New generation of IE malware now circulating
The exploit -- faster, more vicious -- was released just before the weekend
March 31, 2006 12:00 PM ETIDG News Service - Hackers have posted a new version of malicious software that will make it easier for them to exploit an unpatched vulnerability in Microsoft Corp.'s Internet Explorer browser. Based on a critical bug disclosed on March 22, the software was posted by hackers Friday to the Milw0rm.com Web site.
The code exploits a flaw in the way IE processes Web pages using the createTextRange() method. Hackers have been using malware that takes advantage of this vulnerability to install unauthorized software on victims' computers over the past week, but this new generation is considered to be more dangerous, according to security researchers.
Older versions of the malware could freeze victims' browsers for more than a minute, giving them an opportunity to shut down their computers or stop the malicious software before it could complete its work. But the new software works more quickly, meaning it will be particularly effective on older machines with limited memory and processing capabilities, said Craig Schmugar, researcher with McAfee Avert Labs.
Though hackers had not widely adopted the new software as of Friday morning, Schmugar said he expected that to change. "It's still pretty early," he said. "I think it's reasonable to expect that people will shift."
The software also uses new techniques to avoid certain types of signatures used by antivirus vendors, said Aviv Raff, a security researcher based in Israel. "It's much more effective," he said. "I think people should know and understand that ... now they are more vulnerable."
The fact that the code was released just before the weekend is also worrisome, because it means that "administrators have to wait for Monday to apply their protections and to give warning to users," said Juha-Matti Laurio, a security researcher in Helsinki.
With a fix for the problem expected as late as April 11, the date of Microsoft's next scheduled security update, security companies Determina Inc. and eEye Digital Security Inc. issued unsupported patches for the problem. According to eEye, there have been more than 70,000 downloads of its software since its Monday release.
Microsoft does not recommend that users install these patches. Instead, it recommends that users disable IE's Active Scripting feature as a work-around.
Despite the severity of the TextRange() bug, McAfee says that the malware that takes advantage of it is not particularly widespread. This software at present ranks number 13 in McAfee's list of the top 20 pieces of malware being reported, Schmugar said.
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
Additional Resources


White Papers & Webcasts
How Controlling Access to Privileged Accounts Can Keep Insider Threat from Hurting Your Bottom Line
This white paper explores insider attacks and insider risk, and shows how to control them by controlling and monitoring access. The paper describes...
Strategic ECM Webinar
Learn what new strategic business benefits can be realized through ECM!...
Eliminate Spam, Gain Productivity
In this exclusive whitepaper, learn all about the dangers of spam and the cost to your business....
Managing And Protecting Your Ever Increasing Mobile Assets
Learn best practices for desktop and application virtualization, computer security, and computer life-cycle management....
2009 Gartner Magic Quadrant Report
Truly understand your options for WAN Optimization Controllers...
5 Architecture Issues that Impact BES performance
This Live webinar will identify critical log file errors, performance counters, and configurations to pay close attention to when optimizing BES server performance....
Tech Horizons: ASG's metaCMDB, The Technology That Rocks
Improved business productivity often requires more efficient IT and more efficient IT cannot be achieved without a better understanding of the way business...
Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....
The Vector Approach to Data Center Power Planning
This white paper describes an approach that considers the major milestones and thresholds in data center power requirements-and how planners should adjust their...
The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....
Subscribe to Computerworld


