Spyware Confidential
Larry Dignan, Jason Perlow, Tom Steinert-ThrelkeldSpyware pushers cash in big on zero day exploit
Summary
Nearly 50 malware threats being installed though the VML zero day exploit, including familiar names like Virtumonde, BookedSpace, webHancer, SurfSideKick, Qoologic (also known as Qoolaid), Zenotecnico, TagAsaurus, with some trojan downloaders and a backdoor thrown in the mix. Many of these use affiliate programs where the affiliate gets paid per install, so somewhere affiliates of these adware/spyware companies are making a killing off this zero day exploit, trashing computers with their crapware.
Topics
Blogger Info
I expect that most readers have already read about the latest zero day exploit, Microsoft Vector Graphics Rendering Library Buffer Overflow, discovered by Adam Thomas of the Sunbelt Software research team on Monday. I’m not going into detail on it — there is plenty of information about the exploit already, on ZDNet here, Secunia, US-Cert, SANS, and Microsoft Security Advisory (925568). George Ou has blogged that hardware enforced DEP stops the exploit from launching. A BleedingSnort signature has been created for the VML exploit.
SocketShield from Exploit Prevention Labs is said to block the exploit. SocketShield has a 30-day trial and the free Link Scanner on their website will check any URL for the exploit code. Sleazy porn sites are using this vulnerability to drop massive spyware on unsuspecting users. Roger Thompson of Exploit Prevention Labs called it a “massive malware run” with “drive-by attacks hosing infected machines with browser tool bars and spyware programs with stealth rootkit capabilities.”
SunbeltBLOG lists nearly 50 threats being installed though this exploit, including familiar names like Virtumonde, BookedSpace, webHancer, SurfSideKick, Qoologic (also known as Qoolaid), Zenotecnico, TagAsaurus, with some trojan downloaders and a backdoor thrown in the mix. Many of these use affiliate programs where the affiliate gets paid per install, so somewhere affiliates of these adware/spyware companies are making a killing off this zero day exploit, trashing computers with their crapware. I have not tested this exploit yet, but it sounds like kind of payload that would render the machine nearly useless.
Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.
Biography
More from “Spyware Confidential”
Related Discussions on TechRepublic
Did you know you can take part in these discussions with your ZDNet membership?Talkback Most Recent of 2 Talkback(s)
-
What do advertisers think?
"If you hire this company to spread your advertising, they will bundle your material with 50 kinds of spyware and sneak it onto the computers of people who visit porn sites.
As a result, people's computers will become so sluggish that they will pay money to make your advertising disappear.
Because of the potential PR hazard, the rates for this form of distribution are unusually cheap."
As sales pitches go, this one seems comparatively unlikely to be successful.
Anton Philidor09/21/2006 11:03 AM -
jj_forums05/04/2008 01:50 PM
Talkback - Tell Us What You Think
The best of ZDNet, delivered
ZDNet Newsletters
Get the best of ZDNet delivered straight to your inbox
Facebook Activity
Blog Roll
- All About Microsoft
- The Apple Core
- Between the Lines
- BriefingsDirect
- Collaboration 2.0
- Dev Connection
- A Developer's View
- Digital Cameras & Camcorders
- Ed Bott's Microsoft Report
- Emerging Tech
- Enterprise Web 2.0
- Five Nines: The Next Gen Datacenter
- Forrester Research
- Googling Google
- GreenTech Pastures
- Hardware 2.0
- Home Theater
- iGeneration
- India IT
- Irregular Enterprise
- IT Project Failures
- Laptops & Desktops
- Lawgarithms
- Linux and Open Source
- Managing L'unix
- The Mobile Gadgeteer
- Networking
- On Sustainability
- The Semantic Web
- Service Oriented
- Smartphones and Cell Phones
- Social Business
- Social CRM: The Conversation
- Software & Services Safari
- Software as Services
- Storage Bits
- Team Think
- Tech Broiler
- Tom Foremski: IMHO
- The ToyBox
- Virtually Speaking
- The Web Life
- ZDNet Education
- ZDNet Government
- ZDNet Healthcare
- Zero Day
Blog Archive
White Papers, Webcasts, & Resources
- SWITCH - Implementing Cisco IP Switched Networks v1.0In SWITCH, you will learn to plan, configure, and verify the ... (Global Knowledge) Download Now
- Live Webcast: Businesses Thrive with Google AppsBusinesses are increasingly turn to Google Apps as a versatile and ... (Google) Download Now
- Five Basic Steps for Efficient Space Organization within High Density EnclosuresOrganizing components and cables within high density enclosures need not ... (American Power Conversion (APC)) Download Now




