Euro Web sites spread Bofra worm via banner ads
It doesn't affect Windows XP Service Pack 2
November 22, 2004 12:00 PM ETIDG News Service -
Web site visitors who clicked on banner ads on a number of popular European Web sites this weekend may have infected their computers with variants of the Bofra worm, experts warned today.
The attacks take advantage of an unpatched buffer overflow flaw in the way Internet Explorer 6 handles the IFrame tag and has been confirmed on PCs running Windows XP with Service Pack 1 and Windows 2000, according to a warning posted yesterday on the SANS Institute's Web site.
Windows XP Service Pack 2 isn't vulnerable, it said.
The vulnerability allows attackers to gain complete control of a user's computer.
Also yesterday, U.K. technology news Web site The Register reported that its third-party ad-serving company, Falk AG, became infected with the Bofra/IFrame exploit, forcing the Web site to suspend its ads from Falk.
"If you may have visited the Register between 6 a.m. and 12.30 p.m. GMT on Saturday, Nov. 20, using any Windows platform bar XP SP2, we strongly advise you to check your machine with up-to-date antivirus software, to install SP2 if you are running Windows XP, and to strongly consider running an alternative browser, at least until Microsoft deals with the issue," The Register said on its Web site.
According to SANS, there were also reports of sites in Sweden and the Netherlands being compromised by the malicious code.
In the Netherlands, the country's biggest news site, NU.nl, which has more than 450,000 unique visitors per month, was infected through the Falk ad system and served the code to its visitors. The other sites of Ilse Media BV, including one of the largest Dutch sites, Startpagina, distributed the Trojan horse as well.
Ad server tags and link addresses were manipulated in order to install and execute the malware. User requests were redirected from Falk's servers to the URL search.comedycentral.com (199.107.184.146), from where the malicious code was delivered, Falk said in a statement.
Falk competitor Adtech AG released its own statement saying that its ad-serving system, Helios, wasn't affected by the problem.
Microsoft has yet to issue a patch for the Internet Explorer IFrame hole for users who have not installed SP2. However, some "unofficial" patches have been released, including one from a German security researcher at the Web site Cherryware.de.
Wilbert de Vries contributed to this report.
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
Viruses
Additional Resources



White Papers & Webcasts
Share our Strength
Download Now
Key Strategies for Managing Data Growth
What are you storage challenges?
Can Heuristic Technology Help Your Company Fight Viruses?
What is Heuristic Technology and how can it help safeguard your business against viruses? Learn more.
Extending Client Refresh - 11 Steps to Maximize Savings
Register Now!
Eradicate Spam & Gain 100% Asurance of Clean Mailboxes
Get this paper now!
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Mastering eDiscovery: The IT Manager's Guide to Preservation, Protection & Production
Get this paper now!
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Not Just Words: Enforce Your Email and Web Acceptable Usage Policies
Get this paper now!
Consolidate Your Servers and Storage to Lower Costs with Oracle Database 11g
Register for this webcast!
