IE flaws open back door to adware

NEWS An adware purveyor has apparently used two previously unknown security flaws in Microsoft's Internet Explorer browser to install a toolbar on victims' computers that triggers pop-up ads, researchers said this week.

One flaw lets an attacker run a program on a victim's machine, while the other enables malicious code to "cross zones," or run with privileges higher than normal. Together, the two issues allow for the creation of a Web site that, when visited by victims, can upload and install programs to the victim's computer, according to two analyses of the security holes.

The possibility that a group or company has apparently used the vulnerabilities as a way to sneak unwanted advertising software, or adware, onto a user's computer could be grounds for criminal charges, said Stephen Toulouse, security program manager for Microsoft.

"We consider that any use of an exploit to run a program is a criminal use," he said. "We are going to work aggressively with law enforcement to prosecute individuals or companies that do so."

Microsoft learned of the issue when a security researcher posted an analysis of the problem to the Full Disclosure security mailing list on Monday. The software giant has already contacted the FBI and is in the "early stages" of building the case, Toulouse said. The company is considering creating a patch quickly and releasing it as soon as possible, rather than waiting for its usual monthly update.

The flaws are apparently being used to install the I-Lookup search bar, an adware toolbar that is added to IE's other toolbars. The adware changes the Internet Explorer home page, connects to one of six advertising sites and frequently displays pop-ups -- mainly pornographic ads, according to an adware advisory on antivirus company Symantec's Web site.

On Tuesday, security information group Secunia released an advisory about the problem, rating the two flaws "extremely critical."

"Secunia has confirmed the vulnerabilities in a fully patched system with Internet Explorer 6.0," the group wrote. "It has been reported that the preliminary SP2 (a major security update being developed by Microsoft) prevents exploitation by denying access."

The flaws could let any attacker with a Web site send an email message or an instant message with a link that, when clicked on by an Internet Explorer user, would cause a program to run on that victim's computer.

The original analysis, written by a Netherland student researcher, Jelmer Kuperus, who found that the type of programming needed to take advantage of at least one of the flaws required sophisticated knowledge of the Windows operating system.

"While sophisticated, it's so easy to use, anyone with basic computer science can set up such a page, now that the code is out there in the open," Kuperus wrote in an email interview with ZDNet UK sister site CNET News.com. "It's just a matter of changing two or three (Internet addresses) and uploading another" executable file.

Kuperus, who used an email account based in the Netherlands, wrote in an email on Monday that he had been tipped off to the adware Trojan horse by an unnamed individual.

"Being rather sceptical, I carelessly clicked on the link only to witness how it automatically installed adware on my PC!" he wrote.

The Internet address from which the adware Trojan horse was downloaded resolves to I-Lookup.com, a search engine registered in Costa Rica that antivirus firms Symantec and PestPatrol have linked to aggressive advertising software. Two of the top three searches on the site relate to removing such programs, according to I-Lookup.com's own statistics.

A domain name search shows i-Lookup.com's parent company to be Aztec Marketing, but Pest Patrol links the site with iClicks Internet. Emails sent to both companies for comment were not immediately answered.

Kuperus believes that i-Lookup.com's parent company may not be directly responsible for the adware-installing Trojan horse program, but that it could be rewarding the creator through an affiliate program.

"It does pass along a referrer code when downloading," he said. "Whomever created this probably is getting money for every install, so if the folks at (i-Lookup.com) would be willing, they would be able to track down the perpetrators."

Microsoft's Toulouse said Internet Explorer users could harden the software against such attacks by following instructions on the company's site. Other browsers available on Windows, such as Opera and Mozilla, do not contain the flaws.

Talkback

This happened to my computer, not sure what i clicked on that opened it but it installed the search bar and I cant remove it after a million aimless attempts. It doesn't allow me to remove it from add/remove programs because its NOT listed there. There isnt a name for it when I open it up but when I right click on it, it shows me it is called Intelligent Explorer, or realbar. I'm not sure if this is even the same one but it is extremily aggrivating to have something there that shouldnt normally be there. If anyone knows what this is, mind giving me some feedback? Thanks!

11 Jun 04 08:13 Reply

This happened to me last week and cost me a week's work. IE needs to be fixed NOW!!!! Norton Antivirus does not even detect the installed adware because it is an "Extended Threat". I had to manually remove everything. How sad is this?

15 Jun 04 17:56 Reply

This hit me June 13. I've been fighting it ever since. I've added a router, ZoneAlarm, an improved Norton AntiVirus, and I'm still fighting it.

The people who wrote this program should be shot, arrested, tried, convicted, and shot again.

17 Jun 04 13:11 Reply

Put a Linux box people and forget about viruses and backdoors

18 Jun 04 13:56 Reply

This toolbar forced me to switch to Mozilla Firefox, and have experienced no problems atl all since.

22 Jun 04 11:50 Reply

LOL

23 Jun 04 09:36 Reply

many years back, i had used microsoft windows 98 and microsoft had SECRETLY read ALL my documents WITHOUT MY PERMISSION.
why?????
it is a very big sin.
i pray everyday to the One and Only God to punish Microsoft some day and vanish from this world. and i hope it come sooner.
this shows the microsoft products are NOT SECURE AT ALL !!!!!!!!!!!!!!!!!!!!!!!!!!
from that day, i do not believe whatever microsoft "B.S." marketing is telling !!!!!!!!!!!!!!!!
and GOD, i had EXPERIENCED AND TIRED of doing the non-stop service packs, patches and other updates for microsoft products.

24 Jun 04 05:29 Reply

Get AD-aware from:
http://www.lavasoft.nu/
(freeware) and try with that.

25 Jun 04 09:21 Reply

Ever since my 11 year old son visited a 'warez' site we have been plagued with pop-ups. Nothing stops them. We've tried the lot - noadware - spybot S&D -ad-aware, whatever we do they just keep coming. I suspect that some hidden script has modified IE in some way, because the problem does not affect Firefox. There is no obvious toolbar or alteration to IE but I am as sure as I can be that it has been compromised. I would like to remove IE altogether and just use Firefox, or ideally, reinstall a more robust and less vulnerable IE.

31 Dec 04 11:00 Reply

Post your comment

In order to post a comment you need to be registered and logged in

Log in or create your ZDNet UK account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Membership FAQ

ZDNet UK Live

georgiox

love the LHC info. Keep up the good work. May God bless all in volved.

3 hours ago by georgiox on LHC to run for longest continuous period
sgardia

You are quite right. HDS has not been marketing their products well. USPV is miles ahead in terms of ease of use and technology on enterprise...

8 hours ago by sgardia on Will the SUN set on Hitachi Data Systems OEM relationship?
apexwm

Fedora is the same way as well. The yum update system uses "presto" which shrinks the amount of data needed for download. It's a great system....

19 hours ago by apexwm on Can you believe it - 2765 kB will be freed?
cybfor

Updated ID cards considered for 2012: [zdnet.co.uk] The government is considering introducing a new generation of ID... http://dlvr.it/KpBZ

cybfor

Google, Viacom trade blows in YouTube copyright spat: [zdnet.co.uk] Google and the US media giant Viacom have issued... http://dlvr.it/Knht

CIMITL

Be sure to include an audio option - eg. a beep tone - to intensify and reiterate the action. This will greatly benefit some consumers and give...

21 hours ago by CIMITL
DataSecurityUK

Data disposal is really important to get right. There are standards set by UK and US federal governments to ensure that data is kept secure. If...

21 hours ago by DataSecurityUK
chaycon1

Online Fiber Optic Certification Join a talented group of professionals, who are dedicated to Fiber Optic Networking technology. The online course...

23 hours ago by chaycon1 on BT launches 40Mbps fibre-based broadband
chaycon1

Online Fiber Optic Certification Join a talented group of professionals, who are dedicated to Fiber Optic Networking technology. The online course...

23 hours ago by chaycon1 on Google to build gigabit broadband to the home
J.A. Watson

Hi Dava, I'm glad to hear from you, and glad that you see things from the other side. I think that is the most important point of the whole...

24 hours ago by J.A. Watson on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

please please please please please please kill that spam bot.

24 hours ago by dava4444 on ZDNet UK: faster, smarter, still IT all the way
253chelisa253

hi

1 day ago by 253chelisa253 on How security will look in 10 years
lezlow

it is only greedy[microsoft]?

1 day ago by lezlow on Researchers break into BitLocker
dava4444

it didn't post the link it's 'Ubuntu 10.04 Lucid Lynx Beta-1 First Look' on youtube :) Dava

1 day ago by dava4444 on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

Hi James I disagree, Ubuntu needs a GUI update and this one IMO is quite good. your pics show a low res. here's a high res. on YouTube* The...

1 day ago by dava4444 on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

Hi any news on the comment bot? knocking me back from my own blog is a bit cheeky lol *Mulder to Scully* "I think it has an agenda.." I know, I...

1 day ago by dava4444 on ZDNet UK: faster, smarter, still IT all the way
benny boy

if you look at the Brentwood exchange on samknows it servers 21,000 residential propertiesm, Lowestoft serves 31,000! Come on BT sort yourselves...

1 day ago by benny boy on BT fibre broadband coming to 69 more towns
pbreddit

[programming] H.264 - a sting in the tail http://reddit.com/bfu4q [zdnet.co.uk]

reddit

H.264 - a sting in the tail [programming] 13 points, submitted by zigzag [zdnet.co.uk] http://reddit.com/bfu4q

cybfor

Malware infects second Vodafone HTC phone: [zdnet.co.uk] A second Android-based HTC Magic from Vodafone has been... http://dlvr.it/KhKx

Featured white papers

Achieving PCI Compliance for:Privileged Password Management & Remote Vendor Access

For multi-store outlets, including retail, banking, grocery, gas, hospitality, convenience stores and others, reducing (or avoiding) the cost of in-store system support and maintenance while maintaining compliance with PCI and other requirements has become a strategic challenge.

Download now

Web 2.0 Security Threats: How to Protect Your Enterprise Network

Speaker: Dr. Chenxi Wang, Principal Analyst, Security and Risk Management, Forrester Research, Inc. As Enterprises are increasingly connected to the Internet and as hard organizational boundaries are fast disappearing, security professionals are facing fresh challenges in Enterprise computing.

Download now

MindManager - Tutorial for New Users - Short

This tutorial is for new MindManager users and teaches you how to get started, by creating maps, reading maps and organizing your information.

Download now