Phoney 'news stories' hit Internet Explorers as they type...
By Joris Evers
Published: 31 March 2006 09:45 BST
Cyber criminals are spamming email messages to trick people into visiting malicious websites that exploit a recent Internet Explorer flaw, experts warned on Thursday.
The websites take advantage of the vulnerability in the omnipresent Microsoft web browser to install a keystroke logger on vulnerable computers, according to San Diego-based Websense Security Labs.
Websense said in an alert: "This keylogger monitors activity on various financial websites and uploads captured information back to the attacker."
The malicious software could capture log-in names and passwords for the sites, information criminals could sell or possibly use to plunder a victim's account.
The email messages used to lure people to the websites contain excerpts from BBC news stories and offer a link to "read more," Websense said. This link leads to a forged BBC webpage where the malicious software is dropped onto a vulnerable PC by exploiting the "createTextRange()" vulnerability in IE, according to Websense's alert.
The vulnerability has to do with how Internet Explorer handles the createTextRange() tag in Web pages. Since the flaw was disclosed publicly last week, more than 200 websites have been found to exploit it. These sites typically install spyware, remote control software and Trojan horses on vulnerable PCs.
Microsoft has said it is working on a fix for the browser. That update is currently scheduled for delivery on April 11, Microsoft's regular monthly patch day. However, the Redmond, Washington, company has said it's considering an earlier release.
Meanwhile, two security companies have beaten Microsoft to the punch. eEye Digital Security and Determina both released unofficial fixes for the IE flaw earlier this week. Experts, however, have warned users to be cautious with non-Microsoft fixes and instead suggest using a Web browser other than IE, or disabling Active Scripting, which is also Microsoft's advice.
Joris Evers writes for News.com
'Broken: E-crime policing in the UK'
MP fights low-level attacks with new partnership
Corporations riddled with security holes
How safe is your network?
PC security warning for banking online
Banks may not always pick up the bill
E-crime unit on track, says police chief
But where's the funding?
Cotton Traders' site hacked: Thousands of details stolen
Customer credit cards breached
Stories from around the web...
Q&A: The man behind Cisco's security CNET News.com
Laws to clamp down on cyber crime BBC News
Hacking made easy Washington Post
Compliance, not malware, drives IT budgets TechWeb.com via InformationWeek
UK security experts fear for loss of high-tech crime unit Times Online
Make your voice heard
silicon.com and the Bathwick Group have created an opportunity for business and IT executives to share their experience with each other and thus enhance their knowledge of the IT marketplace.
Join our research panel, and you'll be asked to participate in short surveys - and then will be privy to the answers of all your colleagues, as we send you tailored versions of the results.
Extras include complementary passes to silicon.com events and survey prizes such as iPods. Plus, there are the obvious networking opportunities with your fellow panellists.
For more about the Research Panel and how to join, click here
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page