ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Fortnight worm redirects to porn sites

Andy McCue Silicon.com

Published: 23 Jun 2003 10:55 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Failure to patch a three-year-old Microsoft vulnerability is leaving home and business users exposed to a JavaScript worm that redirects Internet Explorer to porn sites.

Increased infections from versions of the Fortnight JavaScript worm, which exploits a hole in Microsoft VM Active X, are being reported by some antivirus vendors.

Malicious code can be executed just by reading a message in an HTML-aware email client, meaning the user does not need to open an attachment to activate the virus. Those infected find their Explorer browser redirected to a 'naughty nurses' site and bookmarks and homepage reset to other porn sites.

Graham Cluley, senior technical consultant at Sophos, told silicon.com that although the Fortnight payload is more of an annoyance than a serious threat, it highlights the fact users have not patched a hole which could be exploited by a more malicious worm.

"We understand systems administrators are under pressure but this is a patch which has been out there for three years," he said.

Worms such as Fortnight are likely to increasingly target unpatched systems of home users as corporates become more aware of the importance of keeping patches up to date, according to Chris McNab, technical director at security consultancy Matta.

"The lesson is it is not just about patching your servers. It is about patching workstations, browsers, and pieces of software like Microsoft Office and Word. In the future as holes in server software like IIS get fewer and fewer you will find that these virus and worms out there will start to target the end user in a much more aggressive way -- like picking up on very small vulnerabilities in Internet Explorer."

A patch for the vulnerability can be found on Microsoft's Web site.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
13 out of 27 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Application Support / Developer - London - SQL, .Net, JavaScript 33k

The technical environment that you will be working in consists of SQL Server 2000, VB6, ASP/JavaScript Exciting new role for an Application Support / ...

C# .Net JavaScript - Technical Architect - London

Net / JavaScript Technical Architect to provide technical leadership for the development and maintenance web based and desktop based applications. ...

JavaScript / AJAX / Web 2.0 development role

They are using technologies such as XSLT, CSS and JavaScript and XML. They are looking for someone who is a VERY technically adept at JavaScript and ...

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains