Back to Forums








View Full Version : Alternative browser spyware infects IE


egghead
March 12th, 2005, 19:22 PM
Some useful citizen has created an installer that will nail IE with spyware, even if a surfer is using Firefox (or another alternative browser) or has blocked access to the malicious site in IE beforehand. The technique allows a raft of spyware to be served up to Windows users in spite of any security measures that might be in place.

Christopher Boyd, a security researchers at Vitalsecurity.org, said the malware installer (http://www.vitalsecurity.org/2005/03/firefox-spyware-infects-ie.html) was capable of working on a range of browsers with native Java support. "The spyware installer is a Java applet powered by the Sun Java Runtime Environment, which allows them to whack most browsers out there, including Firefox, Mozilla, Netscape and others. In the original test, only Opera and Netcaptor didn't fall for the install but Daniel Veditz, who is the head of Mozilla security, has since confirmed to me that this will also work in Opera and Netcaptor," he explained.
\


http://www.theregister.co.uk/2005/03/11/alternative_slimeware/


lovely:eek:
egghead

rik
March 13th, 2005, 00:09 AM
Gotta love it...

cash_site
March 15th, 2005, 02:14 AM
nice one, must be a clever dude :rollseyes:

Curio
March 19th, 2005, 07:59 AM
more detail at http://www.edbott.com/weblog/archives/000562.html

Moderators - is it allowed/reasonable to post a link to where this exploit actually is?

Conan
March 19th, 2005, 10:19 AM
more detail at http://www.edbott.com/weblog/archives/000562.html

Moderators - is it allowed/reasonable to post a link to where this exploit actually is?

Will it infect everyone who visits it?

Curio
March 19th, 2005, 12:42 PM
You don' get infected unless you click yes in the dialog but you will see some hard disk activity when the exe file is downloaded to your system when the page loads - this may trigger some AVs but when I did it I was using Xandros so I wasn't worried anyway. I have since found another link which does some different exploits and crashes I.E. but bitdefender caught all that and prevented the exploit from completing - this is on an otherwise unprotected Windows ME system. Perhaps posting them in a seperated format so you have to reconstruct the link would be nice for interested people, if only to add them to your block list.

Curio
March 19th, 2005, 15:23 PM
Here is the iframe exploit that will crash Firefox - it doesn't do any harm I just thought it might interest people to actually experience the exploit and see what happens.

http://www.active-bait.co.uk/crashmozilla.htm - warning! if you click it using firefox then your firefox will crash

FastGame
March 19th, 2005, 22:43 PM
warning! if you click it using firefox then your firefox will crash
Yep it blew my Firefox to pieces :p

That proves how safe FF is, it will die in order to save its master ;)