Forum     

Go Back   Digit Technology Discussion Forum > News > Random News
Register FAQ Calendar Mark Forums Read

Random News Non-technology news that you feel members should know about. NOTE: Sources to be mentioned at the beginning of each post.


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 25-11-2006, 05:50 PM   #1 (permalink)
a_g = JPKN
 
s18000rpm's Avatar
 
Join Date: Mar 2006
Posts: 5,168
Talking Free P*rn via Internet Explorer Vulnerability


"Free porn via an Internet Explorer Vulnerability? It sounds too good to be true, doesn't it? When was the last time anything good came out from a vulnerability affecting Microsoft's products? Well, joking aside, it does sound too good to be true. This because the free porn offering is an integer part of a social engineering scheme targeting users of unpatched versions of IE prior to Internet Explorer 7.

Sophos, an integrated threat management solutions provider, has warned of the discovery on an aggressive spam campaign promoting free pornography. But, instead of free explicit images and videos, victims will be hit with a Trojan horse. “Psyme-DL exploits a Microsoft Internet Explorer vulnerability, MS06-014, and when the weblink is accessed using Firefox, a message is displayed requesting the user to change browser,” explains Sophos. So if you use Firefox, you are safe. Also, Internet Explorer 7 and prior completely patched versions of the browser are not affected by this vulnerability.

The spammed messages contain a link redirecting the victims to a malicious website designed to download Psyme-DL via the ADODB stream vulnerability. No user interaction is necessary as the flaw allows for remote code execution.

“Despite the numerous warnings users have probably heard about safe computing and appropriate online behavior, emails with racy subject lines still seem hard to resist for some users,” said Carole Theriault, senior security consultant for Sophos. “By infecting machines belonging to users who thought they might steal a peak at some free porn, this malware campaign leads victims down a rathole they might feel embarrassed to be found in. The author of Psyme-DL is not just looking to humiliate but is also attempting to take control of the machines in order to spy, steal or cause havoc on PCs.” "

Source:: SoftPedia News
__________________
★-----------�-----------★
ASUS K53SV SX520D + BF3
★-----------�-----------★

Last edited by s18000rpm; 25-11-2006 at 06:24 PM.
s18000rpm is online now  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 25-11-2006, 07:10 PM   #2 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default

the key-words are 'unpatched ie'. quite posbl ! the porn sites mustve thought, lets hammer at a browser used by the majority, viz ie. so best to use an updated os/browser always ! nice piece of info, thanx !

btw, heard of Heatseek !? its is a pornography focused browser. the point of this software is to make porn browsing more efficient and more secure. the browser is available on windows machines only, and is built on top of internet explorer.
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 26-11-2006, 03:09 AM   #3 (permalink)
a_g = JPKN
 
s18000rpm's Avatar
 
Join Date: Mar 2006
Posts: 5,168
Default Re: Free P*rn via Internet Explorer Vulnerability

^^ you know that HeatSeek browser Installs a Trojan.Generic

Curiosity might have Fcked up my PC , thank goodness i have Kaspersky on me side to forgive my sometimes Curious actions.
__________________
★-----------�-----------★
ASUS K53SV SX520D + BF3
★-----------�-----------★
s18000rpm is online now  
Old 26-11-2006, 06:41 AM   #4 (permalink)
Alpha Geek
 
caleb's Avatar
 
Join Date: Sep 2006
Location: Mumbai
Posts: 581
Default Re: Free P*rn via Internet Explorer Vulnerability

Quote:
Originally Posted by s18000rpm
"Free porn via an Internet Explorer Vulnerability? It sounds too good to be true, doesn't it? When was the last time anything good came out from a vulnerability affecting Microsoft's products? Well, joking aside, it does sound too good to be true. This because the free porn offering is an integer part of a social engineering scheme targeting users of unpatched versions of IE prior to Internet Explorer 7.

Sophos, an integrated threat management solutions provider, has warned of the discovery on an aggressive spam campaign promoting free pornography. But, instead of free explicit images and videos, victims will be hit with a Trojan horse. “Psyme-DL exploits a Microsoft Internet Explorer vulnerability, MS06-014, and when the weblink is accessed using Firefox, a message is displayed requesting the user to change browser,” explains Sophos. So if you use Firefox, you are safe. Also, Internet Explorer 7 and prior completely patched versions of the browser are not affected by this vulnerability.

