Anatomy of an animated cursor attack

by ZDNet Author  |  April 6, 2007 11:10am PDT  |  Image 1 of 9

Previous  |  Next

animatedicons.jpg

The source of the problem

Earlier this week, Microsoft shipped an emergency out-of-band patch to block zero-day attacks against a code execution hole in the way Windows handles animated cursor (.ani) files. This gallery provides a visual look at elements of the hacker attacks, including malicious Web sites, the exploit in action and the adult-themed spam-run linked to the attacks.

Animated cursors are a feature that allows a series of frames to appear at the mouse pointer location instead of a single image. The Animated Cursors feature is designated by the .ani suffix.

Image source: F-Secure.

52
Comments

Join the conversation!

Just In

RE: The source of the problem (Anatomy of an animated cursor attack)
nimd4 17th Feb 2008
IMO it'd be nice to see PNG captures, or even GIFs, instead of blurry JPEGs here...
Why would anyone buy MS CRAP!
0 Votes
+ -
Free Crap
TechnoCritter 6th Apr 2007
I for one wouldn?t pay for any crap, but if you want some, I?ll give you mine for free.

In the mean time, why don?t you try posting something useful. Inciting anger in a discussion forum is kind of immature, don?t you think?
0 Votes
+ -
Why are you inciting anger ?
Intellihence 7th Apr 2007
Th previous poster only spoke of Windows , & here you are speaking of the poster in a lowly manner .
0 Votes
+ -
Why are you even
xuniL_z 7th Apr 2007
attempting to put coherent words together to form a sentence. You've repeatedly proven the only thing you can put together is a string of garbage that has no resemblence to anything besides what flows into a sewage treatment plant.

Only you could defend the original poster and define the ABMer crowd. I hope they are happy to have a poster child like you, it only proves once again that ABM also means Absent Brain Matter.
0 Votes
+ -
Microsoft garbage even affects the World Of Warcraft . Well only if you are using Windows , follow the link son http://news.bbc.co.uk/2/hi/technology/6526851.stm .
Anything associated with Microsoft will have it's problem .

As for me , I defend Steve Jobs , the liberator , the true leader , let's see if Bill Gates will follow suit now . There is alot of talk concerning Plays For Sure and the Zune , all the real news can be found at the BBC folks http://news.bbc.co.uk/2/hi/technology/6520801.stm .

As for Xunil , I take every word of his like I take every word of No-Axe , Loverock Davidson , and any other schmuck whose only defense is to belittle others that don't fit into their politics . I take your words and wipe my as* with it .


"In a world without walls and fences , who needs windows and gates ."
0 Votes
+ -
Well, yes
Badgered 9th Apr 2007
it affects WoW, and Credit Cards, and Banking passwords and everything else. If you don't patch your system. It's a problem, no doubt, but a patch was released to fix it. When Apple has a security flaw, they release a patch and you're fine with it. Why the different attitude toward MS?

"As for me , I defend Steve Jobs , the liberator , the true leader"

Careful there... you're sounding a wee bit like a Jim Jones fanatic.
Makes me wonder if thats who you are .
0 Votes
+ -
Alrighty then........... (NT)
Badgered 9th Apr 2007
.
0 Votes
+ -
Wow....
Hallowed are the Ori 9th Apr 2007
"In a world without walls and fences , who needs windows and gates ."


Hey genius, do you live in a house, or apartment, homeless shelter, etc?

Does it have walls?

Do those any of those walls have windows in them?

At my house they do.

And gee... when I came to work this morning, I had to stop and swipe my ID to get THROUGH THE SECURITY GATE IN THE FENCE.

Your "quote" is as stupid as you are... almost.
0 Votes
+ -
What a Maroon!
fd10801 9th Apr 2007
Have you ever heard of a play on words?

Try this on for size:

If the world of computers) had no (fires)walls or (spyware de)fences, there would be no need for (MicroSoft) Windows, or (Bill) Gates.

Get it now, Richard (as in Dick) Wahd (as in "wad")
0 Votes
+ -
Re: What a maroon
Hallowed are the Ori 9th Apr 2007
Have you ever heard of a play on words?

Why yes, yes I have. And that's not what that 'tard was doing.


Try this on for size:

If the world of computers) had no (fires)walls or (spyware de)fences, there would be no need for (MicroSoft) Windows, or (Bill) Gates.


LMAO... wow... that was quite the stretch to make up something to fit into there. And I'll bet you don't even realize how idiotic what you wrote is.

Congratulations, you've just made yourself appear as stupid as the other mental giant.

Make another wacko reply if you want, but I'll not waste my time reading it.

Good day.
0 Votes
+ -
0 Votes
+ -
Wow, and all this time I thought it was a reference to the fact that Windows is a limiting factor for what you can really do with your computer and Gates perpetuates a religion based around the fact that, even though people know better, Windows is the only way you can do something with a computer.

...I'll stick with OS X and Linux.

BTW, John, your personal attacks show how incredibly weak you really are. If you want us to think less of you, keep it up. happy
0 Votes
+ -
Intellihence:
justanitguy 9th Apr 2007
"As for me , I defend Steve Jobs , the liberator , the true leader".
Would you like some Kool-Ade now?
0 Votes
+ -
But I hate to inform you, that a Windows based machine is the easiest there is to use, the most compatible, has the broadest base of available applications, is the only realistic OS for gaming there is, and is relatively easy to secure. All it requires is that you do your best to shy away from being an idiot like opening unsolicited attachments, responding to clearly fraudulent emails, visiting suspicious or questionable websites and not forgetting to keep your OS and security applications updated.
0 Votes
+ -
As for me , I don't worry about any of those problems . I'll admit Windows has a lot more going for it except security & stability , but besides that , when you have more , that means you will have more problems .
0 Votes
+ -
um
Badgered 9th Apr 2007
The updates are automatically downloaded and installed at 3:00am. What amount of work are you referring to?
0 Votes
+ -
Apparently,
nix_hed 9th Apr 2007
You've never had a Windows machine "break" because of those updates AND you've never worked in an IT/IS department in your lifetime.

Automatic updates will break applications, even ones from Microsoft, and IT/IS departments do extensive testing of these updates before applying them to computers at work.
0 Votes
+ -
wrong on both counts
Badgered 9th Apr 2007
"You've never had a Windows machine "break" because of those updates AND you've never worked in an IT/IS department in your lifetime."

I have had a Windows machine (Server 2003) fail to boot because of an update. A simple "Boot to last know good configuration" fixed the problem.

I have worked in an IT department..... for the last 13 years.

Now, please stop assuming. You might want to consider that your experience with Windows OSes is not everyone's experience.
It's funny , people are always contacting me , Intel come fix my machine . I'm fed up with these people . I'm pretty sure they are the majority of Windows users . Heres another take as to why most people I know haven't patched their Windows machines in months , years . They have a slow crappy dial-up service .
0 Votes
+ -
really?
Badgered 9th Apr 2007
"It's funny , people are always contacting me , Intel come fix my machine."

They actually call you "Intel"?

"I'm fed up with these people."

Perhaps you should find another line of work then.
I have , problem is they still bug me .
0 Votes
+ -
Gaming and broadest base of programs, those are both correct. Then again, I have my Wii and 360 for gaming and 90% of programs that come out for Windows are poorly designed and have the stability of Jello?.

Everything else you stated is either untrue (you've never used Macintosh, have you?) or unrealistic (people, by nature, are stupid and want to open EVERYTHING; this is why we have virus outbreaks like we do). BTW, patching Windows is like playing Russian roulette - every once in a while, you get that one update that will break an application (how many times has this happened with MSIE over the last couple of months?) or the whole Windows installation (I know enough people that got the BSOD when upgrading their XP service pack). If you want to risk automatic updates, that's fine. I prefer to do my updates when I tell the computer to do them, so I know if any patches break any programs or the OS itself.
0 Votes
+ -
Yeah, the patch broke my machine
Big Scoddie 9th Apr 2007
I installed the so called "patch" and it killed my sound drivers. It gave me an error saying that the DLL had been moved in memory, or suchlike. I had to do a system state restore. I'd rather have sound and then have to make a concerted effort to avoid my addiction to all those quality Chinese Forums (as pictured above).
0 Votes
+ -
According to the images of the "exploit in action" above, it seems that you really only need to stay away from Chinese forums! I'm happy to do that, mainly because I don't speak Chinese!!
0 Votes
+ -
Microsoft wants to rule the world!
nomorems 7th Apr 2007
If you have ANYTHING to do with software (SAP. IBM and even HP) Microsoft is out to get you! They will stop at nothing less than total ownership of all bits and bytes!

The danger is Real! The Danger is Microsoft!...
0 Votes
+ -
Come on, there's only smoke and mirrors in that article, a lot of speculation and very little fact and without Windows we wouldn't be playing WoW - and don't pretend just because the Mac can play it, it had anything to do with the growth of 3D cards and on-line games.

And you want to elect a marketer as God huh - Steve Jobs. If Apple can rebadge something, he'll market it.

And I'm oh so worried about the ani exploit - oops what do you know - patched without me doing anything. If the Mac even get's near double figures usage they may have a market for the bad guys, until them keep your head in the sand and keep Apple lying in its adverts. Totally secure OS, no UAC equivalent and Apple invented the MP3 player and they never ever ripped off anything from Xerox. Best of all you only need one mouse button and one ever changing menu at the top of the screen.

The mushroom principle keep the users in the dark and feed em s**t. Glad to see it's working...
0 Votes
+ -
To intellihence

In a world full of intelligence and logic - why do we need you?
Why are you inciting anger . Just because microcrap can't make anything secure does not give you the right to bash others because of mirocraps shortcoming . If anything we need folks like Intellihence to speak the truth . If you haven't noticed , George Ou is hiding in the woodwork with the rest of his pals . You should be following suit , after all you are no different .
0 Votes
+ -
Intellihence
SO.CAL Guy 9th Apr 2007
everyone knows your not a tech your just an apple users who by the way has it's own problems with exploits

you can read about them all over the net they get patched and you guys put your heads in the ground and act like your untouchable but any one who has any kind of tech training at all knows any OS can be exploited

my self I've been working on and competing for well over 23 years and i have never had a virus' worm or any thing else to speak of..

the reason you guys are not hit any more than you are is you are just a small blip on the number of computers on the internet.

what does that mean your just not work the time if and thats a big IF apple ever gets out of the single digits of the % of desktop users then it will be Worth the virus and worm writers to get you

and you know what you will be easy pray you know why because everyone knows mac users are about as dumb as it gets when it comes to security matters and since social engineering is the tool used that gets 99% of the unwanted software on your computer you guys will be easy pickings

and i ask you what do you think the updates you get for what kind of kitty cat is mac using right now for the name of there OS. well anyways the updates are for exploits and OS bugs

but like i said when you hold such a small % of the desktop market share no one really cares enough to write about it and on the mac site they are cult follower to so they keep there mouths shut
It's funny how you group all Mac users together. As a former Windows user, I know that my Mac will eventually be a target for virus writers everywhere. It already is, as a matter of fact, but since the viruses are so few and far between, Apple gets a chance to patch them into not working. Linux, BSD, and any other UNIX is the same way, where the security is eventually put into the OS itself and isn't dependent upon a 3rd-party antivirus solution.

BTW, jus a thought - if you wish to call Mac users dumb, you should really work on grammar and syntax.
You talk a lot of cash sh*t my friend . Get your facts straight , if you could have bought yourself a clue , you would have known I use Mac , Linux & Windows . Well I don't really use Windows I just patch the C.R.A.P. all the time & I'm fed up with it . As for the rest of your mumbo jumbo , keep it , we don't want to hear about your useless rants . This is a Microsoft user --->Oh poor is me , Microsoft continues to stick it to me , why oh why do I put up with it . Intellihence ---> Why do you put up with it ? I'll tell you why , because you don't know any better . Now move along little kiddo . If anything the more problems that hatch up for Microsoft , the more MONEY I make .
0 Votes
+ -
WOW!!!
justanitguy 9th Apr 2007
I love this! Intellihence patting himself on the back. "If anything we need folks like Intellihence to speak the truth ."
I would be more cautious if I were you, Intellihence-you might dislocate your shoulder that way.
0 Votes
+ -
It beats what most Windows users do .
Intellihence 9th Apr 2007
Stuffing their heads up their royal arses !
0 Votes
+ -
INTELLECTUALS GONE BERSERK
BALTHOR 9th Apr 2007
What's in it for these hacker attackers?Is it the joy of using the mind to subjugate,dominate,intimidate,repress,terrorize,and all that other stuff that warped intellects do.This is just another new virus.
0 Votes
+ -
Computer Viruses=Terrorists
nix_hed 9th Apr 2007
"Hey terrorists, terrorize this!"

(Sorry, I saw terrorize in that last post and couldn't help it.)
0 Votes
+ -
For my last note .
Intellihence 9th Apr 2007
I would like thank everyone for doing such a good job here today . I really do enjoy the bashing . As I have for the past couple of years here . You see my reputation precedes me , I can still get all the Microsoft roaches to come out of the woodwork .
0 Votes
+ -
just as
Badgered 9th Apr 2007
"I can still get all the Microsoft roaches to come out of the woodwork."

Just as any story regarding MS gets ABM roaches to creep out and join them. Good work!
0 Votes
+ -
Instead you make a foolish attempt at spinning my remarks . Nice try , but you get no cigar .
why would you expect an original reply?
0 Votes
+ -
reply
pajames@... 9th Apr 2007
My goodness...we certainly have a fine opinion of ourselves, don't we?

I'm new to this site, so I must confess that I have never heard of you. Somehow I managed to struggle along.

I am awaiting eagerly the release of your new bullet-proof OS.

The point being that it takes no skill or talent to whine and throw rocks. A few helpful notions might be a refreshing change ("get Linux" does not qualify).

Not aiming at you personally, but the whole class of those who seem to get a thrill out of putting down those less fortunate.
0 Votes
+ -
Well there are choices .
Intellihence 9th Apr 2007
Some choices are better than others . I'll admit nothing is perfect , for if it were , ZDNET and many others alike would be put out of business . Imagine that , a perfect OS in a perfect world . I'll continue to stick with Macintosh , I've never had a problem with any of my Macs over the past ten years . So my decision to stick with Apple is the right choice .
0 Votes
+ -
Choice of OS... Business driven
notme403@... 10th Apr 2007
There are many business applications which only run on Windows. In the broadcasting world, for instance, the sales force uses applications which run on Windows. In the world of the stand - alone PC user or the graphics developer, you have the option to use Linux or Mac. Until there is a market demand for cross - platform business - specific applications the choice shall continue to be Windows in those millions of hosts.
0 Votes
+ -
Intelligent threads of thought
tulsatech 9th Apr 2007
Instead of attacking each other about their choice of OS or defending fanatical belief systems, why not stay on subject and comment directly about the the story at hand?

Does anyone have anything constructive to add to the discussion about cursor attacks?

I for one would be highly interested in thoughtful discussion about how we can eradicate the usenet nd internet of such irritations. It's bad enough that we constantly have to create new filters to thwart spam from filling our inboxes to overflowing. Let's instead of priding ourselves on how crash proof one Os is over the other come up with a concerted effort for ALL camps to attck a common foe. The cretains who create these malwares and security expolits.

Then the one who successfully manages to slay this final hydra can truly boast that he has the best OS.
0 Votes
+ -
OK...But WHY...
QueenMama 9th Apr 2007
...in the world would you support ANY OS that allows the number of hacks that
Windows/Vista allows? Yes, I believe my OS is the best. If I put my thinking cap on,
however, I just cannot...for the life of me...understand the M$ users mindset. OK,
definitely better gaming. But is that the ONLY reason to stay with an OS that is
buggy, insecure, and...let's face it...dangerous? So, if it's gaming, isn't the purchase
of a Wii, or PS3, or whatever a better option? I mean, I am REALLY stumped! Of
course, OMHO.
0 Votes
+ -
Console gaming vs. PC/Mac...
Raymond Danner 9th Apr 2007
There's one flaw (other than this comparison being OT for this thread) and that's the fact that PC games eventually come down in price. By and large, price drops for console games usually means the console supporting the game is about to vanish.

As for the Mac and Microsoft bashing in this thread? Folks, face it: Neither OS is perfect, and both are being exploited. If Microsoft and Apple had equal market share, the Mac OS would be just as fragile as Windows has proven to be. And the one-button Mac mouse? I've never been keen on the idea. Give me a 3-button mouse and OS/task shell capable of understanding chording so I don't have to use both the keyboard AND mouse to do everyday things any day. (and yes, XWindows (*nix) does understand chording. Has for years now.)

It's curious to see how little progress there is in the Windows camp, actually. Just about every other OS has had a VDM (Virtual Desktop Manager) for years now. Windows still doesn't have one, unless you use a third-party Explorer replacement or Microsoft's lame and very brain-dead VDM... (Come on. Two desktop support? Gimme six at least!) I've been known to use up to nine before, actually.

As for security? Vista fails that test, too. (Big surprise there. NOT!) Linux and the BSDs may not be perfect, but they do have a better track record for security. I expect I'll be installing Linux soon, rather than use Vista.
Firstly, let me just say I'd love a mac. I'd love one because it gets less viruses, and it just looks so damn cool. The only thing stopping me is price.

But - put your thinking caps on - why does a mac get less viruses than Windows? Why does Windows get more viruses than any of the other OSes? First, consider that program compatability isn't always guaranteed with one or the other, as some are made specifically for one operating system. This would - if I'm not horribly mistaken - seem to show that each operating system works in a different way to the next one.

Now consider that Windows has a 90% share in the market, for two reasons: Dell ****** it out to everyone, and I know very few people who don't get their computer from dell; and as Dell does so, more people know about it, the word spreads, and everyone wants (and gets) Windows. Hell, quite a lot of people don't even know what a Mac is (That's the quite a lot of stupid people who're out there, by the way).

So why would people make viruses that would only infect around 9/10% of computer users? They wouldn't, unless they had a specific target in mind. They would go for the big 90% chunk that is Windows. Their virus wouldn't be compatible with the other OSes, but it wouldn't make Windows any less secure.

In fact, logically Windows should be more secure (not that it is. Talking logically here). As there are all these exploits and viruses that target it, Microsoft are constantly releasing patches and bugfixes. When was the last time you saw Apple release a bugfix? Does this mean a Mac has no bugs? Impossible - there's no way an Operating System can be completely impervious to virus attacks; it means that no one is exploiting the bugs in a Mac.

QED
0 Votes
+ -
I loved the video . . . (cue Church organ music dramatic and loud)

(Cue minister?s voice . . . Accent Like Harry Connick?s ?The REV? from the movie Independence day?

We are gathered here together to share the worship of the PC in the Church of the Internet that welcomes all denominations to our fold who gather here daily in their righteous life of daily confirmation of our belief in the the supreme PC (PC=Personal Computer, Apple makes them too)

We have gather together with our brothers and sisters from the Church of Apple, our brothers and sisters from the Church of Microsoft, and our brothers and sisters from the Church of Linux to gather in mutual peace and harmony and to worship our one true God, our PCs.

Brothers and sisters, do not go out into the light! For there you will find evil life, and sunlight!

I have a dream! That one day, all OS?s will unite in a virtual world and deny the evil real world of human interaction and living.

I have a dream that sectarian bickering and the true brotherhood of the the Church of the Internet will unite all our brothers and sisters in the endless dialogue and freedom that the virtual world provides.

Brothers and sisters we can treat all encounters as less than human, and not fear reprisals from the real world in our anonymity.

We can treat with contempt all who have a real life, and do not share our belief in the all powerful and mighty Internet!

Because they cannot hit us, find us, or know who we truly are . . . WE ARE FREE!

Free to post, to condemn, to quote the great books of our codes and and manufacturing.

Yea though we must sometimes walk through the valley of reality, we WILL fear no evil, for in virtuality there is the freedom of no consequences for our words and actions!

The meekest and least of you can gird thyselves in rhetoric, and never have to produce anything yourselves, for no one can find you and discover you actually flip hamburgers at the Local McDonalds in the evil real world.

But I dream of a day, when we all unite, and value the diversity of our fellow PCrs, regardless of the color of their OS or its trademark.

I have a dream!

That one day we will unite, and realize the worth of our natural denominations and cease these petty battles and claims of our superiority. That one day we will realize that all are present in the Church of the Internet, and it matters not how they got here!

That all are here to worship the almighty PC is all that matters regardless of how your OS got you here, or the ministers of hate that divide us.

For verily I say unto you! If you do not unite, you surely will have to go out into the sunlight, and get a real life.

I do not care about the color of a PCs skin! As long as you follow the truth of the Church of the Internet, you will be saved!

Your OS is only a path, one of many, leading you here to the freedom of the light of the One true Internet.

Regardless of your path, your self indignant righteousness, if you got here, it is good.

Be not overly proud of the vehicle of your choice to arrive at the true path.

If it got you here it is good, and it works.

Amen.
0 Votes
+ -
Attacks
Sowhatsupyouranus@... 9th Apr 2007
If everyone stood back and took a look you would all see why there are attacks. Reason #1 Arrogant people running m$. #2 the challenge put out by a arrogant CEO. #3 The use of old soft said to be new, yup built from the bottom up. #4 We could not steal something new.
I use m$ os for fun(when I do not want to use any brain power), Linux when I am serious(when I want to exercise my brain) and (knock on wood) had no problems. Oh the die hard ms'ers will cry, but to you I say repeat out loud very loud till you understand: i am we todd it. i am sofa king we todd it.
IMO it'd be nice to see PNG captures, or even GIFs, instead of blurry JPEGs here...

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity