Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Windows

June 1st, 2007, 15:32 GMT · By

The Anatomy of a Windows Vista Web Attack

SHARE:

Adjust text size:



Enlarge picture
Almost two months after Microsoft bulletproofed Windows Vista against malformed animated cursors, the .ANI file format handling vulnerability is still exploited in the wild. Web-based malicious attacks deliver a great level of risk due to the fact that the exploits are independent from users interaction. In order to get infected all that a user has to do is to navigate to a malformed webpage. This type of attacks is known as drive-by-downloads and Windows Vista is as susceptible as the next operating system to becoming compromised. According to SophosLabs, the volume of websites hosting malicious code has increased significantly, and although it was made available
to the general public just four months ago, Vista is already targeted.

"The start point of the infection chain in this case is a single page containing embedded iframe tags. Using embedded iframes is a useful technique to silently load additional web content when browsing a page (useful both legitimately and maliciously). As is typical with malicious attacks, the size of the embedded frame is set to either zero or very small (

TELL US WHAT YOU THINK:

3,209 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Denial of Service Attacks Lurk on Vista Networks

Windows Vista Down! But Not Out!

x86 and x64 Windows Vista Can Be Completely Taken Over by Attackers

Windows Vista Autopsy - Courtesy of Kaspersky

Windows Vista from Black to Grey and to White Risk

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM