More Than 2K Sites Now Exploit .ANI Security Vulnerability

By
Tue, April 10, 2007

IDG News Service (London Bureau) — More than 2,000 unique websites have been rigged to exploit the animated cursor security flaw in Microsoft's software, according to security vendor Websense.

Those websites are either hosting exploit code or are redirecting Internet users to sites with bad code, Websense's blog reported Monday.

The number of websites engineered to exploit the problem has jumped considerably since the vulnerability was publicly disclosed by Microsoft on March 29. It will likely continue to rise until patches are applied across corporate and consumer PCs, said Ross Paul, senior product manager for Websense.

Hackers are hoping to catch some of the millions of unpatched machines.

"What we've seen is that exploits tend to be used as long as they are effective," Paul said.

Last week, Microsoft broke from its regular patching routine and issued an off-schedule fix due to the danger of the vulnerability, which occurs in the way Windows processes .ani or Animated Cursor files, which allow websites to replace the regular cursor with cartoonish alternatives.

The flaw affects nearly all versions of Microsoft's Windows OS and is the third zero-day flaw that Microsoft has patched out of schedule since January 2006.

Companies tend to patch their machines on fixed schedules and may not immediately apply a patch when it's released, Paul said. Home users may automatically receive the patch if they are using Windows XP Service Pack 2, but users of older Windows OSes will not.

That's especially dangerous since the .ani problem doesn't require user interaction for a machine to be infected, said Graham Cluley, senior technology consultant at Sophos. Merely viewing a website engineered to exploit the vulnerability with an unpatched machine can result in an infection.

As a result, security analysts are generally recommending to apply the patch, even though Microsoft said Friday it was fixing compatibility problems with some applications.

"We are recommending this is a patch you really need to install now," Cluley said.

Websense said that attackers from Eastern Europe and China appear to be at the heart of the efforts. Groups in the Asia-Pacific region and China are exploiting the vulnerability, mainly on machines located in Asia, in order to gain credentials for popular online games such as Lineage, Websense said.

A second group in Eastern Europe, which has been known to use other vulnernabilities in Microsoft's software to install malicious software on machines, "have also added the .ani attacks to their arsenal," Websense said. Those attacks are directed at servers and users in the United States.

The motivation of the Eastern European group appears to be collecting banking details using form-grabbing software or keyloggers, Websense said. The group has also been known to try to use exploits to install bogus antispyware programs.

One technique used by the hackers is to find a vulnerable Web server and cause its viewers to be redirected to another website that will exploit their machine using the .ani problem, Paul said.

The hackers are also planting iframes—hidden windows that can allow code such as JavaScript to run—to activate an exploit. Paul predicts there may be more to come: "I don't think we've seen the last of this."

As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make to help achieve project success.
Learn how Gartner's criteria for next generation IPS helps organizations achieve effective threat prevention despite changes in network communications, new applications, and changes in the threat landscape.
3 minute Flash video - overview of the need for and value of Configuration Control.
Cloud deployments are playing a critical role in propelling innovation for many companies. At the same time security has become the #1 one of the top concerns for IT and business leaders as they migrate into the cloud. In this webinar, learn from Accenture discusses how to recast the cloud as a "fresh chance to rethink your approach to security."
As greater numbers of datacenter servers transition from the physical to the virtual world, the components of virtualization success come to the fore. What scores of organizations have discovered is that success is derived from an optimal pairing of the right software platform with the right hardware platform.
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn about VMware customer, Navicure, and their experiences testing and evaluating the recovery manager, their progress in implementing it in their environment and their advice other customers considering using vCenter.
Many enterprises have discovered that the use of virtualization to support desktop workloads creates a range of significant benefits. These benefits include price efficiencies, improved IT management and greater agility and choice for end users.

This VMware sponsored webcast with IDC will provide both quantitative measurement of the business value -- defined as the expected ROI -- and qualitative analysis associated with the use of VMware View™. IDC will also provide an analysis of the View Composer and ThinApp™ features of VMware View, including the business value of these solutions and an overview of how they work.

Attend this webcast to learn about:
- Challenges and barriers that might impede the adoption of desktop virtualization
- Navigating roadblocks to facilitate a strategic implementation
- Optimizing qualitative and quantitative benefits to IT and your business
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Sponsored Links
Resource Center