ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

MyDoom strikes again through IE flaw

Published: 09 Nov 2004 08:53 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new version of MyDoom uses an unpatched flaw in Microsoft's Internet Explorer to spread, antivirus companies warned on Monday.

The recently discovered vulnerability in the browser software allows the offshoot to infect a PC after a user clicks on a link, according to advisories from security software makers Symantec and McAfee. The program sneaks past antivirus applications that detect malicious software by scanning email messages with attached programs.

The companies said they had only detected a few instances of the infector, which is labelled MyDoom.AG by McAfee and MyDoom.AH by Symantec.

Craig Schmugar, senior virus research manager at McAfee, said: "We have only received one submission from the field, but the technical aspects of this are concerning." "It has all the components there to become a significant virus."

It's not the first time a code writer has exploited a flaw in a Microsoft product before the software giant has had a chance to plug the hole. An aggressive advertiser attempted to surreptitiously install a pop-up toolbar in victim's Web browsers using two previously unpatched security flaws in Internet Explorer.

Microsoft said that it was investigating the flaw and was aware of a new virus exploiting the issue.

"As a best practice, users should always exercise extreme caution when opening unsolicited attachments from both known and unknown sources," said Microsoft in a statement sent to ZDNet UK sister site CNET News.com. "In addition, we continue to encourage customers follow our 'Protect Your PC' guidance of enabling a firewall, getting software updates and installing antivirus software."

The latest MyDoom virus appears as an email in an inbox. The body of the message states: "Look at my homepage with my last Webcam photos!" or "FREE ADULT VIDEO! SIGN UP NOW!" Both messages have text that links them to a Web page generated by the virus and hosted on the infected computer that sent the email.

When the victim clicks on the link, a Windows-based PC will call Internet Explorer and load a malicious Web page from the previously infected computer. The page contains the IFrame vulnerability recently publicised on security mailing lists. The virus uses the flaw to execute code on the victim's computer, infecting the system. The virus harvests email addresses on the compromised system, sends out mail to spread the virus further, sets up a Web server and attempts to contact several internet relay chat (IRC) servers as a way to notify the virus's creator of that a new system has been compromised.

The fact that the virus creates a Web server and uses that server to infect other systems is a significant departure from previous versions of MyDoom, and other viruses in general, Schmugar said.

"There was a decent amount of work that went into this," he said. "There was a good bit of attention [among security researchers] to the demo code [of this flaw]. Someone grabbed the demo code and tweaked it quite a bit."

McAfee rates the program a low threat, but Schmugar said he thinks it might spread widely.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
84 out of 170 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

C# / .Net Excel VBA Development Derivatives - 450

The requirement is going to based working with the Quant team to develop a spread sheet pricing application. C# / .Net Excel VBA Development ...

IT SECURITY LEAD - ISO 27001 AUDIT & RISK MANAGEMENT - WOLVERHAMPTON

Working to ISO 27001 standard, you will take the lead in risk & vulnerability assessments and department auditing. Senior IT Security Analyst opening ...

Technical Author - Contract - London

Knowledge of Symantec NetBackup, Network Appliance Filers, Windows environments with SQL Server and Exchange 2007 would be desirable. Huxley ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment

Trades Unions against ID Cards

The Trades Union Congress (TUC) has backed up airport workers protesting against ID cards, the Financial Times reports. In a letter to Home Secretary Jacqui Smith, the TUC said it... More

Post a comment