ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

New virus first to infect Macromedia Flash

Robert Lemos, CNet News.com ZDNet US

Published: 09 Jan 2002 10:34 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Antivirus companies warned PC users on Tuesday that future Macromedia Flash movies could carry malicious viruses and worms.

The caution came after an unknown virus writer sent just such an infectious program to UK antivirus company Sophos. Dubbed SWF/LFM-926, the new program does little but infect Flash files on a PC when the movie is played.

"It's really a proof of concept, as opposed to something that you should lie awake at night worrying about," said Graham Cluley, senior technology consultant for the Abingdon, England-based company. "But whenever a new vulnerability like this is found, other copycats tend to create more malicious variants."

The SWF/LFM-926 should mainly be a concern to Web site designers who use Flash animations to add pizzazz to their sites, Cluley said. Flash technology, created by digital media company Macromedia, is typically used on sites to add interactive user interfaces and multimedia presentations.

Macromedia went even further, calling the vulnerability through which the virus spread "not that serious".

"Ninety-nine-point-nine percent of the time, people play Flash movies from the Web in their browser," said Pete Santangeli, vice president of engineering for Flash at the San Francisco company. "That's completely safe."

It's only when a Flash file or movie is played on a PC through a standalone player included with Macromedia's authoring tools for Web designers that this type of virus can actually infect a PC.

When the infected Flash movie is played, the virus displays the message "Loading.Flash.Movie..." and drops a 926-byte DOS file onto the PC. This file--named V.COM--is run by the virus and infects all other Flash files in the current directory. The SWF/LFM-926 virus' name is derived from the abbreviation for Shockwave Flash, as Macromedia Flash used to be known, the displayed message and the size of the file.

The virus will infect only Windows NT, Windows 2000 and Windows XP systems, but has not yet been seen circulating the Internet. Moreover, since the virus doesn't have a way to spread quickly, it's unlikely to infect a large number of PCs in its current form, said Craig Schmugar, virus research engineer for security-software maker Network Associates.

"It won't be a very effective spreading method if they only use Shockwave Flash," he said, citing NAI tests that confirmed the virus will not spread when the Macromedia Flash is played in a Web browser.

"It is a double-edged sword," he said. "They have given their authoring community an ability to create increased functionality. For the most part, Macromedia has been strict about security; it would have been difficult for them to see this coming."

The virus is not the first to try to fool those PC users with a weakness for Flash movies. In December 1999, the ProLin worm spread through email by posing as a Flash movie, but in reality it was a simple Windows program file.

SWF/LFM-926 is a pure virus, meaning the program infects files and can only spread when the compromised file is moved to another system.

Macromedia will release a workaround to disable the file association between Flash files and the local Flash player within a couple of days, Macromedia's Santangeli said. In addition, the company plans to close the hole in the player by the next version.

For the time being, email users will have to add the SWF file format to their list of attachments of which to be wary.

"Just as we have seen a first Adobe Acrobat file infector and the first AutoCAD file infector, this is just a new way to get into the PC," Sophos' Cluley said. "It does show that the virus writers are always looking for new battlegrounds."

For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
34 out of 69 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

45K Senior Java Developer role -J2SE/SPRING/HIBERNATE

45K Senior Java Developer role -J2SE/SPRING/HIBERNATE My client is a key player in the finincial spread betting industry, they are the innovators of ...

Operations Manager (Technical pre-sales team)/ IT Manager- Abingdon, Oxfordshire

Operations Manager (Technical pre-sales team)/ IT Manager- Abingdon, Oxfordshire An opportunity for an operations manager with IT experience to move ...

Application Designer

Application Designers / Application Architects London EDS x 2 Excellent Salary + Flexible Benefits Package This is an excellent opportunity for a ...

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains