Search Perform an advanced search query SOFTPEDIA
 
SOFTPEDIA
Updated one minute ago
HomeSubmit a program for being reviewedAdvertise on our websiteGet help on surfing our websitesSend us your feedbackGet information about our XML/RSS backend and how to use itBrowse the news archiveVisit our discussion forumVizitati forumul in limba romana



KLIP
  1. HOME
  2. SCIENCE
  3. TECHNOLOGY
  4. WEBMASTER
  5. SECURITY
  6. MICROSOFT
  7. LINUX
  8. APPLE
  9. GAMES
  10. TELECOMS
  11. REVIEWS
  12. LIFE & STYLE
  13. EDITORIALS
  14. INTERVIEWS
  15. RSS
Welcome!
Hello, Guest

Login if you have a Softpedia.com account.

Otherwise, register for one.

SECURITY

Rogue Security Solutions Take a Bite out of IE8 Beta 1

- ActiveX will continue to come under fire

By: Marius Oiaga, Technology News Editor

Simply because of the ubiquity of its predecessors, Internet Explorer 8 will continue to come under fire. With one of the preferred avenues for attacks continuing to serve as a source of malware even in the next iteration of Microsoft's
proprietary browser, ActiveX add-ons are a traditional vector of attacks on the Windows platform via IE, and Microsoft has worked to bulletproof Internet Explorer 8 as much as possible with an array of mitigations. But additional security features such as Per-User (Non-Admin) ActiveX, ActiveX Opt-In and Per-Site ActiveX can do nothing to protect against social engineering schemes that rely on tricking the user into infecting the operating system.

One illustrative example of ActiveX-based social engineering attacks involves rogue antivirus products. Attackers are counting on the end users' familiarity with the behavior of ActiveX in order to push malware as add-ons, claiming that it is in fact a security solution meant to resolve a plethora of problems on the end user's machine. Security researcher Sandi Hardmeier recently came across a fraudware website pushing a product dubbed Antivirus Scanner.

As soon as a user visits the malicious website, a fake scan is started and performed to the point where the rogue antivirus falsely claims that it has detected malware on the machine. As a direct consequence, it advises users to install and ActiveX add-on, namely the malware itself, and become infected. This threat is tailored specifically to Internet Explorer and the ActiveX technology, and as you can see from the screenshots with IE8 Beta 1, it looks rather convincing.

Now, in Firefox 3.0 RC1, the malicious webpage for Antivirus 2008 Online Security Scanner is broken, as the open source browser does integrate ActiveX add-ons. Still, with the exception of this detail, the attack goes in the same manner, and the end user is, like it or not, offered the malicious payload for download. In general, a rogue antivirus simply blackmails the end user for a moderate sum of money in order to remove the fake threats that it has detected in the first place. But there is no telling what malicious code it will actually install on the computer. Users are advised to run security programs only from trusted vendors, and to steer clear of online scanners that perform unsolicited analysis of their machines.



MORE RELATED ARTICLES: BitDefender Offers Protection From IE8 Beta 1 Critical Zero-Day IE8 Beta 1 Attack Code Available in the Wild Internet Explorer 8 Critical Zero-Day Security Vulnerability Released in the Wild Internet Explorer 8 Beta 1 ActiveX Security Original XP SP3 RTM Integrated Slipstream ISO Images Leaked XP SP3 Ships Complete with a Range of Issues that Survived RTM Mozilla Nearing the Finish Line for Firefox 3.0 Microsoft: Faulty Integration of XP SP3 RTM and IE8 Beta 1 by Design
 
Comments | Link here | Subscribe
Print | Send to friend
Today's News | Yesterday's News

Search:


21st May 2008, 17:39 GMT | Copyright (c) 2008 Softpedia | Contact:
Read by 949 user(s) | Rating: | 5 vote(s) so far | Cast your vote:
Rogue Security Solutions Take a Bite out of IE8 Beta 1 - USER OPINIONS




We are sorry, there are no opinions available for this article.






SHARE YOUR OPINION ABOUT Rogue Security Solutions Take a Bite out of IE8 Beta 1

Since you are not logged on, your comments will have to be approved before being displayed.
Click here to login, or register.
Your Name:
Your Email:
Type in the result:
Your Opinion:
 


DO YOU WANT TO CONTACT US?  

If you have some comments or you want to send us some information you can send us an email directly to .
You can use the form below for the same purpose.
Your full name: (at least 3 characters)
Your email address: (at least 5 characters)
Message subject: (at least 5 characters)
Message text:
(at least 10 characters)
Type in the result:
 
 



© 2001 - 2008 Softpedia. All rights reserved.
Softpedia™ and Softpedia™ logo are registered trademarks of SoftNews NET SRL.
Copyright Information | Privacy Policy | Terms of Use | Contact Softpedia | Update your software | Archive