Feeds

Watch out! Incoming mass hack attack

We're all doomed! Doomed!

  • alert
  • submit to reddit

The essential guide to IT transformation

Security experts have expressed serious concern about recently-discovered flaws in Internet Explorer that seem to be the focus of an insidious attack.

Many popular websites, including search engines and shopping sites, have been secretly hacked and have had mysterious code placed on their Web servers. When a user running Internet Explorer logs on to a contaminated site, the user's PC is infected with malicious code, which has the potential to cause further problems.

The exact nature of the problem is unclear, although experts within many of the world's top e-security firms, as well as the SANS Institute and the US Department of Homeland Security, have acknowledged that something is amiss.

Backdoors are opened on infected PCs and key-logging software is also installed, allowing the creators of the code to steal passwords, PIN numbers and credit card details. According to some analysts, the hackers behind the malware are actually loading computers with so-called "adware" or "spamware" software that can push unwanted ads to users or steal personal data for the purpose of spam emailing.

Of course there is always the possibility of an enormous Distributed Denial of Service (DDoS) attack, once enough computers are converted into zombies. But this is thought to be unlikely.

"This is what everyone has been really frightened about for a while now," said Conor Flynn, technical director with Rits Information Security in Dublin. The fear is rooted in the fact that there is no patch from Microsoft for the flaws, nor is there any indication that a patch is on the verge of being released. Though the virus-like infection rate remains low, experts like Flynn say the matter could become a more serious problem unless a fix is released soon. "There is no question that this one could be devastating," he said.

The perpetrators could be spammers, one of the few groups to have made money from hacking. They me from Eastern European or Russian-organised crime gangs, as the "high quality" code that infects websites redirects browsers to Russian-based Web servers.

For website proprietors, the best defence is to ensure that Web servers are fully patched and guarded against all attacks - particularly those running Internet Information Server (IIS), which seems to be a favourite of attackers due to previously-revealed vulnerabilities.

Home users, meanwhile, should shut down options like ActiveX on Internet Explorer, which is a mechanism used by malicious code to upload onto PCs. Or you could always switch to Opera, Safari, Netscape or Mozilla, Internet Explorer's rival browsers.

© ENN

Related stories

When spyware crosses the line
Browser-based attacks on the up
IE flaw exposes weakness in Yahoo! filtering
MS drop authentication technique to foil phishing
MS alerts users to Windows DirectX vulnerability

Next gen security for virtualised datacentres

More from The Register

next story
Ice cream headache as black hat hacks sack Dairy Queen
I scream, you scream, we all scream 'DATA BREACH'!
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
New Snowden leak: How NSA shared 850-billion-plus metadata records
'Federated search' spaffed info all over Five Eyes chums
Three quarters of South Korea popped in online gaming raids
Records used to plunder game items, sold off to low lifes
Oz fed police in PDF redaction SNAFU
Give us your metadata, we'll publish your data
prev story

Whitepapers

5 things you didn’t know about cloud backup
IT departments are embracing cloud backup, but there’s a lot you need to know before choosing a service provider. Learn all the critical things you need to know.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Backing up Big Data
Solving backup challenges and “protect everything from everywhere,” as we move into the era of big data management and the adoption of BYOD.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?