This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

MySpace Banner Ad Infects Million Users

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://news.yahoo.com/s/nf/20060721/bs_nf/44765
July 21, 2006
"A banner advertisement posted on the MySpace Web site may have infected more than one million users with adware, according to security firm iDefense. The advertisement was included in user profiles on MySpace and could have been operating for about one week. The… advertisement exploited a flaw in the way Microsoft's Internet Explorer (IE) browser handles Windows Metafile (WMF) image files. Users running unpatched versions of IE would never have realized that the banner ad had silently installed programs that generate pop-up ads on their system… An iDefense spyware analyst, Michael La Pilla, told the (Washington) Post that he discovered the attack on Sunday as he browsed the MySpace site. When he came across a page with the offending ad, he received a message from his browser asking him if he wanted to open a file named exp.wmf. After a brief investigation, La Pilla found out that the spyware installation program contacted a Russian-language Web server in Turkey that tracks the PCs on which the program has been installed. The tally had climbed to 1.07 million machines, though La Pilla said the seven Internet addresses contacted by the downloader seem to be inactive now… Though he cannot pinpoint the date the ads began sending out their spyware, it is believed that it coincided with the occurrence on MySpace on July 12. The WMF vulnerability was originally discovered last December after hackers exploited the flaw using a specially created WMF image distributed via e-mail, instant message links, and Web sites. When users opened the image, the hacker could take control of the infected PC. Microsoft released a patch for the bug back in January, but many people did not install the patch. PCs with unpatched systems can become infected simply by accessing a Web page… The exp.wmf Trojan horse program could upload automatically without the warning prompt that La Pilla received. Once installed, PCs running the Trojan horse will contact multiple Web sites and download a slew of unwanted programs such as PurityScan advertising software. PurityScan is an adware program that can cause pop-up windows containing unsolicited ads to appear. The application also keeps track of the user's online activity…"

(Screenshots available here: http://blog.washingtonpost.com/securityfix…ware_to_mo.html )

:ph34r:
FYI…

- http://blog.washingtonpost.com/securityfix…ware_to_mo.html
Update - July 20, 6:21 p.m. ET: Hemanshu Nigam, Myspace.com's chief security officer, issued the following statement in response to these attacks:
"This is a criminal act. This ad is being delivered by ad networks who distribute these ads to over a thousand sites across the Internet in addition to ours. We are working to have these ad networks remove this ad so that they do not appear on our site. At the same time we strongly urge all Internet users to follow basic Internet security practices such as running the latest version of the Windows operating system, installing the latest Windows security patches, and running the latest anti-spyware and anti-adware software. If users have applied the simple patch available from Microsoft.com, they will not be vulnerable to this criminal act."

:rant2: :ph34r: