Home » Internet Browser, Virus Attacks, Windows Security

Attackers approach which targeted 34 major corporations including Google and Adobe

11 March 2010 One Comment

BitDefender today has released an emergency update to shield users against the newly-discovered vulnerability in Internet Explorer versions 6 and 7. Microsoft has detailed the attack scenarios in security advisor #981374, announcing that a patch is being made in order to mitigate the vulnerability.
Users running Internet Explorer versions 6 and 7 can get infected by simply visiting a specially crafted web page that uses highly obfuscated JavaScript code to create a use-after-free error, such as a pointer being accessed after the deletion of an object.

Anatomy of the attack

Initially, the user is lured into visiting a specially crafted web link advertised either via spam messages or as posted on bulletin boards, social networks etc. The respective webpage contains JavaScript code obfuscated using the escape function. In order to bypass detection from various antivirus products, the script calls a secondary JavaScript that replaces a variable with the unescape string.

image006 Attackers approach which targeted 34 major corporations including Google and Adobe

The decrypted result is actually the malicious payload which will trigger a heap spray attack and will write the malicious code into the browser’s User Data area, making it persistent: every time the browser starts, the malicious code is executed without any subsequent intervention (drive-by download), which will result in the automatic download of a file called either notes.exe or svohost.exe (detected by BitDefender as Gen:Trojan.Heur.PT.cqW@aeUw@pbb).
This approach is similar to the one that has been used in targeted attacks against 34 major corporations including Google™ and Adobe™.

image007 Attackers approach which targeted 34 major corporations including Google and Adobe

Mitigating the risks

Microsoft announced that the exploit is already in the wild and that users will be provided with a fix as soon as possible. Since Internet Explorer 8 is not vulnerable to the attack, the next logical step would be to upgrade immediately.

See how Bitdefender modified the code to protect us from this vulnerability

In order to stay safe, BitDefender recommends that you download, install and update a complete antimalware suite with antivirus, antispam, antiphishing and firewall protection and to manifest extra caution when prompted to open files from unfamiliar locations.

You Might Also Like:

One Comment »

What's in your Mind!

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

beingPC is Do Follow and your comments surely becomes quality and solid backlinks !

You can use these tags:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> <pre lang="" line="" escaped="">

This is a Gravatar-enabled weblog. To get your own globally-recognized-avatar, please register at Gravatar.

CommentLuv Enabled

Get Adobe Flash playerPlugin by wpburn.com wordpress themes