Subscribe to Windows IT Pro
June 10, 2004 12:00 AM

New Adware Scheme Takes Advantage of IE Vulnerabilities

Windows IT Pro
InstantDoc ID #42953
Rating: (0)

A malicious adware creator is taking advantage of two vulnerabilities in Microsoft Internet Explorer (IE) to surreptitiously install adware products and pop-up ad generators on users' computers as they browse the Web. The flaws, which let attackers run code on victims' machines and let malicious code bypass IE's security zones, were only recently discovered. 
  
"We consider that any use of an exploit to run a program is a criminal use," Microsoft Security Program Manager Stephen Toulouse said. "We are going to work aggressively with law enforcement to prosecute individuals or companies that do so." Toulouse said that the company is now working with the Federal Bureau of Investigation (FBI) to track down the culprits and that Microsoft will likely issue an IE patch to fix the problem soon instead of waiting for next month's regularly scheduled batch of security fixes.
  
Although reports vary, the malicious code apparently installs an ILookup search toolbar that changes IE's home page and connects to adware-related sites, generating pop-up windows and, occasionally, even desktop shortcuts. The effects are similar but not identical to the behavior I saw during a recent Trojan attack, which I've documented in three parts in Windows & .NET Magazine UPDATE (see the links below). In my case, my machine was infected after I inadvertently turned off Windows Firewall in Windows XP Service Pack 2 (SP2) and used Google to search for video game hints. One of the pages that came up in the Google search results loaded the offending code.

Still Waiting for a Truly Secure System

Details About the Trojan Attack 

My Trojan War Becomes a Quagmire

Related Content:

ARTICLE TOOLS

Comments
  • C. F. Bernard
    8 years ago
    Jun 15, 2004

    I hope Wendy read Paul's comments today: "Also, based on feedback from several readers, I'm going to reinstall XP on my main desktop PC, take it off the domain, and try to live with a non-Administrator account on a nonmanaged box. I've been told by a number of people that this process is a lot less painful than it used to be, and I've frankly not tried it in a while, so I'll give it a shot."


    When installing software that was unwisely designed to require elevated permissions to run:

    Sign on with a local administrator account to change the account you use regularly from a User to an Administrator via Control Panel - Users and Passwords.
    Log on to your regular account that now has Administrator privileges.
    Run a (free) program such as InstallWatch or InstallRite
    http://www.epsilonsquared.com/ to record the changes made to the registry during the istallation.
    Install the desired software.
    Use regedt32's Security menu - Permissions to give your regular account Full Control to the desired program's registry branches.
    You may need to use Windows Explorer to likewise give Full Control to the program's folders.
    Set the account back to User via Control Panel - Users and Passwords.

    For surfing, you may want to install the latest version of Mozilla Firefox http://mozilla.org/ and set it as the default browser. Only use IE for the sites that were unwisely designed to work only in IE.

    Also, give a much needed security zone fix to IE with the free Qwik-Fix utility from PivX Solutions http://www.pivx.com/qwikfix/index.html

  • jonathan
    8 years ago
    Jun 14, 2004

    Without calling anyone dead right or dead wrong, Wendy, it ultimately comes down to what things you need to do when you are logged into Windows. The average user does not need to do administrative stuff very often on their system; thus, they should be using a restricted account. Even as a developer, I use a limited account for all my day to day work. I always keep a command prompt window open, which I started with RunAs, using my administrative account. To install setup files or do other things as an admin, I just enter it from this command prompt. Rarely do I actually ever log into Windows using the admin account.

    I will say that Paul has a valid point: It is true that many applications are ignorant of rights. This is an unfortunate consequence of the long, wide-spread use of Windows 9x, in which everyone is always an administrator. The concept of different user types and privileges has been around since NT 3.1; it is now up to ISVs to create applications that work properly in these secure environments.

    Rather than always run as Admin to appease these applications, run as a limited user and then run only these specific apps as Admin. I mean, if you have an app that needs to connect to the internet, do you disable your entire firewall or do you just open the specific ports to the specific application?

    Regarding XP Home Edition's "crippled" limited user account: It is what I use to do all my web surfing, email, and even all of my programming. It doesn't provide the granularity in user permission like XP Pro, because the average home user doesn't need this.

    Microsoft has done a lot to encourage developers to focus on "least privilege" when writing their apps, so that they work in limited accounts. Unfortunately though, Microsoft has not been educating home users to use limited accounts for their non-admin activities.

    Windows also needs to be like OS X by allowing a limited user to seamlessly switch to the admin account (via password) on demand when accessing an admin feature. Currently, Windows does prompt when you run a program named "Setup.exe", "Install.exe", etc., but it needs to go further.

    The NT security model provides a lot of protection when you use a limited account. You don't see Unix/Linux users doing all their work (including web browsing) as root. Yes, it may take some getting used to, but limited accounts really do protect you.

  • stephen
    8 years ago
    Jun 12, 2004

    I've been surfing with the 'Internet zone' set to High+ for years. When I feel that I must view a site at a lower setting I put it in my Trusted sites. However, my Trusted zone is not the default level, rather it's set at Medium+. I just got tired of all the c**p that scripting and ActiveX enables .. so I surf without it. Scripting is a great thing but only in the hands of responsible people.

  • Graeme Evans
    8 years ago
    Jun 12, 2004

    WWW.OPERA.COM no exploits no activex junk no popups why bother with ie????????

  • Vadim
    8 years ago
    Jun 12, 2004

    There will be no truly secure system ever, and efforts in that direction are mostly waste of time, Sisyphus' effort. If you rely in the protection of your home only on perfect locks and doors, while there's no police in your town, you will be robbed anyways. Microsoft is on the right track taking it to the law enforcement. Same should be done about all that incredible flow of fraud that comes as spam.

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.