ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Porn Trojan exploits old Microsoft hole

Wendy McAuliffe ZDNet.co.uk

Published: 04 Jan 2002 13:43 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new Trojan horse is redirecting Internet users to pornographic Web sites by exploiting an old vulnerability in Microsoft Internet Explorer (IE).

The JS/Seeker-E script can arrive by email or can be embedded into a Web page: when a user opens the email or clicks on the Web page, the script is activated. Once activated, Seeker attempts to change the user's IE settings, such as the start page and search settings, and will redirect the infected user to a porn site.

"It isn't terribly damaging, as it exploits a bug in IE that was first found in October 2000," said Graham Cluley, senior technology consultant at security firm Sophos. "Seeker will only affect those who have not updated their necessary patches."

The security vulnerability that Seeker attacks is in the Microsoft virtual machine ActiveX component. This same vulnerability allows other, more malicious scripts to do a lot more damage. A patch for the hole was released by Microsoft at the end of October 2000, but other holes have since appeared in Internet Explorer that let other types of malicious scripts attack users' PCs.

On Thursday a new vulnerability was detected in IE that could allow the execution of malicious code on systems running IE 5.5 and 6.0 of the browser. A security fix was released for a similar hole, found in November by Finland-based security firm Oy Online Systems, but the patch itself seems to have created a new glitch. The latest bug is in the Microsoft GetObject JScript function, and could allow a malicious user to execute arbitrary programmes on a compromised system.

For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
14 out of 33 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Testing opportunities - Financial Services - Cambridge - 32k - 38k

You role will include defining and developing test strategies, test plans, test cases and scripts from functional specifications, as well as the test ...

Test Analyst - Consultancy - Central London - Contract

You will be responsible for analysing and understanding new and existing software components and requirements, gathering test requirements and ...

Oracle HR, Prince 2, SQL scripts, AIM, UML 6 Mth - Cheshire

Oracle HR, Prince 2, SQL scripts, AIM, UML Methodology My client based in Cheshire is urgently seeking an Oracle HR Application developer to work on ...

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains