Microsoft riled by adware scam

Microsoft flaws let in porno pop-ups...

NEWS An adware purveyor has apparently used two previously unknown security flaws in Microsoft's Internet Explorer browser to install a toolbar on victims' computers that triggers pop-up ads, researchers said this week.

One flaw lets an attacker run a program on a victim's machine, while the other enables malicious code to "cross zones," or run with privileges higher than normal. Together, the two issues allow for the creation of a website that, when visited by victims, can upload and install programs to the victim's computer, according to two analyses of the security holes.

The possibility that a group or company has apparently used the vulnerabilities as a way to sneak unwanted advertising software, or adware, onto a user's computer could be grounds for criminal charges, said Stephen Toulouse, security program manager for Microsoft.

"We consider that any use of an exploit to run a program is a criminal use," he said. "We are going to work aggressively with law enforcement to prosecute individuals or companies that do so."

Microsoft learned of the issue when a security researcher posted an analysis of the problem to the Full Disclosure security mailing list Monday. The software giant has already contacted the FBI and is in the "early stages" of building the case, Toulouse said. The company is considering creating a patch quickly and releasing it as soon as possible, rather than waiting for its usual monthly update.

The flaws are apparently being used to install the I-Lookup search bar, an adware toolbar that is added to IE's other toolbars. The adware changes the Internet Explorer home page, connects to one of six advertising sites and frequently displays pop-ups - mainly pornographic ads, according to an adware advisory on antivirus company Symantec's website.

On Tuesday, security information group Secunia released an advisory about the problem, rating the two flaws "extremely critical."

The flaws could let any attacker with a website send an email message or an instant message with a link that, when clicked on by an Internet Explorer user, would cause a program to run on that victim's computer.

Robert Lemos writes for News.com

Comments

There are 4 comments. Join the discussion

  1. 1. Craig

    Security still top of their agenda eh?

    • 11 June 2004 11:00
    • Add comment
  2. 2. Nigel

    Hmmm... Think this infected my computer last weekend and I'm running a fully patched, firewall and virus protected machine! It's an absolute PAIN to deal with - a real intrusion that messes with so much. I just do not understand why these vulnerabilities aren't plugged earlier.

    • 14 June 2004 21:06
    • Add comment
  3. 3. Kevin

    I gussed it was a security flaw in IE, at least it stops my wife from surfing...............

    • 17 June 2004 13:42
    • Add comment
  4. 4. nathan

    I say these jerk offs get hammered. This crap keeps popping up on my screen and it's relentless. It would be nice for the FBI to really make an example out of them. Perhaps a caning is in order.

    • 6 July 2004 00:10
    • Add comment

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your silicon.com account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ

Get silicon.com's daily newsletter

  • Register on silicon.com

    Enter your email to register

Keep in touch with silicon.com

silicon.com newsletters