• On last.fm: Create Your Own Online Radio Stations

March 30, 2006 6:04 PM PST

BBC stories used as bait for IE exploit

  • Print
Cybercrooks are spamming e-mail messages to trick people into visiting malicious Web sites that exploit a recent Internet Explorer flaw, experts warned Thursday.

The Web sites take advantage of the vulnerability in the omnipresent Microsoft Web browser to install a keystroke logger on vulnerable computers, according to San Diego-based Websense Security Labs.

"This keylogger monitors activity on various financial Web sites and uploads captured information back to the attacker," Websense said in an alert. The malicious software could capture log-in names and passwords for the sites, information criminals could sell or possibly use to plunder a victim's account.

The e-mail messages used to lure people to the Web sites contain excerpts from BBC news stories and offer a link to "read more," Websense said. This link leads to a forged BBC Web page where the malicious software is dropped onto a vulnerable PC by exploiting the "createTextRange()" vulnerability in IE, according to Websense's alert.

The vulnerability has to do with how Internet Explorer handles the createTextRange() tag in Web pages. Since the flaw was disclosed publicly last week, more than 200 Web sites have been found to exploit it. These sites typically install spyware, remote control software and Trojan horses on vulnerable PCs.

Microsoft has said it is working on a fix for the browser. That update is currently scheduled for delivery April 11, Microsoft's regular monthly patch day. However, the Redmond, Wash., company has said it's considering an earlier release.

Meanwhile, two security companies have beaten Microsoft to the punch. eEye Digital Security and Determina both released unofficial fixes for the IE flaw earlier this week. Experts, however, have warned users to be cautious with non-Microsoft fixes and instead suggest using a Web browser other than IE, or disabling Active Scripting, which is also Microsoft's advice.

See more CNET content tagged:
Websense Inc., Microsoft Internet Explorer, flaw, malicious software, vulnerability

Add a Comment (Log in or register) 4 comments
Nothing fresh here
by n3td3v March 30, 2006 7:38 PM PST
Nothing fresh in this article apart from what we already found out when Websense sent the industry an e-mail alert some 4 and a half hours ago. Maybe Cnet just re-publish Websense e-mail alerts when they get bored on a Thursday evening.
Reply to this comment
Which makes them.........
by PlOtTiNg March 31, 2006 6:28 AM PST
No different than you and your elite hacker group!

Regurgitation of everyone else's research.
View reply
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Microsoft (12.26%) 2.15 19.68
WEBSENSE INC (5.06%) 0.71 14.75
Dow Jones Industrials (6.54%) 494.13 8,046.42
S&P 500 (6.32%) 47.59 800.03
NASDAQ (5.18%) 68.23 1,384.35
CNET TECH (5.95%) 56.25 1,002.00
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right