ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

US Report: Visual Basic holes open for e-mail viruses

Published: 20 Nov 1998 14:25 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

"Just the fact that your mail program shows e-mail in a window (could) spread the virus to your system," said Igor Grebert, senior researcher at anti-virus maker Trend Micro company publicly announced, on Wednesday, efforts to include protection against such viruses in its anti-virus software.

Last week, anti-virus firm Central Command warned of a more isolated virus that affected ActiveX controls in certain cases. Microsoft accused the companies of scare tactics. "We are extremely confident that this is nothing that users should be worried about," said Mike Nichols, Internet Explorer product manager at Microsoft.

Indeed, at present, HTML viruses present no danger. Grebert has only encountered what he refers to as "test viruses" that do not have any destructive payload. In addition, while HTML viruses have potential to be nasty, they will have a hard time spreading out of control over the Internet. In order to copy itself to a new Web page, the HTML virus must execute on a machine from which it is allowed to change the page. This essentially means that only Webmasters have the possibility of being "Typhoid Mary." "If you are just a user, you will not infect other people's Web pages," said Grebert.

Still, whoever they are, the virus writers have been busy. In the past two weeks, Trend Micro has tallied no less than 17 new variants, written in Microsoft VBScript. While none of them could harm users, don't expect the viruses to have their teeth filed for long. Soon, they could cause significant problems for users who get them.

Technically, the viruses resemble normal programs. "There is no security in Windows that limits what VBScript can do," said Grebert. "Can it read your files? Yes. Can it format your hard drive? Yes." Essentially a macro virus, the viruses -- written in VBScript -- are embedded in the HTML included in a Web page or e-mail. Users of Windows 98 or more recent versions of Microsoft's (Nasdaq:MSFT) Internet Explorer and Outlook are at risk, according to Trend Micro, since both programs are set up with Microsoft's Windows Scripting Host -- needed to run VBScript.

Microsoft said the problem did not affect Internet Explorer. "As a user you would have to go to a site that was designed to be malicious, and users would have to lower the (default) security," said Microsoft's Nichols. Even when security is lowered, users still are prompted every time a script tries to run, he said, putting only the most ignorant at risk.

Still, Outlook and other e-mail programs that read VBScript will allow the virus to execute, claimed researchers. "The real angle of attack is on HTML e-mail," said Russ Cooper, moderator of NTBugTraq "In that regard, people are wide open to attack." Originally, the threat of e-mail macro viruses was expected to come from Microsoft's combination of Outlook 98 and Windows 98.

At the end of July, Finnish students found holes in Outlook that let viruses spread by e-mail. However, that security hole could only be exploited by luring the user to click on an overlong HTML link. Several experts had predicted that some virus writer would put the two together.

Netscape's (Nasdaq:NSCP) Navigator, which does not support its rival's VBScript, is immune, said Grebert. "Yet, with the new features that Sun is putting into Java to compete with Visual Basic, they may have a similar problem in the future."

In addition, Cooper warns that an HTML virus could be written in JavaScript just as easily as VBScript.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
58 out of 102 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:











Related Jobs

Firewalls Engineer Lead

Good working knowledge of anti-spam technologies. Good working knowledge of anti virus technologies. With broad global resources and deep technical ...

NT SYSTEMS ENGINEER - CITRIX PS4 - FINANCE - 50K

The successful candidate will have extensive experience of: - Administering Windows 2003 server - Active Directory - Exchange2003 - Citrix PS4 - MS ...

Technical Support Engineer Windows XP 2003, Microsoft Outlook, LANs, WANs, DNS,

Technical Support Engineer Windows XP 2003, Microsoft Outlook, LANs, WANs, DNS, - Lambeth - 2198 RM helps to push the boundaries of technology to ...

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains