On CBSNews.com: Aniston: What Jolie Did Was "Uncool"
BNET Business Network:
BNET
TechRepublic
ZDNet

September 20th, 2006

Spyware pushers cash in big on zero day exploit

Posted by Suzi Turner @ 9:24 pm

Categories: Spyware/adware warnings, Spyware/adware news

Tags:

I expect that most readers have already read about the latest zero day exploit, Microsoft Vector Graphics Rendering Library Buffer Overflow, discovered by Adam Thomas of the Sunbelt Software research team on Monday. I’m not going into detail on it — there is plenty of information about the exploit already, on ZDNet here, Secunia, US-Cert, SANS, and Microsoft Security Advisory (925568). George Ou has blogged that hardware enforced DEP stops the exploit from launching. A BleedingSnort signature has been created for the VML exploit.

SocketShield from Exploit Prevention Labs is said to block the exploit. SocketShield has a 30-day trial and the free Link Scanner on their website will check any URL for the exploit code. Sleazy porn sites are using this vulnerability to drop massive spyware on unsuspecting users.  Roger Thompson of Exploit Prevention Labs called it a "massive malware run" with "drive-by attacks hosing infected machines with browser tool bars and spyware programs with stealth rootkit capabilities."

SunbeltBLOG lists nearly 50 threats being installed though this exploit, including familiar names like Virtumonde, BookedSpace, webHancer, SurfSideKick, Qoologic (also known as Qoolaid), Zenotecnico, TagAsaurus, with some trojan downloaders and a backdoor thrown in the mix. Many of these use affiliate programs where the affiliate gets paid per install, so somewhere affiliates of these adware/spyware companies are making a killing off this zero day exploit, trashing computers with their crapware. I have not tested this exploit yet, but it sounds like kind of payload that would render the machine nearly useless. 

  • Talkback
  • Most Recent of 2 Talkback(s)
RE: Spyware pushers cash in big on zero day exploit
http://www.analogstereo.com/lamborghini_diablo_owners_manual.htm... (Read the rest)
Posted by: jj_forums Posted on: 05/04/08 You are currently: Logged In | Log out
What do advertisers think? Anton Philidor   | 09/21/06
RE: Spyware pushers cash in big on zero day exploit jj_forums   | 05/04/08

What do you think?

3 Trackbacks

The URI to TrackBack this entry is:
http://blogs.zdnet.com/Spyware/wp-trackback.php?p=852

  • spyware pushers cash in big on zero day exploit
    nearly 50 malware threats being installed though the vml zero day exploit, including familiar names like virtumonde, bookedspace, webhancer, surfsidekick, qoologic (also known as qoolaid), zenotecnico, tagasaurus, with some trojan ...

    Trackback by spyware tool — September 20, 2006 @ 9:24 pm

  • Spyware pushers cash in big on zero day exploit
    Spyware pushers cash in big on zero day exploit ZDNet Blogs - Many of these use affiliate programs where the affiliate gets paid per install, so somewhere affiliates of these adware/spyware companies are making a killing off this zero ...

    Trackback by The Computer Masters Blog — September 21, 2006 @ 9:07 am

  • Food Calendar (Suzi orman)
    ZDNet Blogs - Spyware pushers cash in big on zero day exploit by ZDNet ’s Suzi Turner — Nearly 50 malware threats being installed though the VML zero day exploit, including familiar names like Virtumonde, BookedSpace, webHancer, ...

    Trackback by SUZI ORMAN — September 27, 2006 @ 9:39 am

advertisement

Recent Entries

Top Rated

    advertisement

    Archives

    Favorite Links

    ZDNet Blogs

    advertisement
    Click Here