Johannesburg

Wednesday

Sunny. Pleasantly warm.

12°C
28°C

7 day forecasts

Hackers exploit Windows flaw

2007-04-01 15:56

Seattle - Hackers stepped up attacks on Friday on computers running some versions of Windows, a day after Microsoft disclosed a hole related to the mouse cursor.

Microsoft sent out a security advisory on Thursday warning customers that a vulnerability in ".ani" files - used to change the cursor into an hourglass while a program works, or into a dancing animal or other animation on specially designed websites - was allowing hackers to break into computers and install malicious software.

"Overnight we did see the attacks change from limited and targeted attacks to slightly more, but do still categorise it as a limited attack," said Mark Miller, director of the software maker's security response group.

The so-called zero-day attack, a vulnerability that is discovered before Microsoft has a chance to fix the problem, is aimed at PCs running Windows Vista, the new operating system that the company has touted as its most secure.

The hole has also been found on Windows 2000 Service Pack 4, Windows XP Service Pack 2 and some versions of Windows Server 2003.

Once hackers have access to a computer, they can install any number of nasty programs - ones that steal passwords or record keystrokes, which the hackers could then sell to identity thieves.

Microsoft first learned of the vulnerability in December, and has been working on a patch since, Miller said. He did not say whether it would be distributed on its own or as part of a scheduled update.

On Wednesday, security software vendor McAfee saw a post on a Chinese message board indicating hackers were planning to exploit the hole, which set Microsoft's security advisory in motion.

"It is important to note that while we do think Vista is the most secure operating system released, no software is 100% secure," Miller said.

Computer users could end up with a malicious program on their PC after a web browsing session and not know it, said Craig Schmugar, a virus researcher for McAfee Avert Labs, the research arm of McAfee Inc.

So far, he said, attacks have been limited to web surfing with Internet Explorer versions 6 or 7. Firefox, the open-source browser from Mozilla, does not yet seem vulnerable.

While Microsoft urged people to be extremely cautious with e-mail, security companies said they have not seen any instances of attacks via e-mail.

While it's hard to tell what hackers will do once they have access to a computer, a group of Chinese hackers may be plotting to steal login information for the wildly popular multiplayer video game, World of Warcraft. People who buy the stolen login information can profit by selling items inside the game world, said Ken Dunham, director of the rapid response team at iDefense, the research division of VeriSign.

Dunham said his team learned of the plan on a Chinese hacker message board.

- Dow Jones

inside news24

Cpt: 15-18°C Rain showers. Morning clouds. Mild. Pta: 16-31°C More sun than clouds. Pleasantly warm.
Jhb: 12-28°C Sunny. Pleasantly warm. Bloem: 12-29°C High level clouds. Pleasantly warm.
Dbn: 18-30°C Sprinkles early. More sun than clouds. Warm. PE: 14-23°C Drizzle. Morning clouds. Mild.
7 day forecasts...
Western Cape Eastern Cape Kwazulu Natal Gauteng

Randburg - 10:23:38 AM Slow moving traffic between the Malibongwe Drive exit and the Rivonia Road exit in Suninghill More traffic reports...

Here are the winning Lotto numbers from the Saturday, November 7 draw.

18, 24, 25, 31, 35, 42 Bonus 38

Lotto plus: 4, 14, 17, 20, 21, 34 Bonus 3

SMS the word Lotto to 31222 to get lotto numbers sent directly to your phone. The service costs just R10 per month. 
More lotto numbers...

Jobs - Find your dream job

Financial Director

Gauteng - Johannesburg
Cassel & Co

Creditors Clerk

Gauteng - East Rand
Cassel & Co

Bookkeeper

Gauteng - JHB North/Sandton
Cassel & Co

Cars - Search 1000's of new and used cars

AUDI

2008 A4 1.8T Multitronics from R 269 000

AUDI

TT Coupe Quattro 3.2 S-Tronic
2007
R 369,000.00

VOLKSWAGEN

Kombi T5 SWB 1.9 TDi MPV Dsl
2006
R 199,990.00

AUDI

A4 2.0 TDi Ambition Dsl MY09
2009
R 319,000.00

Property - Find a new home

MAGALIESKRUIN

Single Residential R2,150,000

MONTANA

Single Residential R3,550,000

CAPE TOWN

Multiple Unit R720,000

Travel - Look, Book, Go!

Free Games - TOO MUCH NEWS? TAKE A BREAK!