Dean's World
 Defending the liberal tradition in history, science, and philosophy.

.:: Dean's World: Uh, Oh..A NEW Virus...(Joe Gandelman) ::.

June 26, 2004

Uh, Oh..A NEW Virus...(Joe Gandelman)

Just when you thought it was safe to order online, the Washington Post reports this:

    A new Internet virus has surfaced that allows hackers to steal passwords, credit card numbers and other personal information when someone merely visits an infected Web site, government computer security experts warned this week.

    Hundreds of Web sites have been targeted by the virus, which exploits flaws in Microsoft Corp.'s Windows Internet software, according to an alert issued Thursday by the U.S. Computer Emergency Readiness Team (US-CERT), a division of the Department of Homeland Security.

    Infected sites were programmed to connect people using the Microsoft Internet Explorer browser to a Web site that contains code allowing hackers to record what users type, such as passwords and credit card and Social Security numbers. The code then e-mails that information to the anonymous attackers.

    Government officials would not identify the infected sites; computer security vendors said many have taken steps to fix the problem. In addition, most large Internet service providers have stopped forwarding Web traffic to the Russian Web site that apparently hosts the software that records what is typed, minimizing the theft of data, officials said.

    Among the several Web sites hit by the virus, dubbed "js.scob.trojan" by one antivirus vendor, were the Web sites of the Kelley Blue Book automobile pricing guide and MinervaHealth Inc., a Jackson, Wyo., company that provides online financial services for hospitals and health care businesses.


Darn! Does this mean they can get my credit card information after I ordered that "enlargement" product??

Posted by joe gandelman | PermaLink | TrackBack (1)

Discuss This Article!

 

Speaking of enlargement, here comes the judge.

I'm posting about this at my site tomorrow, but, you HAVE to read it.

Posted by Andrew | BYTE BACK on June 26, 2004 at 3:21 AM


Oh, I see you got the link below. Still OmG. This man of dubious judgment was .... a !@#$% judge.

Yikes.

Posted by Andrew | BYTE BACK on June 26, 2004 at 3:26 AM


Stay away from IE! Bad! Bad!

Try Opera or Firefox.

Posted by Mason on June 26, 2004 at 3:29 AM


Joe: strictly speaking, this is not a virus. A trojan, perhaps.

And it is NOT limited to IE users. Any browser which has Javascript enabled is vulnerable (Mason!! {g}). What you need to do is disable Javascript in your browser for now.

In Mozilla (for Windows) 1.6 you can select Edit/Preferences/Advanced/Scripts and Plugins to disable Javascript in the browser.

The main vulnerability is with servers which use Microsoft's Internet Information Server (IIS) 5. The alerts I've seen don't say so explicitly, but I imagine that Apache servers (as opposed to IIS 5 servers) are not vulnerable.

Posted by Casey Tompkins on June 26, 2004 at 6:04 AM


 



.:: ABOUT DEAN'S WORLD ::.


.:: BEST OF DEAN'S WORLD ::.


.:: RECENT ENTRIES ::.


.:: ARCHIVES ::.


.:: MISC ::.