HZGN.COM
welcome to my space
X
Feng Shui | Graphic Design | Cosmetics | Causes and Organizations | Regulatory Compliance | Gadgets and Gizmos | Computer Forensics | Tools and Equipment | Related articles
Search:  
Welcome to:hzgn.com
NAVIGATION: Home >>
Analysts: Expect More Ad Server Attacks
Published by: smith 2009-01-06

Security analysts said recent attacks on several high-profile European Web sites, through compromised ad servers, is a sign of more trouble to come as hackers take aim at launching viruses in unique ways.

"Instead of only defacing the Web site, they have the potential to do some serious damage," said Vincent Gullotto, vice president of McAfee's AVERT virus research group. "So far the infection numbers are probably into the thousands, but not at an epidemic or outbreak proportion."

Although Gullotto said he was surprised these types of breaches didn't happen more often, he said the trend would likely continue until the vulnerability was patched.

As reported Monday by internetnews.com, British tech-focused Web site The Register said some of its banner advertising, served by third-party ad serving company Falk AG, "became infected with the Bofra/IFrame exploit" thanks to a known IFRAME buffer overflow (define) vulnerability in Internet Explorer.

Security firm Secunia, which labeled the vulnerability "extremely critical," said it is caused by a boundary error in the handling of certain attributes in the "IFRAME," "FRAME," and "EMBED" HTML tags.

"This can be exploited to cause a buffer overflow via a malicious HTML document containing overly long strings in e.g. the 'SRC' and 'NAME' attributes of the IFRAME tag."

On high fives, 10 million, rats and more - TwinCities.com::
Place an Ad. Search Job Listings. Post Your Resume. Career Advice. Top Careers. Cars. Sell your Car As hosts, we expect guests will show respect for each other.
http://www.twincities.com/opinion/ci_6307694
HOME
Microsofts Big Online Ad Buy::
Bomb Attacks Aimed at Indias High-Tech Heart? RSS Feed: Most Discussed Stories What To Expect From A Technology Assessment.
http://www.businessweek.com/technology/content/may2007/tc2gy+index+page_top+stories
HOME
John Pescatore, security analyst and vice president and research fellow at research firm Gartner, said unless users are running Windows XP Service Pack 2 (SP2), which is immune to the IFRAME vulnerability, they should consider running an alternate browser to IE.

"Aside from that, the best way to protect yourself is not to click on ad banners," he said.

He also recommended operators of Web sites serving banner ads to use add-on security products that are designed to stop these types of attacks, like Prevx and McAfee's intrusion prevention software. "Those are the primary options," Pescatore told internetnews.com.

Microsoft has not issued a patch for the vulnerability.

The Bethesda, Md.-based SANS Internet Storm Center has been posting warnings on its Web site since Saturday, reporting compromised sites in Britain, Sweden and the Netherlands. The center also warned operators of Web sites that serve banner ads to verify that the ads don't contain the IFRAME exploit code.

"You might want to consider disabling banner ads for a little while to minimize the risk of accidentally infecting your users and propagating," SANS recommended. "Since this vulnerability is easy to exploit, it is likely that malware for his issue will come in many flavors and colors."

So far it appears North American-based sites have not been affected.


Linux Patent Protection Group Loses Ally
XAML Tidbits Previewed in Microsoft's Avalon

#If you have any other info about this subject , Please add it free.#
Your name:
E-mail:
Telphone:

Your comments:


If you have any other info about Analysts: Expect More Ad Server Attacks , Please add it free.
  • hotmail login problem using opera browser and agnitum outpost firewall
  • outpost log issues
  • outpost firewall causing kinda freezes
  • this guys bypass my firewall
  • http log not working
  • block private data transfer is not working part ii
  • outpost 2009 and nod32 v3
  • a good av recomendation to match with my outpost pro
  • slow ping
  • how i can set different application rules for different networks in outpost
  • outpost firewall and a program called netshare
  • who is boring holes in my firewall
  • outpost firewall 2009 blocked printing
  • some cranks with udp filtering
  •  
  • help with ipblocker
  • ofp 2009 on an ics machine blocks port forward error
  • stop port opening pop up
  • safety overlap or overkill advice requested please
  • problem with firefox download
  • avast opf problem solved
  • block most policy not working
  • proto139
  • dumb question about web browser
  • outpost firewall blocks downloads
  • outpost firewall pro 2009 xbox live set up
  • problem with outpost firewall
  • outpost pro 2009 blocks gzip compression

  • About us -Site map -Advertisement -Jion us -Contact usExchange linksSponsor us
    Copyright© 2008 hzgn.com All Rights Reserved
    Site made&Support support@hzgn.com    E-mail: web@hzgn.com