Back to Forums








View Full Version : Huge spyware threat on all browsers using sun java found!!!!


egghead
March 12th, 2005, 20:31 PM
What if there was an infection out there that could bypass Firefox and still get its grubby little paws on IE, and from there, the heart of your OS? What if that same infection could get past not only FF, but a whole raft of other (supposedly more secure) browsers too?

What if, of all people, Neil Diamond was indirectly involved in this craziness?

Unfortunately, this has now become a reality and woe betide anyone looking for lyrics from Neil's latest hit. You're more likely to end up with a nasty case of browseritis. After hearing rumours of a Firefox Adware bundle from this (http://forums.tomcoyote.org/index.php?showtopic=31385) thread, I thought I'd go check it out. The results were, as they say, a right kick in the pants.

But how could this happen?

The answer is, some sneaky coding is being used to get around your browser of choice. Upon visiting the target website, nothing happens. Nothing that is, unless you have Sun Java Runtime Environment (http://java.sun.com/) installed on the host machine. And seeing how everyone is being urged to turn away from Microsoft's Java in favour of Sun's version, this could spell problems for browsers currently lording it over IE.

Think you're safe because you're not actually using IE? Think you're safe because you have IE locked down tight with HOST files, Spywareblaster and the inbuilt security settings cranked up to the max? Wrong. This (http://www.vitalsecurity.org/ieblocked.gif) is a shot of IE with the infection domain already added to the "Restricted Sites" zone in Internet Options. Note the "ironic" affiliate banner for Firefox.

http://www.vitalsecurity.org/2005/03/firefox-spyware-infects-ie.html


OMG
egghead

lynchknot
March 12th, 2005, 20:34 PM
I do not have java enabled.

*edit - what's the big deal? It pops up a dialog asking for permission - unlike that classloader trojan. Just say no.

egghead
March 12th, 2005, 21:15 PM
I do not have java enabled.

*edit - what's the big deal? It pops up a dialog asking for permission - unlike that classloader trojan. Just say no.

yep

the article wording was missleading

i feel better knowing you get a prompt.

lynchknot
March 14th, 2005, 19:05 PM
my dear watson, please deduce:

It pops up a dialog asking for permission - unlike that classloader trojan.

as for intricate details, I don't know.