The spammed messages contain a link redirecting the victims to a malicious website designed to download Psyme-DL via the ADODB stream vulnerability. No user interaction is necessary as the flaw allows for remote code execution.

“Despite the numerous warnings users have probably heard about safe computing and appropriate online behavior, emails with racy subject lines still seem hard to resist for some users,” said Carole Theriault, senior security consultant for Sophos. “By infecting machines belonging to users who thought they might steal a peak at some free porn, this malware campaign leads victims down a rathole they might feel embarrassed to be found in. The author of Psyme-DL is not just looking to humiliate but is also attempting to take control of the machines in order to spy, steal or cause havoc on PCs.” "

Source:: SoftPedia News
Thanks for the info
Am I happy that I updated my PC to IE7 just 4 days ago.
Hey about sophos, when I used to work in England that company used to use sophos and the IT director there, used to say that it is the best Antivirus.
__________________
Intel D805 on D101Ggc/XFX8600GT/Transcend 2GB DDR /250+160GB SATA+WD250GB External/Epson StylusCX5500/LG DVDRW/Acer19" LCD/ VISTA HP & Sabayon 3.3/Compaq Presario V6112AU 2GB Ram/nVIDIA6150/VISTA HP
caleb is offline  
Old 26-11-2006, 07:37 AM   #5 (permalink)
In The Zone
 
drsethi's Avatar
 
Join Date: Jan 2004
Location: Amritsar
Posts: 220
Default Re: Free P*rn via Internet Explorer Vulnerability

I never visit pornographic sites.
They always demand money and infect your computer.
drsethi is offline  
Old 26-11-2006, 08:20 AM   #6 (permalink)
The pWnster
 
Vyasram's Avatar
 
Join Date: Oct 2004
Location: Karaikudi,TN
Posts: 841
Default Re: Free P*rn via Internet Explorer Vulnerability

Quote:
Originally Posted by drsethi
I never visit pornographic sites.
They always demand money and infect your computer.
ppl need open-source porn these days
__________________
Sigs suck
Vyasram is offline  
Old 26-11-2006, 09:38 AM   #7 (permalink)
Hanging, since 2004..
 
tarey_g's Avatar
 
Join Date: Aug 2004
Location: hanging..
Posts: 3,334
Default Re: Free P*rn via Internet Explorer Vulnerability

Quote:
Originally Posted by anandk
the key-words are 'unpatched ie'. quite posbl ! the porn sites mustve thought, lets hammer at a browser used by the majority, viz ie. so best to use an updated os/browser always ! nice piece of info, thanx !

btw, heard of Heatseek !? its is a pornography focused browser. the point of this software is to make porn browsing more efficient and more secure. the browser is available on windows machines only, and is built on top of internet explorer.
Hmmm heatsek... i think everyone should try that . Btw the best porn browser is safari on mac .


Quote:
Originally Posted by Drsethi
I never visit pornographic sites.
They always demand money and infect your computer.
Internet is big, you will find everything here,free.
__________________
Windows 8 ? :lol:
I have a better OS installed, people call it Windows7 8-)
tarey_g is offline  
Old 26-11-2006, 09:59 AM   #8 (permalink)
a_g = JPKN
 
s18000rpm's Avatar
 
Join Date: Mar 2006
Posts: 5,168
Default Re: Free P*rn via Internet Explorer Vulnerability

Hey guys, didnt you read my second post here , the HeatSeek browser Installs a Trojan.Generic in this location=> "C:\Documents and Settings\<User Account>\Local Settings\Temp\is-PU9HQ.tmp\is-P35GQ.tmp"

Kaspersky AV detected it.

try this NeoDownloader Lite 2.1c (freeware) it has that section.
__________________
★-----------�-----------★
ASUS K53SV SX520D + BF3
★-----------�-----------★

Last edited by s18000rpm; 26-11-2006 at 10:05 AM.
s18000rpm is online now  
Old 26-11-2006, 10:07 AM   #9 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default

Quote:
Originally Posted by s18000rpm
^^ you know that HeatSeek browser Installs a Trojan.Generic
didnt know that ! never tried it !

true with kaspersky on ur side one can afford to be experimentative and reckless sometimes...
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by Tenida
- by iinfi
- by icebags
- by gohan89
- by gforz
- by Who

Advertisement




All times are GMT +5.5. The time now is 09:14 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2