Mobile Version
Subscribe
Contact Us
About Us
Advertising
Editorial
SC UK
SC Aus/NZ
Home
News
Features
Opinions
Newsletters
Sectors
Company Moves
Products
First Looks
Reviews
Group Tests
About Reviews
Blogs
The News Team Blog
The Data Breach Blog
Buyers Guide
Whitepapers
Jobs
Events
SC World Congress
Awards
Podcasts
Digital Download
Editorial Webcasts
Vendor Webcasts
eConference
Subscribe
Newsletters
Subscribe to SC
Issue Archive
Topic Center:
Email Security
Compliance
Patch Management
Financial Services
Health Care
Retail
RSS
|
Login
|
Register
Home
>
News
> Active exploits target social networking ActiveX flaw
Active exploits target social networking ActiveX flaw
Dan Kaplan
February 25, 2008
Print
Email
Reprint
Font Size:
A
|
A
|
A
Users who remain vulnerable to an
ActiveX
photo uploader vulnerability used on many websites are now being targeted in active attacks, researchers from Symantec said today.
Earlier this month, Symantec
warned of a critical bug in an image uploader plug-in
made by software development company Aurigma and distributed by many of the popular social networking sites -- including
MySpace
and
Facebook --
to enable the addition of photos.
On Friday, researchers said they first noticed in-the-wild attacks taking advantage of the vulnerability, which has been patched, said Kevin Haley, director of product management for Symantec Security Response.
Under the attack scenario, individuals receive phishing emails that direct them to a bogus MySpace login page, Haley told SCMagazineUS.com today. Once there, the malicious sites search victims' computers to learn if they are vulnerable to the image uploader issue. If they are, the site attempts to install a medley of trojans.
“It's a double whammy,” he said. “It's going to try to steal your credentials [MySpace username and password] and it's going to try to download some malware on your machine.”
An Aurigma representative did not respond to a request for comment.
If users are not running the Aurigma software – or if their PCs are pached for the flaw – the sites will look for
other vulnerabilities
, including a recently disclosed Yahoo Jukebox ActiveX flaw.
Haley said businesses might consider disabling ActiveX on their browsers, but ideally they should ensure their machines are running the latest fixes.
“Once the patches are available, you need to get them out,” he said. “The bad guys and the malware writers are where the users are, and today that's the social networks.”
Most Popular
Most Emailed
Most Recent
Keylogger spyware ordered off the market
Email ruse uses Federal Reserve Bank name to drop PDF exploit
Military's ban of USB thumb drives highlights security risks
Microsoft to offer free security solution, discontinue OneCare
Bank on it: An end to anti-virus
Hot or not: Software update vulnerabilities
Cybercrime expected to ramp up during holiday season
Massachusetts data security law rule extended four months
Cybersecurity advice for President-elect Obama to be previewed at SC World Congress
Teen cybervandal pleads guilty to corporate hacks
Email ruse uses Federal Reserve Bank name to drop PDF exploit
Microsoft to offer free security solution, discontinue OneCare
Keylogger spyware ordered off the market
Military's ban of USB thumb drives highlights security risks
Bank on it: An end to anti-virus
Massachusetts data security law rule extended four months
Hot or not: Software update vulnerabilities
Teen cybervandal pleads guilty to corporate hacks
Cybercrime expected to ramp up during holiday season
Adobe's AIR 1.5 update addresses Flash Player vulnerabilities
Malware masquerading as "High School Musical" files on file sharing networks
Obama's cell phone records breached
Military's ban of USB thumb drives highlights security risks
Software-coding inefficiencies to be addressed at SC World Congress
Spam levels remain down following McColo shutdown
Microsoft to offer free security solution, discontinue OneCare
Hot or not: Software update vulnerabilities
Teen cybervandal pleads guilty to corporate hacks
Massachusetts data security law rule extended four months
Panel at SC World Congress to offer advice on getting ahead of attackers
Popular Tags
Access Control
Anti Spam
Anti Virus
Apple Threats
Breaches & Exposures
Compliance
Consumer Threats
Email Security
Emerging Threats
Finance
Government
High Tech
Identity Management
Insider Threats
Intrusion Prevention
Lawbreakers & Cybercrime
Microsoft
Mobile Endpoint Security
Non-Microsoft Patches
Patch Management
Phishing
Retail
Security Management
Spam Techniques
Vulnerabilities & Flaws
Sponsored Links