NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Free Porn via Internet Explorer Vulnerability

Emails with racy subject lines still seem hard to resist

By Marius Oiaga, Technology News Editor

25th of November 2006, 11:38 GMT

Adjust text size:


Free porn via an Internet Explorer Vulnerability? It sounds too good to be true, doesn't it? When was the last time anything good came out from a vulnerability affecting Microsoft's products? Well, joking
aside, it does sound too good to be true. This because the free porn offering is an integer part of a social engineering scheme targeting users of unpatched versions of IE prior to Internet Explorer 7.

Sophos, an integrated threat management solutions provider, has warned of the discovery of an aggressive spam campaign promoting free pornography. But, instead of free explicit images and videos, victims will be hit with a Trojan horse. "Psyme-DL exploits a Microsoft Internet Explorer vulnerability, MS06-014, and when the weblink is accessed using Firefox, a message is displayed requesting the user to change browser," explains Sophos. So if you use Firefox, you are safe. Also, Internet Explorer 7 and prior completely patched versions of the browser are not affected by this vulnerability.

The spammed messages contain a link redirecting the victims to a malicious website designed to download Psyme-DL via the ADODB stream vulnerability. No user interaction is necessary as the flaw allows for remote code execution.

"Despite the numerous warnings users have probably heard about safe computing and appropriate online behavior, emails with racy subject lines still seem hard to resist for some users," said Carole Theriault, senior security consultant for Sophos. "By infecting machines belonging to users who thought they might steal a peak at some free porn, this malware campaign leads victims down a rathole they might feel embarrassed to be found in. The author of Psyme-DL is not just looking to humiliate but is also attempting to take control of the machines in order to spy, steal or cause havoc on PCs."
Read by 385,370 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.9/5) 108 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Microsoft Is Testing A New Homepage

Microsoft Didn't Create "Zune"

Overweight and Obese Microsoft Is on a Diet - 61,100 Pounds Lost

Update on the Packaging for Windows Vista and 2007 Office

Microsoft SQL Server Is the Safest Database

Microsoft to Launch Live OneCare 1.5 on January 30, 2007

Adobe CEO Threatens Microsoft with Potential Vista Lawsuit

Microsoft Snaps Console Game Market Share from Sony

Microsoft Condemns Vista PatchGuard Hack

Microsoft Manipulates Google to Promote OneCare

Microsoft Debuts Aggreg8

Microsoft Showcased Windows Compute Cluster Server 2003 for the First Time in the Middle East

Microsoft Unveils Windows Media Photo

Google Is No Match for Microsoft

Microsoft & Novell & Patent Infringement

Linux Infringes Microsoft's Intellectual Property

Microsoft Has Closed Down the Max Project

For the Nice... The Naughty... And Everyone in Between... From Microsoft

780.5 Million Euros Later Microsoft Completes EU Technical Documentation

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM