November 22, 2004 3:50 PM PST

Attackers strike using Web ads

Online intruders breached the security of at least one server at advertising host Falk this weekend and used the computer to distribute an attack to the service's clients, including The Register, a technology news and opinion site.

Both Falk and The Register confirmed details of the attack, which infected some users' systems on Saturday morning. The problem was later corrected, Falk said. The attack used a recently discovered flaw in Microsoft's Internet Explorer 6 that has not yet been patched.

The attack used banner ads to infect victims' computers. According to security company Lurhq, the program, when viewed as an advertising banner, executes some fancy Internet footwork to jump to three other Web sites, further infecting the victim's computer at each step. Once compromised by the program, an infected system will allow an attacker to install additional programs.

"The attackers were not targeting...The Register," said Marcus Sachs, director of the Internet Storm Center, a network-monitoring group funded by the SANS Institute. "It just happens. If you did not have updated antivirus, you could have been hit by it."

The attack exposed, for the second time this year, the danger posed by insecure Web services. In June, an attack that similarly used a flaw in Internet Explorer was posted to several Russian sites. By exploiting a centralized advertising hosting service with insecure servers, the latest attack found a way to spread more widely.

Advertising hosts generally serve up banner advertisements to their Web site clients. What may seem like a banner, however, can easily contain malicious code, which is what happened when attackers breached the security of one of the servers at Falk, the company said.

"This attack made use of a weak point on this specific type of load balancer," Falk said in a statement. "The function of a load balancer is to evenly distribute requests to the multiple servers behind it. The system concerned was only used to handle a specific request type to our ad server and has now been investigated."

The attack is not a virus, because once it infects a user's system through Internet Explorer, the program will not spread further. However, many reports confuse the Internet Explorer vulnerability, referred to as the iFrame vulnerability, and the Bofra virus, which has used the flaw to spread. Bofra was originally referred to as a variant of the MyDoom virus. Security company Lurhq referred to the latest attack as Trojan.Agent.EC.

"The (program) was originally introduced to our European network, where it was first detected," Falk said in a statement. "As of 11:30 a.m. GMT (3:30 a.m. PST Saturday), the virus was removed from all Falk European and U.S. networks, and normal ad delivery was restored.

The Register blocked banner advertisements during the incident and said it does not plan to resume the service until Falk can make assurances regarding the security of its ads.

"We have asked Falk for an explanation and for further details of the incident, and pending this we do not intend to restart ad-serving via the company," The Register said in a statement. "Although the matter was beyond our direct control, we do not regard it as acceptable for any Register reader to be exposed in this way."

Microsoft pointed out that the attack will only infect PCs with Internet Explorer 6 installed, and which don't have the Service Pack 2 update.

"Microsoft is working to forensically analyze the malicious code in Bofra and will work with international law enforcement to identify and bring to justice those responsible for this malicious activity," the company said in response to the Falk attack. "Microsoft is taking this vulnerability very seriously; accordingly, an update to correct the vulnerability is currently in development."

A representative of Microsoft, which has offered rewards for leads on virus attacks in the past, would not comment on whether the company plans to offer a reward for the leads to Falk's attacker or those responsible for the Bofra virus.

See more CNET content tagged:
Bofra worm, banner advertisement, LURHQ Corp., attacker, Microsoft Internet Explorer 6

Add a Comment (Log in or register) 4 comments
So, Non XP PCs are open to infection
by 203129769353146603573853850462 November 22, 2004 4:14 PM PST
Since only those having XP SP2 are protected, more than 50% of the world is open to infection right?

MS's answer? upgrade to Xp. No doubt.
My answer? Exit IE, Firefox here I come.
Reply to this comment View all 2 replies
Banner bashing of browser
by Sonny Lyon November 22, 2004 6:46 PM PST
The real bad person here is not the hacker...its the browser builder who after years of having a product will not secure it for all users
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly-written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    In NFL deal, an extra point for Adobe's Flash

    Football fans will get to see live streaming of NBC's Sunday night games via Flash--not NBC's Olympic teammate, Silverlight.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Webware

    At the TechCrunch50, an unfair advantage?

    Inside baseball: How Webware and other blogs can compete with TechCrunch in covering the TechCrunch50 event.

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.