IT DRILLDOWN
 
NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 
 
 
LEADERSHIP
 
CIO Executive Programs
The Leader in Face-to-Face Education for Senior Executives

Offering regional and national programs, CIO (and CSO) events bring together some of the most respected names and thought leaders in information technology and security. Presented by CIOs and other senior level executives, these invitation-only programs offer timely topics and strong networking. Learn More »

 
CIO Executive Council
A Peer-Advisory Service and Professional Association for CIOs

Public Teleconferences
Join CIO Executive Council members and participate in the following live one-hour teleconferences:

* Transforming IT Teams
September 16

* Global CIOs: How to Lead on the World Stage
September 18

* Social Responsibility's Strategic Benefits
October 29

More / Register »

Learn more about the CIO Executive Council »



 
 
RESOURCE CENTER
 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 
 

Ad on MySpace Serves Up Adware to 1M PCs

 

July 20, 2006CIO

More than 1 million users of MySpace.com and other websites may have been infected with adware spread by a banner advertisement, according to iDefense, a computer security group.

The advertisement, for a site called deckoutyourdeck.com, appeared in user profiles on MySpace, an online community with at least 70 million users, said Ken Dunham, director of the rapid response team at iDefense, which is owned by VeriSign.

The ad exploits a problem in the way Microsoft’s Internet Explorer browser handles Windows Metafile (WMF) image files.

The browser vulnerability raised alarms in December after hackers distributed a specially crafted WMF image through e-mail, instant-messaging links and websites. If the image were opened, it could allow a hacker to gain control over a victim’s computer.

There are at least 600 websites that take advantage of the WMF vulnerability, Dunham said. Microsoft issued a patch for the problem in January, but many consumer computers may not have applied the patch, leaving them unprotected.

Unpatched machines are particularly vulnerable. Merely visiting a page with the deckoutyourdeck.com banner ad causes a download of a Trojan horse program. Those who have installed the patch see a prompt asking to download a file called "exp.wmf" when visiting a page with the advertisement, Dunham said.

Once it starts to run, the Trojan in the banner ad causes infected machines to contact multiple websites and download, among other unwanted programs, advertising software from PurityScan. The PurityScan software can cause unwanted pop-up windows to appear, and also tracks a user’s online activity.

Adware can be very difficult to remove, even for technically savvy users.

"The problem is hackers are using a variety of exploits, especially WMF, to illegally and silently install this [adware] on users’ computers," Dunham said.

MySpace has increasingly been targeted by hackers because of its popularity. MySpace officials contacted in London Thursday afternoon had no immediate comment. iDefense’s Dunham was not sure whether the banner advertisement has been taken down yet, but said that it could have been active for weeks.

Websites that distribute adware are paid based on the number of machines that get infected with the software, and hackers have created ways to spread the adware without user consent, increasing their payments.

iDefense estimated the number of infections caused by the deckoutyourdeck.com ad through a server in Turkey hosting the adware. The server appears to track the number of machines infected with the adware, and indicated that 1.07 million computers had downloaded the program, Dunham said.

A Whois search for deckoutyourdeck.com leads to a winding trail of registrants. Dunham said hackers frequently use false credentials when registering a domain name to cloud inquiries.

Loading...
 
 
ABCs
 

Just the basics, please. Sometimes we all need a refresher or we need to make sure our team and our colleagues are all on the same page.

Over 25 tutorials on everything from business intelligence to virtualization.

 
 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

The Challenge of Network Access Control -- Is a Managed Service the Answer?

White Paper: Businesses Thrive by Unifying Business Communications

The Latest Advancements in SSL Technology

How to Offer the Strongest SSL Encryption

Destination: Intelligent Data Center Automation

Build up or Tear down? See how UC makes sense with Nortel. Calculate your UC ROI

Protecting Data in a Highly Networked World

How the Mac is Becoming an IT Standard in the Enterprise

Storage Efficiency: The Key to Green Storage Operation

Oracle Database 11g: Real Application Testing & Manageability

Reap the Benefits of Unified Communications

Renowned Engineering Institution Chooses AMD Processor-Based Servers

New research validates telepresence solutions.

Configuration Assessment: Choosing the Right Solution

Best Practices for Providing Secure and Cost-Effective Remote Access

How Does Your IT Help Desk Measure Up?

Sheriff's Office Uses PocketCop to Access Police Databases from BlackBerry® Smartphones

The BlackBerry Solution Adds Significant Benefit to Toshiba

Network Immunity Manager Video

Spam-proof your business with Google's hosted security solutions

Global Crossing is the most viable alternative for voice, video and data

Plan better, manage better

Dell Latitude: Battery life up to 19 hours. Learn more

Video: 21st Century Networking for a 12th Century Castle

Speed, agility, flexibility - The HP BladeSystem c-Class

Effective Security with a Continuous Approach to ISO 27001 Compliance

Unified Communications Software: The Death of VoIP?

Getting in Compliance with Government Data Regulations

Forrester Total Economic Impact (TEI) report: Save Millions in Fraud Losses.

The Benefits of Data Deduplication for Data Protection in the Enterprise

File Integrity Monitoring: Secure Your Virtual & Physical IT Environments

Consolidation: Just the Starting Point for Virtualization

Maximizing Site Visitor Trust Using Extended Validation SSL

Standalone Server vs. Open Source Toolkits

Getting Off on the Right Foot: Avoiding Common Master Data Management False Starts

Efficient by design: Watch this flash demo of the Quad-Core AMD Opteron Processor

HP and Oracle deploy unbreakable computing infrastructure at Replacements, Ltd.

Optimizing Infrastructure Control

They Can't Steal What You Don't Have: Smart Security Choices for Mobile Workers

How to Calculate the ROI of Remote Support

31 Best Practices for the Service Desk

Heinz Uses a Wireless, Automated, Auditing process on BlackBerry® devices

Write an RFP for Master Data Management: 10 Common Mistakes to Avoid

HP Puts Its Disaster-tolerant Capabilities to the Test

Compuware.com - See how we make IT rock around the world

CA delivers deeper insight into your assets, resources, projects & services so you can make more informed IT decisions

Discover PMI's credentials and career path tools

SOA Educational Library at the TIBCO SOA Resource Center

TDWI Report shows strong validation for investing in predictive analytics

Learn about the software-based VoIP solution from Microsoft