time to find alternatives (I suggest FireFox and Thunderbird). Crackers and spammers are getting more and more sophisticated, and are finding ways to fool even experienced and skilled computer users."
- 05/01/2003 - 06/01/2003
- 06/01/2003 - 07/01/2003
- 07/01/2003 - 08/01/2003
- 08/01/2003 - 09/01/2003
- 09/01/2003 - 10/01/2003
- 10/01/2003 - 11/01/2003
- 11/01/2003 - 12/01/2003
- 12/01/2003 - 01/01/2004
- 01/01/2004 - 02/01/2004
- 02/01/2004 - 03/01/2004
- 03/01/2004 - 04/01/2004
- 04/01/2004 - 05/01/2004
- 05/01/2004 - 06/01/2004
- 06/01/2004 - 07/01/2004
- 07/01/2004 - 08/01/2004
- 08/01/2004 - 09/01/2004
- 09/01/2004 - 10/01/2004
- 10/01/2004 - 11/01/2004
- 01/01/2005 - 02/01/2005
- 02/01/2005 - 03/01/2005
- 03/01/2005 - 04/01/2005
- 04/01/2005 - 05/01/2005
- 05/01/2005 - 06/01/2005
- 06/01/2005 - 07/01/2005
- 07/01/2005 - 08/01/2005
- 08/01/2005 - 09/01/2005
- 09/01/2005 - 10/01/2005
- 10/01/2005 - 11/01/2005
- 11/01/2005 - 12/01/2005
- 12/01/2005 - 01/01/2006
- 02/01/2006 - 03/01/2006
- 03/01/2006 - 04/01/2006
- 04/01/2006 - 05/01/2006
- 05/01/2006 - 06/01/2006
- 06/01/2006 - 07/01/2006
- 07/01/2006 - 08/01/2006
- 08/01/2006 - 09/01/2006
- 09/01/2006 - 10/01/2006
- 10/01/2006 - 11/01/2006
- 11/01/2006 - 12/01/2006
- 12/01/2006 - 01/01/2007
- 01/01/2007 - 02/01/2007
- 02/01/2007 - 03/01/2007
- 03/01/2007 - 04/01/2007
- 05/01/2007 - 06/01/2007
- 07/01/2007 - 08/01/2007
- 09/01/2007 - 10/01/2007
- 07/01/2008 - 08/01/2008