WHIR | BLOGS | WEB HOST NEWS | FIND WEB HOSTS | RESELLER HOSTING | MAGAZINE | WHIR TV | NEWSLETTER | rss feeds
web hosting news - daily web host interviews, insight Jobs | Events | Sitemap | Search
Green Data Center Info


WEB HOSTING NEWS | BLOGS | INTERVIEWS | EUROPE | EVENTS | WEB HOSTING JOBS

<< PacHosting Hosts BlackBerry Email     Web Host Webair Offers CDN Services >>


IE Feature Causing Malware

By Justin Lee, theWHIR.com

June 27, 2008 -- (WEB HOST INDUSTRY REVIEW) -- An online security researcher has found a drive-by malware download that exploits an Internet Explorer feature to launch cross-site scripting attacks, according to a report by ZDNet (blogs.zdnet.com/security/?p=1361).

   
DataPipe’s high-value managed global IT services help thousands of businesses decrease CAPEX, OPEX, & risk while increasing overall service levels. Partner with DataPipe – Improve your ROI - Extend your IT resources

Roel Schouwenberg, an analyst at Kaspersky Lab (kaspersky.com), detected the attack at a compromised legitimate site, is using a modified GIF file to exploit the cross-site scripting feature/vulnerability.

Schouwenberg said he notified Microsoft of the flaw when a similar attack occurred a while ago on a lower traffic site. He told Microsoft that the JavaScript embedded into GIF files can be executed under certain circumstances. 

Microsoft, however, disagreed with his findings, and he said the vulnerability went unfixed.

The most recent attack took place on a high traffic website, where a GIF file with an embedded iFrame redirects IE users to a known malicious site. 

Although the malicious site in question is currently offline, Schouwenberg says there is proof that the site is involved in ID-theft attacks. He says that the advanced malicious site is difficult to detect because the view source does not show any trace of malicious code.

Schouwenberg has once again contacted Microsoft about this most recent attack, asking the software firm to take another look at the problem.

Print this Page       Email this Page        Add to: | del.icio.us | digg


COMMENTS

Be the first one to comment on this article. Click the link below to post your comment.

[POST COMMENT]



Q&A: Jim Lewandowski, Rackspace

Q&A: Clint Poole, Brinkster

New Features in Parallels Plesk 9

Q&A: James Bond, Apptix

Noise Filter: McColo Taken Down

Wowza Offers Friction Free Flash

Sun Battles for Greenest Data Center

More feature interviews and reports
 

Go Daddy Ads in the Grey Cup

Video Interview with Vinay Nagpal, Tata Communications

Copywriting for Direct Mail - Part 2: Big Guns

What Exactly is Semi-Dedicated Hosting?

Own your own jet

MLB.com switches to Flash; Hosting and Video Streaming Questions

More posts from our Bloggers


NameCheap Launches Twitter Promo

CBS Web Site Faces Malware Hack

VineyardHosting Limits Eternal Hosting

Email Use Increases As Economy Slows

HostNine Re-Launches New Website

SoftLayer Sponsors MSDN Conference

Hosting Sales and Promos Roundup

SoftLayer Shows Continued Growth

Microsoft Named on Spam Host List

3FN Ups Hardware Swap Capability

ZNet Brings Hyper-V VPS to India

Black Friday Causes Shutdowns


 

Marketing/Sales Trainer

Sales Operator

Management Trainer

Senior Account Manager, Dedicated Hosting

Sales Executive

Senior Accounting Analyst

Technical Solutions Engineer

Product Manager

Account Manager

Ajax Experienced Developer

 

SPONSORED LINKS
> Apollo Hosting: Award Winning Website Hosting from $6.96 – Click Here!

> iWeb: Quality servers. 3000GB of traffic for only $69

> TopLayer: SC Mag Recommended. Protect against DDoS Attacks & more.

> Parallels: Automation and Virtualization. Buy ONLINE or Learn MORE!

> Rackspace: What Do You Get With Your Hosting Provider?

> Verio: Get Email Anywhere w/ Hosted Exchange $11.95/mo, 2 Mo Free

> IronScale: Why Rack? Automate with IronScale Managed Hosting

> Learn more about the greening of the data center here.

> Is your company hiring? Post your job listing here!

> Get your company listed in our annual Buyer's Guide magazine issue - Deadline: Dec 31

WHIR NEWSLETTER SIGN-UP | MANAGE SUBSCRIPTIONS | WHIR RSS FEEDS
Name:
Email:
Password:
theWHIR Blog Email Update
Magazine
Daily News
Find Web Hosts
Occupation:
Company Type:

Find Web Hosts | Reseller Hosting | Personal Web Hosting | Small Business Web Hosting | Dedicated Servers | Managed Hosting | Adult Web Hosting


About WHIR | Online Advertising | Print Advertising | Print Subscription | Email Newsletters | RSS Feeds
 
Submit News | Privacy Policy | Buy Reprints

Web Host Industry Review, Inc. is not responsible for the content of comments submitted by our users.

  © Copyright Web Host Industry Review, Inc.