This is priceless.
Nov. 24th, 2004 11:26 pmVideo of a fresh XP install getting pwn3d by visiting a website
The video is a screen-capture movie from Benedelman.org and shows how an unpatched WinXP system will get rooted and sutffed full of spyware just by visiting one website in IE. No confirmation box, no warning. By the time anything other than a blank page appears the system is already compromised.
He does note that XP SP2 isn't vulnerable. What he doesn't mention is that IE under every other platform is vulnerable even if it's patched to date, especially Windows 98/Me (and a lot of people do still run 9x). Ditto for Windows 2000 and XP SP1, and there are lot of corporate desktops in that category.
Firefox on any platform, of course, is not vulnerable.
I am so glad I no longer clean this shit up every day.
The video is a screen-capture movie from Benedelman.org and shows how an unpatched WinXP system will get rooted and sutffed full of spyware just by visiting one website in IE. No confirmation box, no warning. By the time anything other than a blank page appears the system is already compromised.
He does note that XP SP2 isn't vulnerable. What he doesn't mention is that IE under every other platform is vulnerable even if it's patched to date, especially Windows 98/Me (and a lot of people do still run 9x). Ditto for Windows 2000 and XP SP1, and there are lot of corporate desktops in that category.
Firefox on any platform, of course, is not vulnerable.
I am so glad I no longer clean this shit up every day.
no subject
Date: 2004-11-24 08:52 pm (UTC)::grumbles::
I finally found a program at work that pukes if you try to install it on a SP2 machine. Fortunately, it's pretty easy to get around, as the problem appears to be well documented (except by the company who wrote it - they want you to pay for that privledge via a support contract).
no subject
Date: 2004-11-24 08:58 pm (UTC)wow. All that from one URL. Amazing.
However, there are a few opurtunaties that the user could, in theory, NOT install the crap, although by that time it's probably too late anyway.
no subject
Date: 2004-11-24 10:48 pm (UTC)no subject
Date: 2004-11-25 01:02 am (UTC)no subject
Date: 2004-11-25 01:03 am (UTC)no subject
Date: 2004-11-25 01:49 am (UTC)maybe
no subject
Date: 2004-11-25 01:51 am (UTC)no subject
Date: 2004-11-25 01:52 am (UTC)no subject
Date: 2004-11-25 01:57 am (UTC)Yeah. Looks like. I'm not sure if this is really a fair, real-world situation. I've seen many customer's computers completely unusable due to spyway - but does it really happen this quickly? all at once?
no subject
Date: 2004-11-25 04:39 am (UTC)It's definitely a fake - one of the popup windows has the url "www.sp2fucked.biz/user28/2dimension*something*ExploitsEmc.php"
Still, should be good for scaring the shit out of end users....
no subject
Date: 2004-11-25 05:30 am (UTC)Now, back to watching Ad-Aware at work on another customer's PC... after neutralizing most of the spyware there with HijackThis, LSPFix and WinsockFix, it's up to 2887 critical objects and counting...
no subject
Date: 2004-11-25 05:52 am (UTC)Definately NOT a fake.
Date: 2004-11-25 07:43 am (UTC)Domain Name: SP2FUCKED.BIZ
Domain ID: D7921805-BIZ
Sponsoring Registrar: DIRECT INFORMATION PVT. LTD., (D.B.A. DIRECTI.COM)
Sponsoring Registrar IANA ID: 303
Domain Status: clientDeleteProhibited
Domain Status: clientTransferProhibited
Domain Status: clientUpdateProhibited
Registrant ID: DI_937571
Registrant Name: John Miller
Registrant Organization: Liber Inc
Registrant Address1: 135/2 Washington str
Registrant City: Limasson
Registrant Postal Code: 06432
Registrant Country: Cyprus
Registrant Country Code: CY
Registrant Phone Number: +944.8735673
Registrant Email: support@coolsearch.biz
Details faked out the ass, but notice the support email: coolsearch.biz
sp2fucked.biz is CoolWebSearch
xpire.info
Date: 2004-11-25 07:49 am (UTC)Re: Definately NOT a fake.
Date: 2004-11-25 04:38 pm (UTC)At any rate, it wouldn't surprise me not at all to learn CWS's creators are behind something THIS nasty. I gotta show this to our training managers.
no subject
Date: 2004-11-30 10:29 pm (UTC)considering that the average time for an unpatched clean XP install to get hit by viruses/worms/etc is now down to 4 minutes, from 15...well, i'm glad I went to Linux ;)
no subject
Date: 2005-11-23 08:56 pm (UTC)no subject
Date: 2005-11-23 08:56 pm (UTC)the quality settings are very adjustable
no subject
Date: 2005-11-30 01:02 am (UTC)