ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Old hack haunts WebTV

Robert Lemos, CNet News.com ZDNet.co.uk

Published: 21 Mar 2000 10:19 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

An HTML hack -- which had previously allowed attackers to command users' machines to send forged email -- caused renewed headaches for Internet-over-TV provider WebTV Networks this past weekend.

The new spin on an old security hole allows cyber vandals to use an embedded URL in email and newsgroup postings that cause subscribers to execute a WebTV-specific macro program. In this case, the macros caused the offending URL to be copied into the user's signature file, and thus be appended to all future emails and newsgroup postings. It also sends an email to several specified newsgroups.

The result last weekend was that unsuspecting users caused an avalanche of postings to several WebTV newsgroups, which buried all normal postings.

WebTV acknowledged the problem, pointing its finger at an old bug that it thought that it had fixed. The bug allows WebTV's proprietary macros, which are embedded in messages, to execute as "trusted" applications.

"Modifying the signature and posting the message without the user's knowledge are two things that this bug allows," said Jeff Allen, operations engineer for WebTV Networks. "When you put them together, you get something like this."

The problem only affected WebTV users with the WebTV Classic device and the service's internal newsgroups. By the weekend, 14 users had complained to WebTV. Some reports called the exploit a "virus", despite WebTV's assurances that it wasn't.

According to a WebTV's Allen, the embedded URL hidden in the subscribers' signatures calls an external homepage that contains the HTML macro program. Because of the WebTV bug, the program runs on the user's WebTV device with "trusted" privilege, allowing it to execute any valid commands.

WebTV has not taken the online vandalism sitting down. "Clearly, this is a pretty embarrassing bug, and we want to get it fixed as soon as possible," said Allen.

While some newsgroups had been flooded last week, Allen and others have succeeded in shutting down the external pages that contained the embedded code, thus stopping the exploit at the source. The company's network administrators are monitoring the service's newsgroups 24 hours a day to minimise the effect of any new uses of the exploit. In addition, WebTV has promised to patch the network hole by the end of this week.

WebTV has little patience with any "wannabee hackers" who attempt to use the code, said Allen. Anyone caught using the bug to cause a WebTV user to send messages without their knowledge will be kicked off the system. The company has not yet tried to find out who began spreading the malicious code. "We have a zero tolerance policy," he said. "We were able to cancel at least a few people for using code like this. It has worked pretty well. The number of people has basically gone down to zero."

Have you see ZDNet's updated TOPIC Hackers area, complete with downloads, and all the latest hacking news?

What do you think? Tell the Mailroom and read what others have to say.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
21 out of 64 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:












Related Jobs

SAS contract-ETL (DI Studio, ETL Studio, SAS Base, Macro)

SAS ETL, Base, Macro. SAS consultant required by my key financial client to take ownership of loading data into a product portfolio system to provide ...

Application Support/Coding/Bug Fixing - North London to 30k SQL

Exciting new role for a Application Support Engineer with some Programming experience to join my leading client based in North London to work on ...

Oracle Support/Developer

We are committed to being a great place to work, a trusted business partner and an attractive investment for your career Construct/modify software in ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains