|
This topic comprises 2 pages: 1 2
|
Author
|
Topic: Adware...Kill me NOW
|
|
|
|
|
|
|
|
|
|
|
|
|
|
David Buckley
Jedi Master Film Handler
Posts: 525
From: Oxford, N. Canterbury, New Zealand
Registered: Aug 2004
|
posted 09-23-2004 05:07 PM
Oh and it just gets better.
From just a couple of days ago on thereg: http://www.theregister.co.uk/2004/09/22/opt-out_exploit
Click here to become infected By John Leyden Published Wednesday 22nd September 2004 09:15 GMT
Users should be wary of pressing the 'click here to remove' link on spam messages because it serves to confirm to spammers that junk mail messages are being read. Such email addresses can be sold at a premium to other spammers.
That's reason enough to simply delete spam messages, but a junk mail message doing the rounds today provides an even more compelling reason. Selecting the 'click here to remove' link on messages blocked by MessageLabs today triggers an attempt to load malicious code onto potentially vulnerable Windows PC.
MessageLabs is blocking spam linking to the domains www. xcelent.biz (space deliberately inserted) which, if users click on the remove link and scroll down the page triggers a DragDrop JavaScript exploit. This uses an IE bug to download and run an EXE file, currently been analysed by MessageLabs.
Alex Shipp of MessageLabs writes: "I have not finished analysing the EXE currently hosted (currently called windows-update.exe), but the spammers can change this at any time by uploading a new Trojan. Typically, your machine may be turned into an open proxy, have passwords extracted, and keyloggers installed.
"So not only do you confirm your email address to the spammers, you also get to host their next spam run, and get your bank account cleaned out," he adds.
The US's CAN-SPAM Act requires junk mailers to put an opt-out link on their wares. It comes as little surprise that this feature is been taken advantage of in a social engineering exploit; but it does illustrate the security problems of the opt-out approach that were always apparent to security experts - and ignored by legislators.
| IP: Logged
|
|
|
|
All times are Central (GMT -6:00)
|
This topic comprises 2 pages: 1 2
|
Powered by Infopop Corporation
UBB.classicTM
6.3.1.2
The Film-Tech Forums are designed for various members related to the cinema industry to express their opinions, viewpoints and testimonials on various products, services and events based upon speculation, personal knowledge and factual information through use, therefore all views represented here allow no liability upon the publishers of this web site and the owners of said views assume no liability for any ill will resulting from these postings. The posts made here are for educational as well as entertainment purposes and as such anyone viewing this portion of the website must accept these views as statements of the author of that opinion
and agrees to release the authors from any and all liability.
|