Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Security
Virus and Vulnerability Roundup
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

Euro Web sites spread Bofra worm via banner ads

It doesn't affect Windows XP Service Pack 2

November 22, 2004 12:00 PM ET

IDG News Service - Web site visitors who clicked on banner ads on a number of popular European Web sites this weekend may have infected their computers with variants of the Bofra worm, experts warned today.
The attacks take advantage of an unpatched buffer overflow flaw in the way Internet Explorer 6 handles the IFrame tag and has been confirmed on PCs running Windows XP with Service Pack 1 and Windows 2000, according to a warning posted yesterday on the SANS Institute's Web site.
Windows XP Service Pack 2 isn't vulnerable, it said.
The vulnerability allows attackers to gain complete control of a user's computer.
Also yesterday, U.K. technology news Web site The Register reported that its third-party ad-serving company, Falk AG, became infected with the Bofra/IFrame exploit, forcing the Web site to suspend its ads from Falk.
"If you may have visited the Register between 6 a.m. and 12.30 p.m. GMT on Saturday, Nov. 20, using any Windows platform bar XP SP2, we strongly advise you to check your machine with up-to-date antivirus software, to install SP2 if you are running Windows XP, and to strongly consider running an alternative browser, at least until Microsoft deals with the issue," The Register said on its Web site.
According to SANS, there were also reports of sites in Sweden and the Netherlands being compromised by the malicious code.
In the Netherlands, the country's biggest news site, NU.nl, which has more than 450,000 unique visitors per month, was infected through the Falk ad system and served the code to its visitors. The other sites of Ilse Media BV, including one of the largest Dutch sites, Startpagina, distributed the Trojan horse as well.
Ad server tags and link addresses were manipulated in order to install and execute the malware. User requests were redirected from Falk's servers to the URL search.comedycentral.com (199.107.184.146), from where the malicious code was delivered, Falk said in a statement.
Falk competitor Adtech AG released its own statement saying that its ad-serving system, Helios, wasn't affected by the problem.
Microsoft has yet to issue a patch for the Internet Explorer IFrame hole for users who have not installed SP2. However, some "unofficial" patches have been released, including one from a German security researcher at the Web site Cherryware.de.
Wilbert de Vries contributed to this report.


Reprinted with permission from

IDG.net
Story copyright 2009 International Data Group. All rights reserved.

Additional Resources

POLL RESULTS
Accelerate your knowledge of the IT world you inhabit by viewing the results of a series of polls taken by your IT peers. These polls of 100+ IT professionals each are available for full viewing. They cover key topics such as virtualization, processor performance, green IT, cloud computing and many others. Be a part of the buzz.
WHITE PAPER
Technology is complex. Keeping it running productively shouldn't be. To that end, you want to minimize the number of solutions needed in-house to simplify operations, maintenance, and support. Kodak offers a best-practices model. One company provides support for both scanner and software, for fast problem resolution without vendor finger-pointing. Download now!
WHITE PAPER
Utilizing demand intelligence improves the precision of pricing, product assortments, channel/store placement, and promotion, which are all essential for sustainable revenue management performance. Learn more, download this free whitepaper today.

White Papers & Webcasts

Addressing Compliance Initiatives with Tripwire and the Center for Internet Security
Learn the basics about security benchmarks, and specifically how the security benchmarks developed by the Center for Internet Security (CIS) can help you...  

Strategic ECM Webinar
Learn what new strategic business benefits can be realized through ECM!...

An All-in-One Approach to Web Security
Granting web access to employees poses challenges to IT administrators and introduces unique security risks. Even as companies have perfected their security techniques...  

Managing And Protecting Your Ever Increasing Mobile Assets
Learn best practices for desktop and application virtualization, computer security, and computer life-cycle management....

The Hidden Dangers of Spam
Beyond the well-understood productivity drain that spam inflicts on businesses, threats posed by illicit email circulating through a network are causing many security...  

5 Architecture Issues that Impact BES performance
This Live webinar will identify critical log file errors, performance counters, and configurations to pay close attention to when optimizing BES server performance....

Case Study: The Ritz London
Discover how the superior capabilities of Webroot E-mail Security SaaS allows user to focus on their principal tasks instead of wasting their time...  

Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....

Case Study: Richmond Ambulance Authority (RAA)
In this case study, find out how Webroot Web Security SaaS delivers the proactive web security RAA needs....  

The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....