The Digital Rag
Real World Information in a Virtual World
Sign Up!
Login
Welcome to The Digital Rag
Tuesday, February 07 2012 @ 01:39 PM PST

Update on ANIMATED CURSOR exploit - it's even worse!

Newsletter PostingsI've added in all my customers on this notice as the potential for bad trouble has increased. The Chinese Internet Security Response Team is reporting (via SANS.org) that there is a WORM out now that exploits the Animated Cursor vulnerability and that they have seen this worm put into all manner of content including HTML ASPX HTM PHP JSP ASP and EXE files which means that if your system allows files of these types to be included in e-mails or you visit infected web pages that link to files of these types (and who doesn't?) that your system can be infected simply by previewing e-mail for example (which is why I advocate text-only e-mail!)

Domains that have been noted as having the infected pages include:
2007ip.com
microfsot.com (don't they just love mis-spellings!)

SANS is also noting that Windows 2003 with Service Pack 2 is also
vulnerable.

McAfee is reporting there is a spam campaign that exploits this too -
I've added .ani to the list of file extensions that are tagged as spam in the FIRE mail system.

See: http://blog.pacdat.net/article.php/20070330000705739 for the
original notice and links as well as
http://isc.sans.org/diary.php?storyid=2551 for more on tools and
http://www.microsoft.com/technet/security/advisory/935423.mspx for the updated Microsoft advisory

----
In the first of a series of updated articles based on my 2004 visit to personal privacy and the Internet, you'll learn about why using HTML mail has been banned by the US Department of Defence and is seriously being considered for banning by many other government and industry institutions.

http://blog.pacdat.net/article.php/20070331144425900 is "A
Reintroduction to Internet/Computer Privacy Invasion"

-----

This is not an April Fools joke - but enjoy others as you find them :)

richard

What's New

Stories

No new stories

Comments last 2 days

No new comments

Trackbacks last 2 days

No new trackbacks

Older Stories

Thursday 15-Sep


Saturday 10-Sep


Tuesday 30-Aug


Saturday 20-Aug


Thursday 18-Aug


Sunday 14-Aug


Thursday 04-Aug


Tuesday 02-Aug

?

Ads by Clickochet

G+ Public Posts

There was a problem reading this feed (see error.log for details).
?

G+

?

Facebook Page

RSS Feed

Richard's Digital Rag

Poll

How do you like to find out news about the internet and computers?

  •  Newspaper
  •  Radio
  •  TV
  •  Web Search
  •  Favourite Web Site(s)
  •  Pod Cast
  •  Video Online
  •  Email List(s)
  •  RSS - Syndication
  •  Word of mouth
This poll has 0 more questions.
Results
Other polls | 28 votes | 0 comments