ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Trojan horse exploits Explorer flaw

Published: 03 Oct 2003 08:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A malicious program, dubbed QHosts, infects PCs using a recent flaw in Microsoft's Internet Explorer to take control of how computers look up Internet addresses, antivirus firms warned on Thursday.

The program takes advantage of a critical flaw in the popular Internet Explorer Web browser, which Microsoft has made an integral part of its Windows operating system. The flaw, which Microsoft has labeled an "object type" vulnerability, can be used to cause Web site visitors to unknowingly run malicious code onto their computers when surfing a compromised site. Such an attack is referred to as a Trojan horse.

The Trojan horse used a banner ad that the attacker somehow placed on Web hosting provider FortuneCity.com's site to infect PCs running Windows, said Craig Schmugar, a virus-research engineer with security company Network Associates. When a page containing the booby-trapped ad is displayed in Internet Explorer, the malicious code will automatically install the Trojan horse on the user's PC.

"The banner ad displayed another pop-up, and that pop-up would load the content," he said. "Viewing that page would allow the Trojan to execute." FortuneCity.com has already taken down the banner ad, he added.

While the QHosts program does not seek out new computers to infect -- and so, is not considered a worm or virus -- its ability to automatically infect PCs and the fact that no fix exists for the vulnerability makes the appearance of the Trojan horse worrisome, Schmugar said.

"The ones (flaws) that are exploited tend to get patched faster. I am sure -- given all the attention -- Microsoft is thinking of bumping up the time frame" to repair the issue, Schmugar said. Microsoft originally patched the flaw in late August, but later discovered that the fix didn't solve the problem.

A Microsoft representative said that the company was working to solve the problem, but had no time frame for a fix.

"While we will release a fix for this variation shortly, users can help protect against this newly reported issue by changing their IE Internet security zone settings to prompt them before running ActiveX components," the company said in a statement. More information can be found in the advisory on Microsoft's Web site.

How it works
The QHosts program changes the Internet addresses of the computers at which the infected PC will look to resolve unknown Web sites and domain names. Known as the domain name service (DNS) servers, such computers are generally operated by a trusted organisation, such as an Internet service provider. However, QHosts will send the requests to other servers, which Schmugar believes are likely to be owned by the originator of the Trojan horse.

Such hostile servers could reroute an infected computer's request for a Web site to an entirely different page.

The servers to which the original QHosts program referred have since been removed from the Internet, but future versions of QHosts could easily replace the addresses of those servers with new ones, said Schmugar. "The silver lining is that we can contact the Web host and have the page taken down," he said. "The downside is that when one site is taken down, another could pop up."

Still, few reports of the Trojan horse have emerged, according to Vincent Weafer, the senior director of the incident response team at security company Symantec.

"We have less than a handful of people reporting the issue," he said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
83 out of 147 people found this useful


Full Talkback thread

1 comment

  1. Me thinks Microsoft needs another security program... adebayo omo-dare

Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

3rd line support engineer

Key skills: > Active Directory - internal AD design, GPOs, sites and subnets, AD replication, global catalogues and domain control. My blue-chip ...

Systems Engineer

ESSENTIALS SKILLS/QUALIFICATIONS: Knowledge of AD and W2k3 server build and implementation. The role will require the analysis of an existing single ...

Firewalls Engineer Lead

Ensure all firewall related break/fix SLA timescales are met and all associated reporting is completed in a full and timely fashion. Project manage ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment