Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Mainstream Web sites spreading back-door infections

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Latest Breaking News Donate to DU
 
teach1st Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-25-04 05:48 AM
Original message
Mainstream Web sites spreading back-door infections
Mainstream Web sites spreading back-door infections

http://news.zdnet.co.uk/internet/security/0,39020375,39158636,00.htm

Robert Lemos
CNET News.com
June 25, 2004, 08:40 BST

Surfers visiting trusted Web sites, such as banks and merchants, are falling victim to organised-crime groups that have exploited two Internet Explorer flaws to hide attacking code

Security researchers warned Web surfers on Thursday to be on their guard after uncovering evidence that widespread Web server compromises have turned corporate home pages into points of digital infection.

The researchers believe that online organised crime groups are breaking into Web servers, surreptitiously inserting code that takes advantage of two flaws in Internet Explorer that Microsoft has not yet fixed. Those flaws allow the Web server to install a program that takes control of the user's computer.

The extent of the attacks is unknown, but the security community has seen numerous cases of personal computers infected when the user merely visits a Web site.

More


Printer Friendly | Permalink |  | Top
ayeshahaqqiqa Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-25-04 06:04 AM
Response to Original message
1. Will a firewall help?
I've been on sites where my firewall has gone nuts and refused to let programs into my computer. Later I've found that those sites were ones with such programs. These were independent sites, though. Is the programming language being used by the criminals more sophisticated?
Printer Friendly | Permalink |  | Top
 
Renew Deal Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-25-04 06:15 AM
Response to Reply #1
4. Probably not.
You need to have anti-virus. A firewall will only really help with network based attacks (which these are), but anti-virus sees the infected code.
Printer Friendly | Permalink |  | Top
 
RC Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-25-04 06:05 AM
Response to Original message
2. So we read this and click on the provided link.... And???
:think:
Printer Friendly | Permalink |  | Top
 
teach1st Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-25-04 06:08 AM
Response to Original message
3. Running without a firewall is dangerous
Edited on Fri Jun-25-04 06:11 AM by teach1st
Here's what I wrote to the teachers on my web site so far. I haven't gotten to the firewall part, but zonealarm free does work. Perhaps others have further suggestions.

http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp

I recommend downloading and using an alternate browser (these have all evolved from Netscape):

http://www.mozilla.org/

My favorite is Firefox, but Mozilla is more popular overall.

If you don't use virus protection, do so now. Keep it updated - automatic updates are the best. My virus protection has updated itself a few times in the past twenty-four hours, probably in response to the alert above.

I use and recommend Trend's PC-Cillin for overall ease of use and effectiveness. I have used it for years and it's saved my butt a few times. The package also includes a firewall. Do the thirty day trial.

http://www.trendmicro.com/en/home/us/personal.htm

(Right on the front page: Trend Micro PC-cillin Internet Security)

You should also be using software to help you detect spyware. For many of you, cleaning up your computer with spyware detection software will speed up your computer tremendously. I bet more than 50% of you are already infected with some sort of spyware. The software below is free. These must be updated often to remain effective

Proactive (protects against spyware - make sure you do the full innoculate):

http://www.javacoolsoftware.com/

Reactive (scans for and cleans up spyware - I use both programs below, since each can catch what the other can't):

http://www.safer-networking.org/index.php?page=home
http://lavasoft.element5.com/default.shtml.en
Printer Friendly | Permalink |  | Top
 
dbt Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-25-04 06:50 AM
Response to Original message
5. Are these infections SPYWARE by any chance?
I have noticed a hell of an increase in these buggers over the past 90 days. There's one called Download.trojan that Norton can recognize but can do nothing about, for instance. Many more just sail past Norton AND a firewall, apparently. I had to use FIVE separate programs to get rid of all the spyware in just one box at work.

:argh:
dbt
Printer Friendly | Permalink |  | Top
 
teach1st Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-25-04 07:11 AM
Response to Reply #5
8. Macs are safe from this specific exploit, apparently
Edited on Fri Jun-25-04 07:12 AM by teach1st
The article says that Macs are unaffected.

Here's a recent DU Thread, "Mac OS X security myth exposed."

http://www.democraticunderground.com/discuss/duboard.php?az=show_topic&forum=105&topic_id=1320084

ON EDIT: POSTED IN WRONG SPOT. Sorry. This is in reference to POST 6. Need more coffee....
Printer Friendly | Permalink |  | Top
 
Bozita Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-25-04 07:15 AM
Response to Reply #8
9. Thanks, I skimmed and obviously missed it
Printer Friendly | Permalink |  | Top
 
Bozita Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-25-04 07:05 AM
Response to Original message
6. Article only mentions PCs -- Are Macs and Linux machines safe?
Printer Friendly | Permalink |  | Top
 
Tandalayo_Scheisskopf Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-25-04 07:56 AM
Response to Reply #6
13. Linux...
Laughs at these feeble attacks.

Why you people continue to run Redmond's PoS OS is beyond me. But do keep running it. I fix it and make money. I like making money.

Meanwhile, Linux is free.

Oh well, so much for today's logic exercise...
Printer Friendly | Permalink |  | Top
 
bemildred Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-25-04 08:59 AM
Response to Reply #13
14. Indeed. I run Mozilla on FreeBSD for this sort of thing.
Using MS OSes on the web is like putting a big target on your back.
(And, they are annoying to maintain too.)
Printer Friendly | Permalink |  | Top
 
catmandu57 Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-25-04 07:05 AM
Response to Original message
7. There's a tough one out there
coolweb it hijacks and misdirects, puts all kinds of nasty crap on your computer, it morphs so the fight is constant. If you go to http://www.merijn.com you can download tools to fight this bugger. Also you need to get spybot search and destroy, plus a firewall, but these people (probably republicans) just laugh at firewalls.
Thdere is a foreum designed to help with computer problems caused by crap like this, http//www.spywareinfo.com if you have problems you can go there and get help.
We need a world court to deal with this crap.
Printer Friendly | Permalink |  | Top
 
Media_Lies_Daily Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-25-04 07:38 AM
Response to Reply #7
12. Here's a better link, plus a ton of information on coolweb,....
...how it works, and how to get rid of it:

<http://www.spywareinfo.com/~merijn/cwschronicles.html>

I personally downloaded one of their tools called "CWShredder", because my browser had somehow gotten hijacked and was redirecting me to places I did not want to go. Now I use CWShredder every day without fail. As they recommend, check back for updates as often as you can. Here's the page that you can use to download CWShredder:

<http://www.spywareinfo.com/~merijn/cwschronicles.html#cwshredder>

Another tool that I use is Ad Aware because I have seen it pick up spyware that Spybot may miss, and vice versa:

<http://www.lavasoftusa.com/software/adaware/>

Go to the right-hand menu and click on the phrase "Our software" located right below the word "DOWNLOAD".

In case you want all of this information in one post, here is the link to Spybot Search & Destroy:

<http://spybot.safer-networking.de/>

Click on "Download" in the top menu bar.

Printer Friendly | Permalink |  | Top
 
missile_bender Donating Member (193 posts) Send PM | Profile | Ignore Fri Jun-25-04 07:22 AM
Response to Original message
10. Is Netscape safe?
Printer Friendly | Permalink |  | Top
 
teach1st Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-25-04 07:29 AM
Response to Reply #10
11. According to the article, yes N/T
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Tue Apr 23rd 2024, 05:24 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Latest Breaking News Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC