Advertisement
Promo

Security threats Toolkit

Trojan horse exploits Explorer flaw

Published: 03 Oct 2003 08:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A malicious program, dubbed QHosts, infects PCs using a recent flaw in Microsoft's Internet Explorer to take control of how computers look up Internet addresses, antivirus firms warned on Thursday.

The program takes advantage of a critical flaw in the popular Internet Explorer Web browser, which Microsoft has made an integral part of its Windows operating system. The flaw, which Microsoft has labeled an "object type" vulnerability, can be used to cause Web site visitors to unknowingly run malicious code onto their computers when surfing a compromised site. Such an attack is referred to as a Trojan horse.

The Trojan horse used a banner ad that the attacker somehow placed on Web hosting provider FortuneCity.com's site to infect PCs running Windows, said Craig Schmugar, a virus-research engineer with security company Network Associates. When a page containing the booby-trapped ad is displayed in Internet Explorer, the malicious code will automatically install the Trojan horse on the user's PC.

"The banner ad displayed another pop-up, and that pop-up would load the content," he said. "Viewing that page would allow the Trojan to execute." FortuneCity.com has already taken down the banner ad, he added.

While the QHosts program does not seek out new computers to infect -- and so, is not considered a worm or virus -- its ability to automatically infect PCs and the fact that no fix exists for the vulnerability makes the appearance of the Trojan horse worrisome, Schmugar said.

"The ones (flaws) that are exploited tend to get patched faster. I am sure -- given all the attention -- Microsoft is thinking of bumping up the time frame" to repair the issue, Schmugar said. Microsoft originally patched the flaw in late August, but later discovered that the fix didn't solve the problem.

A Microsoft representative said that the company was working to solve the problem, but had no time frame for a fix.

"While we will release a fix for this variation shortly, users can help protect against this newly reported issue by changing their IE Internet security zone settings to prompt them before running ActiveX components," the company said in a statement. More information can be found in the advisory on Microsoft's Web site.

How it works
The QHosts program changes the Internet addresses of the computers at which the infected PC will look to resolve unknown Web sites and domain names. Known as the domain name service (DNS) servers, such computers are generally operated by a trusted organisation, such as an Internet service provider. However, QHosts will send the requests to other servers, which Schmugar believes are likely to be owned by the originator of the Trojan horse.

Such hostile servers could reroute an infected computer's request for a Web site to an entirely different page.

The servers to which the original QHosts program referred have since been removed from the Internet, but future versions of QHosts could easily replace the addresses of those servers with new ones, said Schmugar. "The silver lining is that we can contact the Web host and have the page taken down," he said. "The downside is that when one site is taken down, another could pop up."

Still, few reports of the Trojan horse have emerged, according to Vincent Weafer, the senior director of the incident response team at security company Symantec.

"We have less than a handful of people reporting the issue," he said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
89 out of 153 people found this useful


Full Talkback thread

1 comment

  1. Me thinks Microsoft needs another security program... adebayo omo-dare

Company/Topic Alerts

Create a new alert from the list below:



Video icon

Video

Sentry Posts Blog

Campaigners criticise '£10bn NHS IT ov...

The National Health Service's flagship IT project has been criticised by a tax campaign group for running billions of pounds over budget. The NHS National Programme for IT (NPfIT)... More

2 comments

Climate research centre compromised

One of the UK's leading climate change research centres has had a security breach. The Climate Research Unit at the University of East Anglia (UEA) suffered a compromise of information,... More

1 comment

Government web-monitoring plans on hol...

Government plans to compel ISPs to process and store details of all web communications have been put on hold until after the next election. The Home Office told ZDNet UK on Wednesday... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters