iTnews
  • Home
  • News
  • Technology
  • Security

Attackers flock to Internet Explorer VML exploit

By Shaun Nichols
Sep 26 2006 9:56AM
Follow google news

Vulnerability becomes increasingly to spread trojans and spyware.

Attackers flock to Internet Explorer VML exploit
Security experts are noticing in increase in the number of exploits of the unpatched VML-vulnerability in Microsoft's Internet Explorer browser.

"More and more sites are being discovered to be using this exploit code," McAfee Avert Labs virus researcher Craig Schmugar told vnunet.com.

The inclusion of the exploit in a malware toolkit known as "WebAttacker" has made it easier to implement the exploit, according to Schmugar.

"[WebAttacker] is known for making it easier for someone with less skills to use this toolkit to install their payload. Tools have been posted for you to be basically able to plug in an URL and build an exploit that downloads and executes the file of choice," said Schmugar.

Reports surfaced last Wednesday of an unpatched vulnerability in Internet Explorer's Vector Markup Language (VML) that could allow attackers to take over control of a system. The vulnerability was first exploited through a group of adult websites that were hosted in Russia.

Over the weekend an existing data phishing operation started using the VML exploit in an effort to steal login data for financial websites, Roger Thompson, chief technology officer with Exploit Prevention Labs told vnunet.com.

The group sends out weekly spam emails informing the recipient that they have received a digital card through Yahoo Greetings. While users in the end visit the Yahoo website, they are first taken past an exploit server that infects their system with a trojan, Thompson explained.

The Trojan is designed to collect all the data that users enter in online forms, allowing the attackers to collect login information for banking websites and online payment services such as Paypal.

The attackers have been active for about four to five months. Prior to exploiting the VML vulnerability, they targeted a critical security hole in the Microsoft Data Access Components in Windows that was repaired in April.

Even when the group was targeting the patched vulnerability, the attackers harvested 200Mb of data every week, according to Thompson's research. He projects that the group will make even more victims now that it started exploiting the unpatched VML exploit.

In another attack, online criminal hacked into user accounts with hosting provider HostGator through a vulnerability in the cPanel hosting software that the provider had failed to patch.

The attackers tweaked the websites that were hosted through the provider to display a small 'iFrame' that directed users to a site hosting the exploit.

"What's interesting is the exploit in cPanel only functions if you are a member of the hosting service," Eric Sites, vice president of research and development for Sunbelt Software told vnunet.com. The security vendor first discovered the exploit through the hosting provider.

Microsoft is planning to release a patch for the VLM vulnerability on 10 October as part of its regular patch release cycle. Last Friday a group of independent researchers published an unofficial fix for the vulnerability.

The increasing use of the vulnerability however could force Microsoft to  release its patch sooner as patch, because security vendors are unable to add detection signatures for all the malware that is starting to exploit the vulnerability.

The SANS Internet Storm Center said that the some instances of the exploit have been found to include browser and operating system detection.

"Adding patterns for new [...] payloads is an arms race the anti virus vendors can't win. If you have the option, we suggest you use the work around of unregistering the DLL as indicated in our earlier diary entry," wrote Daniel Wesemann.  

Tom Sanders contributed to this report.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:
attackersexploitexplorerflockinternetsecuritytovml

Related Articles

  • US gov shortens cyber fix window to three days US gov shortens cyber fix window to three days
  • Anthropic releases Mythos-class model for public use Anthropic releases Mythos-class model for public use
  • Apple bumps up security in fresh operating system releases Apple bumps up security in fresh operating system releases
  • Meta accuses NSO Group of violating court order by WhatsApp spear phishing Meta accuses NSO Group of violating court order by WhatsApp spear phishing
Join our WhatsApp Channel

Partner Content

You meet the security standard. Shame no one can see it
Promoted Content You meet the security standard. Shame no one can see it
Take control of your connectivity with Telstra’s Adaptive Networks Centre
Partner Content Take control of your connectivity with Telstra’s Adaptive Networks Centre
Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
Partner Content Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
CommBank creates opportunities for technologists to upskill  with frontier AI companies
Partner Content CommBank creates opportunities for technologists to upskill with frontier AI companies

Sponsored Whitepapers

When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Researchers build self-replicating AI worm with BYO LLM

Researchers build self-replicating AI worm with BYO LLM

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.