ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Hackers launch Bofra banner ad attacks

Dan Ilet ZDNet.co.uk

Published: 22 Nov 2004 15:05 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security experts are warning that hackers may have launched a wide-spread attack in Europe using banner ads to redirect users to Web sites that download malicious code.

After receiving several reports of rogue banner ads infecting users, researchers at the SANS Internet Storm Center have cautioned that hackers may have attacked a large number of servers hosting the adverts. This means that hackers would reach a larger number of victims on hundreds of sites by 'advertising' to click the ad that would lead to the code.

Hackers have already attacked several European Web sites using the as yet un-patched IFRAME exploit, otherwise known as Bofra, in Internet Explorer 6.0.

"The Storm Center received a report of a high profile UK Web site that contains a pointer on their main page to another URL hosting the Bofra/IFRAME exploit," wrote Marcus Sachs director of the SANS Internet Storm Center. "We have confirmed that if this site is visited using Internet Explorer the exploit will be downloaded. Please exercise caution when using Microsoft's Internet Explorer since this issue has no current patch. The Storm Center recommends using an alternative browser when visiting sites other than those you absolutely trust."

Banner ads are an ideal tool for mass distribution of malicious code because they are able to distribute code on many Web sites at the same time.

Users who have clicked on the ads have seen their computers infected by the Bofra worm, which emerged head five days after the vulnerability was announced earlier this month.

The worm combines multiple attack techniques using spamming, social engineering, virus infection and Trojans to attack its victims' computers.

Windows XP users who have loaded Service Pack 2 are thought not to be affected by the worm. Microsoft has yet to release a patch for the exploit, but earlier this month the company chastised the independent researchers who published the vulnerability for failing to inform it first.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
103 out of 202 people found this useful


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Hosting/ISP - Network Engineer East Midlands

I have a fantastic opportunity for a Network Engineer to join this established and growing organisation. This is a brand new role that has come about ...

Data Centre Operations Technician (Hardware, Server, IT, Windows, Linux)

Job Title Data Centre Operations Technician (Hardware, Server, IT, Windows, Linux) Company Description Rackspace Hosting is Europe's fastest growing ...

DESKTOP/NETWORK SUPPORT- HOSTING COMPANY - HOLBORN - 30k

A leading (centrally based) managed services company is seeking a new employee to join this ever expanding business. They are seeking a 1-3rd line ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Biometric devices. Do you need one?

When saying “biometrics” I am not thinking about law enforcement, AFIS systems, national ID and visa projects. I first think about personal solutions that will make my life easier.... More

1 comment

Barracuda launches counter-suit agains...

Court cases are never pleasant or simple. The ongoing battle between security companies Trend Micro and Barracuda Networks took a new twist on Wednesday, when Barracuda launched a counter-suit... More

Post a comment

Mobile Speed Demon: Wireless Surpasses...

Mobile Speed Demon: Wireless Surpasses Landline Author: Eric Everson, Founder MyMobiSafe.com As I look around my house and throughout my network of friends, I instantly realize... More

Post a comment