Monday, July 24, 2006

Hacked Ad Seen on MySpace Served Spyware to a Million - Security Fix

I mentioned, in the chat during the show yesterday, WAY TOO MANY people being caught by a 6 [or so] month old fixed exploit. I found the link to this article about the exploit:

An online banner advertisement that ran on MySpace.com and other sites over the past week used a Windows security flaw to infect more than a million users with spyware when people merely browsed the sites with unpatched versions of Windows, according to data collected by iDefense, a Verisign company.

Michael La Pilla, an iDefense "malcode" analyst, said he first spotted the attack Sunday while browsing MySpace on a Linux-based machine. When he browsed a page headed with an ad for DeckOutYourDeck.com, his browser asked him whether he wanted to open a file called exp.wmf. Microsoft released a patch in January to fix a serious security flaw in the way Windows renders WMF (Windows Metafile) images, and online criminal groups have been using the flaw to install adware, keystroke loggers and all manner of invasive software for the past seven months.

--MissM
Hacked Ad Seen on MySpace Served Spyware to a Million - Security Fix

tip o' the hat to Schneier on Security for the article.

No comments:

Post a Comment

All comments are moderated.

Note: Only a member of this blog may post a comment.