News Radio WOAI KTKR AM Sports
SpursReport.com  
Go Back   SpursReport.com > SpursReport Fan Forums > The Cantina

  #1  
Old 07-21-06, 05:40 PM
TexasPandaMama's Avatar
SpursReport Team Bench
 
Join Date: May 2006
Location: Stuck in the house..... for what seems like forever!
Posts: 1,021
Myspace Banner Ad infects millions of users

MySpace Banner Ad Infects Million Users
Walaika K. Haskins, newsfactor.com
Fri Jul 21, 12:28 PM ET

A banner advertisement posted on the MySpace Web site may have infected more than one million users with adware, according to security firm iDefense. The advertisement was included in user profiles on MySpace and could have been operating for about one week.


The deckoutyourdeck.com advertisement exploited a flaw in the way Microsoft's Internet Explorer (IE) browser handles Windows Metafile (WMF) image files. Users running unpatched versions of IE would never have realized that the banner ad had silently installed programs that generate pop-up ads on their system.

"This is a criminal act," said Hemanshu Nigam, chief security office at MySpace, in a statement. "This ad is being delivered by ad networks who distribute these ads to over a thousand sites across the Internet in addition to ours. We are working to have these ad networks remove this ad so that they do not appear on our site."

Banner Patch

An iDefense spyware analyst, Michael La Pilla, told The Washington Post that he discovered the attack on Sunday as he browsed the MySpace site. When he came across a page with the offending ad, he received a message from his browser asking him if he wanted to open a file named exp.wmf.

After a brief investigation, La Pilla found out that the spyware installation program contacted a Russian-language Web server in Turkey that tracks the PCs on which the program has been installed. The tally had climbed to 1.07 million machines, though La Pilla said the seven Internet addresses contacted by the downloader seem to be inactive now.

According to La Pilla, the ad also attempted to infect users of Webshots.com, a photo-sharing site. Though he cannot pinpoint the date the ads began sending out their spyware, it is believed that it coincided with the occurrence on MySpace on July 12.

The WMF vulnerability was originally discovered last December after hackers exploited the flaw using a specially created WMF image distributed via e-mail, instant message links, and Web sites. When users opened the image, the hacker could take control of the infected PC. Microsoft released a patch for the bug back in January, but many people did not install the patch.

PCs with unpatched systems can become infected simply by accessing a Web page with the deckoutyourdeck.com ad. The exp.wmf Trojan horse program could upload automatically without the warning prompt that La Pilla received.

Once installed, PCs running the Trojan horse will contact multiple Web sites and download a slew of unwanted programs such as PurityScan advertising software. PurityScan is an adware program that can cause pop-up windows containing unsolicited ads to appear. The application also keeps track of the user's online activity.

Two Wrongs

Rob Ayoub, an analyst at the research firm Frost & Sullivan, said two facts stand out regarding the MySpace infections. First, home users are clearly not as educated about the need to make sure they have up-to-date patches and other security fixes installed. Second, MySpace needs to have a better security system to identify dangers hidden in the ads they serve.

If you are a legitimate business with a legitimate Web site hosting banner ads, you have a responsibility to keep the service clean, Ayoub said. "MySpace has some problems and this is a real blunder on their part. I can't believe any business would not scan or take more caution with banner ads posted on their sites. Ad network or not, there is no excuse for them not having a checking system."

One million people is a very large number, Ayoub said, and it demonstrates that the technology industry, and security firms and software makers in particular, might not have done enough to impress upon home users the importance of downloading patches. PCs that have not been updated exponentially increase problems with viruses, spyware and adware.

"MySpace should have been checking and users should have been patching," Ayoub said. "And because of that combination you have a million downloads."

Some PC users have said their reluctance to install patches and updates centers around the fear that any changes will negatively impact their computers. However, Ayoub pointed out, unwanted changes or problems with updates is relatively rare these days.

"There was a time when you had to watch and be very careful with your patches," Ayoub said. "And some of the big ones are a problem, but there haven't been big problems with patches for ages."

Home users, Ayoub predicted, will not start to take security seriously until Internet service providers start to make antivirus and antispyware software compulsory. That may or may not be the best solution, he said, but incidents like this are a "perfect storm" for users not protecting themselves.

"That's extremely dangerous," Ayoub said. "Maybe what we need to do is run public service announcements."

MySpace is "strongly" urging all Internet users to "follow basic Internet security practices such as running the latest version of the Windows operating system, installing the latest security patches, and running the latest anti-spyware and anti-adware software."
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2  
Old 07-21-06, 05:49 PM
MomBear's Avatar
MomBear
Guest
 
Posts: n/a

son of a
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3  
Old 07-21-06, 05:59 PM
Jason R's Avatar
SpursReport Staff Writer
 
Join Date: Apr 2004
Location: San Antonio
Posts: 10,012

Suck it MySpace.

And given the underage use of that network I'm betting that there are a ton of kids with unpatched IE that are now suffering from adware created slowdown.
__________________
Matt Bonner gets indigestion when swallowing his pride.
You can't divide by zero, but Matt Bonner can.
Matt Bonner and Chuck Norris only ever met once... that was the day dinosaurs went extinct.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4  
Old 07-21-06, 06:00 PM
braeden0613's Avatar
SpursReport Team Bench
 
Join Date: Apr 2003
Location: San Antonio
Posts: 2,001

Im glad i use firefox
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5  
Old 07-21-06, 06:02 PM
SimTek's Avatar
SpursReport Team Bench
 
Join Date: Sep 2002
Location: Pen Island
Posts: 1,244

Quote:
Originally Posted by braeden0613
Im glad i use firefox
I'm glad I make my kids use firefox too.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6  
Old 07-22-06, 11:39 AM
fakemxcan's Avatar
SpursReport Team Member
 
Join Date: May 2006
Location: AUWWWSTIN TEXAS BABY!!
Posts: 698

Quote:
Originally Posted by braeden0613
Im glad i use firefox
Quote:
Originally Posted by SimTek
I'm glad I make my kids use firefox too.
ya for real, im glad someone came up with the IDEA of firefox
__________________
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7  
Old 07-22-06, 04:22 PM
DizzG's Avatar
SpursReport Team Veteran
 
Join Date: Feb 2000
Location: In front of my laptop
Posts: 50,407

Dump IE and you wont have to worry about these things that attack IE
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8  
Old 07-22-06, 06:45 PM
Angel Face^i^'s Avatar
SpursReport Team Starter
 
Join Date: Oct 2002
Posts: 4,407

Quote:
When he came across a page with the offending ad, he received a message from his browser asking him if he wanted to open a file named exp.wmf.
ahh I wondered what that was. I kept getting the same thing and luckily noticed it before accidentally clicking it. I had never seen that before. I swear, ever since I got on that thing I've gotten up to 15 viruses and tons of spyware. A friend of mine warned me against it. I used to never want to get on myspace until a friend took it upon themselves to make me a page. I keep up with it now to keep in touch with people but all that virus/spyware crap gets annoying. I've started to use Firefox for it too.
__________________
Every step that you make, could be your biggest mistake.
It could bend or it could break, but that's the risk that you take.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9  
Old 07-22-06, 06:51 PM
Grego's Avatar
SpursReport Team Veteran
 
Join Date: Feb 2003
Location: Los Angeles, CA
Posts: 17,569

Myspace is so poorly put together, it's not even funny...... oh well.....
__________________
UCLA!!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10  
Old 07-23-06, 12:25 PM
DizzG's Avatar
SpursReport Team Veteran
 
Join Date: Feb 2000
Location: In front of my laptop
Posts: 50,407

This isnt the fault of myspace. it came from the ad networks they subscribe too

this same exact ad in question has caused people problems on a UT site I post on. Its part of an ad network that serves thousands of different sites

just like some ads have caused problems on SR.com. Its the ad networks...not the websites themselves trying to do this to people
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #11  
Old 07-23-06, 05:47 PM
Ducks's Avatar
SpursReport Team Veteran
 
Join Date: Mar 2001
Location: Yuma, Az USA
Posts: 10,849

spursreport.com uses ad network

it really is not myspace fault
xp usually reminds people to to the windows updates


why can not bill gates make an ie right the first time though
__________________
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #12  
Old 07-23-06, 06:53 PM
Grego's Avatar
SpursReport Team Veteran
 
Join Date: Feb 2003
Location: Los Angeles, CA
Posts: 17,569

Quote:
Originally Posted by DizzG
This isnt the fault of myspace. it came from the ad networks they subscribe too

this same exact ad in question has caused people problems on a UT site I post on. Its part of an ad network that serves thousands of different sites

just like some ads have caused problems on SR.com. Its the ad networks...not the websites themselves trying to do this to people
I know its not myspace's fault. That doesn't hide the fact that the site is put together pretty crappy. Defintely not gainning members because of its web design.. Goggle def was smart to avoid buying myspace when they had the opportunity.
__________________
UCLA!!

Last edited by Grego; 07-23-06 at 06:55 PM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #13  
Old 07-23-06, 11:18 PM
braeden0613's Avatar
SpursReport Team Bench
 
Join Date: Apr 2003
Location: San Antonio
Posts: 2,001

Quote:
Originally Posted by Grego
I know its not myspace's fault. That doesn't hide the fact that the site is put together pretty crappy. Defintely not gainning members because of its web design.. Goggle def was smart to avoid buying myspace when they had the opportunity.
Yeah and it crashes all the time (cant get on right now) and is painfully slow
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #14  
Old 07-24-06, 12:45 AM
usckk's Avatar
SpursReport Rookie
 
Join Date: Jul 2005
Posts: 180

Well, California had a power outage today, so that's why it's down today. But I do have to agree. I have problems logging on all the time.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #15  
Old 07-24-06, 01:21 AM
JamesR's Avatar
SpursReport Team Veteran
 
Join Date: Jun 2003
Posts: 17,799

Hint: Move the servers OUT OF FRICKEN CALIFORNIA!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #16  
Old 07-24-06, 02:42 AM
Grego's Avatar
SpursReport Team Veteran
 
Join Date: Feb 2003
Location: Los Angeles, CA
Posts: 17,569

Quote:
Originally Posted by JamesR
Hint: Move the servers OUT OF FRICKEN CALIFORNIA!
Actually that is fine. What you do is add more servers in other states. Diversify! Not like they don't have the funds to do it.
__________________
UCLA!!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -5. The time now is 08:41 PM.


Powered by vBulletin Version 3.7.4 Copyright © 2000-2008 Jelsoft Enterprises Limited.

Content Relevant URLs by vBSEO 3.2.0