VIA Root
VIARoot Security News Security alerts Business IT security Services Security Tools About VIARoot
China's attacks used IE6 zero-day vulnerability
Search
Security News
security
Mathew J. Schwartz, InformationWeek
2010-08-27 14:11:17
Email and peer-to-peer networks also rank as significant venues for malware attacks, which have increased slightly in the U.S. but declined in Europe, according to Panda Security.
intel
Hugo Jean, Heptacube Inc.
2010-08-24 14:51:53
The motivation behind the $7.68 billion deal is unclear, but Intel says it wants to integrate computer security into its hardware.
IT Directory
Wiseleap Solutions Inc.
Founded in 2005, Wiseleap Solutions Inc.'s mission consists in providing companies with the information necessary to make cri [...]
IT Ration Consulting Inc.
IT-Ration Consulting inc has been a NetSuite Partner since 2005 and helps your enterprise grow by aligning your Information T [...]
HumanWare
Empowering People Focused on enhancing the lives of people with visual and learning disabilities, HumanWare provide [...]
By Hugo Jean, Heptacube Inc.
IElogo
2010-01-15 11:08:18

After the mid-December attacks on Google and at least twenty more companies, including Adobe, experts have been busy trying to find the attack vector used by the hackers. Security firm McAfee announced yesterday that it had found out the attacks had been perpetrated using a zero-day vulnerability in Microsoft Internet Explorer. The software giant quickly realeased a security advisory detailing the previously unknown vulnerability and ways to prevent being infected through it.

Google and McAfee, among others, have presented these attacks as being "highly sophisticated and targeted". McAfee's CTO George Kurtz maintains in his blog post that such attacks have been seen in the past targeting government infrastructures, but insists on the fact that this time was the first where the commercial sector was targeted by those “advanced persistent threats” (APT). Those are "designed to infect, conceal access, siphon data or, even worse, modify data without detection." It could be the first of many.

McAfee named this threat "Aurora", after the name found in the filepath of one of the source codes used in the attack. They maintain that Aurora "is changing the cyberthreat landscape", as it looks like hackers are not using their most sophisticated attacks only to disturb government activity or gain monetary profit like they were doing in the past. They are now after something maybe even more valuable: intellectual property.

Initial reports maintained that the hackers had used rigged PDF files for their attacks, but McAfee has found nothing relating them to Adobe's products. Instead, Microsoft's advisory says the culprit is an invalid pointer reference in Internet Explorer. Targets have to be lured into downloading a malware by clicking on a specially crafted link in an email or downloading an email attachment that seems legitimate, for instance. Once it is installed, the remote attacker can control the victim's computer as he wishes, having all of his or her user rights across the network.

While the vulnerability in question is present in Internet Explorer 6, 7 and 8, McAfee said that the hackers' exploit code was only used in conjunction with IE6. Nonetheless, Microsoft's security advisory confirms that all three versions are at risk and recommends enabling Data Execution Protection (DEP) on IE6 and 7. It is activated by default on the latest version of the browser. Also, setting Internet and local intranet security zone settings to "high", which will show a prompt before running ActiveX and Active Scripting, is a good protection. Additionally, Internet Explorer on Windows Server 2003 and 2008 is set to a "high" security level by default.










Tags
Adobe China Google hack IE6 InternetExplorer McAfee Microsoft