Hackers launch Bofra banner ad attacks

Dan Ilett, Special to ZDNet

23 November 2004 08:20 AM

Tags: bofra, worm, ie, iframe, website, web site, storm, attack

Security experts are warning that hackers may have launched a wide-spread attack in Europe using banner ads to redirect users to Web sites that download malicious code.

After receiving several reports of rogue banner ads infecting users, researchers at the SANS Internet Storm Center have cautioned that hackers may have attacked a large number of servers hosting the adverts. This means that hackers would reach a larger number of victims on hundreds of sites by 'advertising' to click the ad that would lead to the code.

Hackers have already attacked several European Web sites using the as yet un-patched IFRAME exploit, otherwise known as Bofra, in Internet Explorer 6.0.

"The Storm Center received a report of a high profile UK Web site that contains a pointer on their main page to another URL hosting the Bofra/IFRAME exploit," wrote Marcus Sachs director of the SANS Internet Storm Center. "We have confirmed that if this site is visited using Internet Explorer the exploit will be downloaded. Please exercise caution when using Microsoft's Internet Explorer since this issue has no current patch. The Storm Center recommends using an alternative browser when visiting sites other than those you absolutely trust."

Banner ads are an ideal tool for mass distribution of malicious code because they are able to distribute code on many Web sites at the same time.

Users who have clicked on the ads have seen their computers infected by the Bofra worm, which emerged head five days after the vulnerability was announced earlier this month.

The worm combines multiple attack techniques using spamming, social engineering, virus infection and Trojans to attack its victims' computers.

Windows XP users who have loaded Service Pack 2 are thought not to be affected by the worm. Microsoft has yet to release a patch for the exploit, but earlier this month the company chastised the independent researchers who published the vulnerability for failing to inform it first.

Like this article? Click below to send it to your mobile for free!

Talkback 1 comments

  1. Makes me glad I use Firefox as my browser of choice and even though I us Windows XP - SP2 and update regularly, this type of exploit is making me think seriously about migrating to Linux. Anonymous -- 23/11/04

    Makes me glad I use Firefox as my browser of choice and even though I us Windows XP - SP2 and update regularly, this type of exploit is making me think seriously about migrating to Linux.


Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Alex Serpo Will the NSW Govt put Linux in schools?
    The NSW Government's release this week of an expressions of interest tender to give low-cost laptops to every senior public school student in NSW is a big step, but will these systems be Windows or Linux?
  • Array Naked Mac versus protected PC: What wins?
    What's easier to manage — 200 Mac OS X systems without antivirus or 200 Windows systems running a leading antivirus package?
  • Array Dear Telstra: pack up your toys, go home
    Rejecting Telstra's proposal, after all, is the only conclusion Conroy can reach: as someone whose entire philosophy is built around transparency and process, he simply cannot keep Telstra as part of the NBN bidding process anymore.
  • More blogs »

Tags

Back to top

Featured