<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Anatomy of a Drive-by-Install in Security</title>
<link>http://www.dslreports.com/forum/r13144000</link>
<description></description>
<language>en</language>
<pubDate>Wed, 09 Dec 2009 10:58:06 EDT</pubDate>
<lastBuildDate>Wed, 09 Dec 2009 10:58:06 EDT</lastBuildDate>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13211810</link>
<description><![CDATA[<A HREF="/useremail/u/817075"><b>Kiwi</b></A> : Strange really, in some respects -I use IE, but as noted no activeX or Java unless needed. Firefox has become a popular hunting ground, so it's moot weather one uses IE or Firefox!<br><br>The Java disable noted by  ElJay <A HREF="/useremail/u/972855"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> is most important, JavaSun is great if one knows how to configure the latest updates;) <br><br>Of course safe hex is the answer to most problems people suffer :) Few 'Surfers' realize the value of the 'electronic condom' ;)<br><br>Cheers<br><SMALL>--<br>2.66g/533fsb Intel CPU @ 3.48g<br>512meg Twinmos PC3700~466 DDR @ 2.8v -PCpower&Cooling 512.<br>ATI 9500 Pro @ 9700 Pro @1.6v<br>--<br>AMD ASUS A7N8X-E ~<br>2500+ @3200 ATI 9500 Pro, Corsair 512LL.-- Aristotle.net</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13211810</guid>
<pubDate>Tue, 19 Apr 2005 19:39:05 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13207759</link>
<description><![CDATA[<A HREF="/useremail/u/628749"><b>PavTheMan</b></A> : <div class="bquote"><SMALL>said by  Shriyash <A HREF="/useremail/u/1163957"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>plus i have a online TV app. which needs java to run.<br>oh and not to mention pr0n.<br>java is indespensible.<br> </DIV>:D  Well you shouldn't need Java to see pr0n, er......  apparently. :D  <br><br>I just avoid any site that won't show me pics or vid clips without Java.  Ther are plenty of free ones that will.<br><br>Besides, P2P-ing  for pr0n is, IMHO, a lot safer and more fruitful than those websites.  Just run it as a limited account and lock it down.<br><br>:)<br><SMALL>--<br>No Thanks <A HREF="http://www.againsttcpa.com/">Fritz</A>, I'll Decide Who To Trust</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13207759</guid>
<pubDate>Tue, 19 Apr 2005 12:02:39 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13198132</link>
<description><![CDATA[<A HREF="/useremail/u/403861"><b>Mele20</b></A> : Yes, I'm seeing it upside down. I played it more than once hoping it would right itself but no luck. Maybe I don't have the right codec for it. Ahhh...I didn't think about this sooner but I suppose I could flip the screen with nVidia and invert it and then it would be right side up. Of course the Winamp controls would be upside down but that might not matter. I'll try that tomorrow.<br><br>I didn't realize you need Java for online TV. I avoid Yahoo but yeah if you like launchcast and pron! :D then I suppose you do need Java. ;)<br><SMALL>--<br>The first and foremost function of our jurors is to protect private citizens from a tyrannical and intrusive government...Jurors are the last line of defense for liberty. Thomas Jefferson 1789</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13198132</guid>
<pubDate>Mon, 18 Apr 2005 08:18:55 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13198001</link>
<description><![CDATA[<A HREF="/useremail/u/1163957"><b>Shriyash</b></A> : you are seeing the video upside down? <br>i viewed it again in winamp and windows media player{10}, and it plays fine here.<br>one of my favoutite sites is launch.yahoo.com, and you need java to play launchcast.<br>plus i have a online TV app. which needs java to run.<br>oh and not to mention pr0n.<br>java is indespensible.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13198001</guid>
<pubDate>Mon, 18 Apr 2005 07:35:45 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13197571</link>
<description><![CDATA[<A HREF="/useremail/u/403861"><b>Mele20</b></A> : That video plays upside down! Can't watch that. <br><br>I see Spazbox no longer exists? I guess all this publicity drove the site off?<br><br>I still can't believe anyone would click through the expired certificates warning or would install that very suspicious Active X on IE or any of those things. If you are that ignorant then you have no business owning a computer. Plus what sites are people going to where they see a lot of Java Applets? I NEVER see Java applets except when I go to the Speakeasy sites to speed test. I don't even have Java for Fx which I use 90% of the time. I don't need Java so I sure wonder what kinds of sites people are visiting that use so much Java applets.<br><SMALL>--<br>The first and foremost function of our jurors is to protect private citizens from a tyrannical and intrusive government...Jurors are the last line of defense for liberty. Thomas Jefferson 1789</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13197571</guid>
<pubDate>Mon, 18 Apr 2005 03:22:29 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13197510</link>
<description><![CDATA[<A HREF="/useremail/u/911165"><b>diver196</b></A> : Really great info.  Just remember, in most cases the user does have to let the spyware onto his/her machine by giving consent, even if not informed.<br><SMALL>--<br>Only those defenses are good, certain and durable, which depend on yourself alone and your own ability.  The Prince, by Niccolo Machiavelli.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13197510</guid>
<pubDate>Mon, 18 Apr 2005 02:48:09 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13196245</link>
<description><![CDATA[<A HREF="/useremail/u/1163957"><b>Shriyash</b></A> : oh my god!<br>u guys have to see this video for yourself, its a short clip, 1.2 MB, but its an 'experience' watching it. whew!<br>heres the link again:<br>&raquo;<A HREF="http://netrn.net/spywareblog/archives/2005/04/09/oh-what-a-tangled-web-we-weave/" >netrn.net/spywareblog/archives/2&middot;&middot;&middot;e-weave/</A><br><br>just click on the "spazbox video" on the above link, and see for yourself.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13196245</guid>
<pubDate>Sun, 17 Apr 2005 22:45:38 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13195955</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> :   Im suprised nobody has sued these companies butts off into total submission.. if i had a business computer, and had it trashed by these guys, i would OWN 180search assistant, and burn all the crap they use to create this stuff, then id wipe my *** with any piece of life,money, or dignity these guys had left]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13195955</guid>
<pubDate>Sun, 17 Apr 2005 22:07:38 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13166184</link>
<description><![CDATA[<A HREF="/useremail/u/1188447"><b>paperghost</b></A> : Thanks B - though as its turned out from new discoveries, the .Xpi is (in yet another strange twist) possibly the least of our worries. How about a potential 30,000 strong botnet through IRC? I've discovered that in all likelyhood, this is where Spazbox.net's huge traffic is coming from despite not being listed well (if at all) in search engines. However, it just raises more and more questions...!<br><br>&raquo;<A HREF="http://www.revenews.com/wayneporter/archives/000594.html#more" >www.revenews.com/wayneporter/arc&middot;&middot;&middot;tml#more</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13166184</guid>
<pubDate>Thu, 14 Apr 2005 01:24:49 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13164698</link>
<description><![CDATA[<A HREF="/useremail/u/229804"><b>B</b></A> : Thanks, Paperghost.<br><br>Unfortunately, as with most things Mozilla, I don't trust them to implement Java whitelisting with any diligence.  (The "whitelisted" XPI sites, for example, is an empty list and is disabled by default in the Moz suite, and the Fireweasel has but a single whitelisted site.  This is nearly useless.)<br><br>Your update addendum was new to me though:<br><br><div class="bquote">In my original tests, I found that disabling software installs in firefox would send the page into a tailspin - and i couldnt figure out why. Someone from a Firefox forum suggested that this behaviour only happens when a Firefox specific install (in other words - an XPI) is attempted. Check out the below, lifted from the Javascript installer served from ysbweb.com:<br><br>if (InstallTrigger.updateEnabled()) {<br>InstallTrigger.install({'Content Access Plugin 1.01' : ''});<br>} else { location.replace(''); }<br><br>The code above tries to load in a piece of rogue firefox .xpi. This is a rather crude .xpi installer to load xxx toolbar into IE - its currently being examined by some of our "file curious" members.<br><br>By chance, I happened to stumble upon a bunch of other sites that (last year) tried similar .xpi installs, which mozilla put out a fix for, rather quickly. Upon revisiting these sites - they now all use the Java applet alongside the .xpi install, and its possible the .Xpi's have been updated, which is why they're now currently being looked at (to see how they work alongside the java).<br><br>So after all the chaos and "browser warring" that erupted over this whole thing, it actually turns out there was "Firefox spyware" buried away in the code</DIV>Interesting stuff.<br><br>-- B<br><SMALL>--<br>In a realm outside causality and function</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13164698</guid>
<pubDate>Wed, 13 Apr 2005 22:17:27 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13163675</link>
<description><![CDATA[<A HREF="/useremail/u/1172151"><b>johnpro</b></A> : It's purely a convenient coincidence that Integrated Search Technologies happens to be using an expired certificate from a CA not yet "trusted" by users (most of whom won't understand what it would take to "trust" a CA/issuer in the first place).<br><br>*************<br><br>I have never trusted "trust us certification" for a number of reasons.<br><br>Trust is built up over time. Anyone can claim they are trustworthy. <br><br>Look at Truste certification for example. This company certifies that giants such as microsoft and intel are trutworthy.   I happen to agree with them.<br><br>However they also certify that dubiates such as idownload and lycos are also trustworthy.<br><br>As one scribe recently wrote ...can truste be trusted!<br><br>My emails to truste were just ignored when I asked them to clarify their position of certification on many of the bad guys in the industry.<br><br>Verisign  et al also have difficulties. Most players do not know the significance of these certificates anyway.<br><br>jp  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13163675</guid>
<pubDate>Wed, 13 Apr 2005 20:26:45 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13163470</link>
<description><![CDATA[<A HREF="/useremail/u/827318"><b>Bobby_Peru</b></A> :  B <A HREF="/useremail/u/229804"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>, in addition to  ElJay <A HREF="/useremail/u/972855"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>'s Java Control Panel configuration pointer, putting the Java Toggle on the toolbar (from one of those button extensions, Pref Buttons, or ToolBar Enhancements?), with strict instructions to keep it deselected, and to inquire if a page/task fails, but not to select it without first checking, has worked for me, and the somewhat clueless newbies.<br><br>For my own installs, I keep the JavaScript (Per Tab) Toggle right next to it, as well.<br><SMALL>--<br>**~~<A HREF="/faq/8428">Infected/Hijacked? FAQ</A>~~~<A HREF="/faq/8463">Protect/Secure Your Box/Data FAQ</A>~~~<A HREF="/faq/security">Security Forum FAQs</A>~~**</SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/13163470?c=807438&ret=L2ZvcnVtL3IxMzE0NDAwMC54bWw%3D"><IMG TITLE="9645 bytes" BORDER=0 WIDTH=505 HEIGHT=96 SRC="/r0/download/807438~5ae2fb8afad74b320d1e2021a81617f2/FxJavaToggle.jpg"></A><br>Weasel Java Toggle</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13163470</guid>
<pubDate>Wed, 13 Apr 2005 20:04:25 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13163104</link>
<description><![CDATA[<A HREF="/useremail/u/403861"><b>Mele20</b></A> : Thank you. The video codec worked and I viewed both movies. The IE one is so obvious that no one would install that! It shows you the Eula. Why would anyone accept that? It clearly indicates it is advertising.<br><br>The Fx one is even more suspicous. Why, if I did not have Sun  Java, would I agree to install something so OBVIOUSLY WRONG? The install is not for Runtime Environment 5.0 but for some weird something called "update 1". Red flag, red flag! Geez, I'd be outta there in second! Secondly, the certificate is OBVIOUSLY BAD. Again, no one would trust that! <br><br>There is nothing confusing about install on either browser. If users are so ignorant that they can't see all the red flags here then they better either get rid of their computers or learn something about their computer. I was ignorant when I got my first computer but I started learning immediately and have never stopped. If you want to have a computer you have to be willing to learn continously.<br><br>The one bad thing I do see is that install on IE 6SP1 (which I use) is HIGHLY DECEPTIVE since nothing happens and it is all silent. But since this uses Sun Java to install, the safe thing for SP1 users is to just use MSJVM and avoid Sun Java if you use IE. Or if you must install Sun Java to use the new dslr speed test applet because your ISP leases it then just don't use IE for anything else or disable Sun Java after running a speed test and continue to use IE with JVM. Of course, I would just have shrugged my shoulders if I ran across a site demanding that I install Sun Java. I detest Sun Java so I would just forget about that site.   <br><SMALL>--<br>The first and foremost function of our jurors is to protect private citizens from a tyrannical and intrusive government...Jurors are the last line of defense for liberty. Thomas Jefferson 1789</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13163104</guid>
<pubDate>Wed, 13 Apr 2005 19:20:11 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13159500</link>
<description><![CDATA[<A HREF="/useremail/u/972855"><b>ElJay</b></A> : <div class="bquote"><SMALL>said by  Mele20 <A HREF="/useremail/u/403861"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR>Winamp won't play the movies. Plus, they won't play in the version of WMP I have. Why can't they be played in Real Player? I have the latest version of it.</DIV>Try downloading the video codec from &raquo;<A HREF="http://www.techsmith.com/products/studio/codecdownload.asp" >www.techsmith.com/products/studi&middot;&middot;&middot;load.asp</A> (169kb)<br><br><div class="bquote"><SMALL>said by  Mele20 <A HREF="/useremail/u/403861"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR>I don't have Sun Java. Does this vulnerability also exist for  MSJVM? It wouldn't matter probably for me since I only use JVM for speed tests and that is one the rare times I use IE instead of Fx.</DIV>I wonder if the Microsoft VM would even ask you before running this nasty installer. Or perhaps the Microsoft VM is so old that it won't be able to run this applet.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13159500</guid>
<pubDate>Wed, 13 Apr 2005 12:18:26 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13157152</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : "I realize it's not Mozilla's issue per se; perhaps Sun can address this."<br><br>Hi B - I covered this type of install a while back (March 9th)and off the back of this initial investigation, Mozilla said they would look to "whitelist" applets with Sun, and a developer for Opera said they would look to change the way "accept" is highlighted as a default. More <A HREF="http://www.vitalsecurity.org/2005/03/firefox-spyware-infects-ie.html">here</A>.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13157152</guid>
<pubDate>Wed, 13 Apr 2005 01:47:34 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13156248</link>
<description><![CDATA[<A HREF="/useremail/u/403861"><b>Mele20</b></A> : &raquo;<A HREF="http://www.spywareguide.com/articles/anatomy_of_a_drive_by_install__72.html" >www.spywareguide.com/articles/an&middot;&middot;&middot;_72.html</A><br><br>Winamp won't play the movies. Plus, they won't play in the version of WMP I have. Why can't they be played in Real Player? I have the latest version of it. So, I can't read the article (I tried copying it to Word and it still produces a horizontal scroll bar) or play the files. :(<br><br>I don't have Sun Java. Does this vulnerability also exist for  MSJVM? It wouldn't matter probably for me since I only use JVM for speed tests and that is one the rare times I use IE instead of Fx.<br><SMALL>--<br>The first and foremost function of our jurors is to protect private citizens from a tyrannical and intrusive government...Jurors are the last line of defense for liberty. Thomas Jefferson 1789</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13156248</guid>
<pubDate>Tue, 12 Apr 2005 23:28:21 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13154880</link>
<description><![CDATA[<A HREF="/useremail/u/326716"><b>redxii</b></A> : <div class="bquote"><SMALL>said by  ElJay <A HREF="/useremail/u/972855"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>Would this help save a Mozilla/Firefox user from this "drive-by?"<br> </DIV>I'm glad you asked:<br><br>With the second option unchecked, I was still given options Yes No and Cancel. With the  first one unchecked, it went away, but applets using the "&lt;applet=""&gt;" code still worked on other (legit) websites. <br><br>For some reason I can't get 3 sites to give a me a popup anymore... trying to undo what I did but they may have taken it down and left the flash one in IE up. I'll restore a fresh image and see what happens...<br><SMALL>--<br>Asus A7N8X-X, Athlon XP 2400+ @ 2.0GHz, 1024MB DDR RAM (@ PC2100), GeForce FX 5600Ultra 128MB, Samsung SD-616T 16x DVD-ROM and Sony CRX215E1 48x24x48 CD-RW, 40GB & 120GB HDD. <br><A HREF="http://www.tuxfiles.org/antihelp/altview.html">Y I Hate L-i-n-u-x</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13154880</guid>
<pubDate>Tue, 12 Apr 2005 21:10:00 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13150564</link>
<description><![CDATA[<A HREF="/useremail/u/229804"><b>B</b></A> : <br>Good find; I don't know.<br><br>The Java 1.4.2 control panel I have doesn't offer anything like that tab...<br><br>-- B<br><SMALL>--<br>In a realm outside causality and function</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13150564</guid>
<pubDate>Tue, 12 Apr 2005 12:35:40 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13150431</link>
<description><![CDATA[<A HREF="/useremail/u/972855"><b>ElJay</b></A> : I noticed in the latest Java VM (1.5.0/"5.0 Update 2") there's an option to disallow granting "permissions to content from an untrusted authority." I can't remember if this option was available in the 1.4.x version.<br><br>Would this help save a Mozilla/Firefox user from this "drive-by?"<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/13150431?c=806676&ret=L2ZvcnVtL3IxMzE0NDAwMC54bWw%3D"><IMG TITLE="10404 bytes" BORDER=0 WIDTH=440 HEIGHT=468 SRC="/r0/download/806676~40618bf52f9fce2b7a590c02a5573a86/jre1.5.0security.png"></A><br>Java Control Panel Security Settings</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13150431</guid>
<pubDate>Tue, 12 Apr 2005 12:15:24 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13150185</link>
<description><![CDATA[<A HREF="/useremail/u/229804"><b>B</b></A> : <br>It's really unfortunate.  It seems that the only way to properly secure clueless newbie browsing under Mozilla is to disable Java entirely?<br><br>I realize it's not Mozilla's issue per se; perhaps Sun can address this.  I believe I've said before in a different thread here -- the Java plug-in really shouldn't even be capable, by default, of breaking the sandbox with a single real-time "drive-by" style query.<br><br>-- B<br><SMALL>--<br>In a realm outside causality and function</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13150185</guid>
<pubDate>Tue, 12 Apr 2005 11:43:04 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13146388</link>
<description><![CDATA[<A HREF="/useremail/u/1125256"><b>xblock</b></A> : B.<br><br>"The Porter/Hertens article seems to omit a rather important little detail -- what does the user have to do, if anything, in order to allow the spyware to install?"<br><br>In the case of IE SP1- they have to do nothing. Just hit the web page which appears blank. I posed this question to my son (a 7 year old) and asked him what happened when he hit the web page on the IE SP1 page. He said "nothing happens Dad". Obviously if you look at the packet log a lot things happpen.<br><br>In the case of IE SP2- The user will see an elaborate movie explaining how to accept the installation. But there is  reference to what is being installed, why it is being installed, or from where it is being installed. The only information they receive from the little movie, aside from install instructions, is a large sign that says THEY MUST INSTALL it.<br><br>In the Firefox the user is presented with a java prompt which asks them to install, but the key factor here is again no EULA is presented.<br><br>Much more analysis is planned on that piece- we worked on it over the weekend to get some dialogue started. It was like digging into a hole and finding a pool of water, the further we swam into the water the more stuff we found until we realized it wasn't water we were wading through but more like a high-stream sewer. So we took one aspect of the problem and focused on it. There are a myriad of things that can be studied and learned from that page. <br><br>The idea for this piece was taken from watching how my son (an eight year old) interacted with a web page and a discussion with my wife ( a teacher) about how kids interact with web pages in her lab.<br><br>So naturally prevention is important, if not the cornerstone of the problem, but we wanted to focus on what the user sees versus what it is actually happening and how the entire installation is mixed up with inadequate diclosure, confusing prompts, and no real attempt to tell the user what is going to happen. <br><br>regards,<br>Wayne]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13146388</guid>
<pubDate>Mon, 11 Apr 2005 21:41:21 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13146336</link>
<description><![CDATA[<A HREF="/useremail/u/817075"><b>Kiwi</b></A> : I'm a wee bit lost, to whom were the replies directed? I see the link works now.<br><br>Cheers]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13146336</guid>
<pubDate>Mon, 11 Apr 2005 21:37:03 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13146324</link>
<description><![CDATA[<A HREF="/useremail/u/1125256"><b>xblock</b></A> : B.<br><br>"The Porter/Hertens article seems to omit a rather important little detail -- what does the user have to do, if anything, in order to allow the spyware to install?"<br><br>In the case of IE SP1- they have to do nothing. Just hit the web page which appears blank. I posed this question to my son (a 7 year old) and asked him what happened when he hit the web page on the IE SP1 page. He said "nothing happens Dad". Obviously if you look at the packet log a lot things happpen.<br><br>In the case of IE SP2- The user will see an elaborate movie explaining how to accept the installation. But there is  reference to what is being installed, why it is being installed, or from where it is being installed. The only information they receive from the little movie, aside from install instructions, is a large sign that says THEY MUST INSTALL it.<br><br>In the Firefox the user is presented with a java prompt which asks them to install, but the key factor here is again no EULA is presented.<br><br>Much more analysis is planned on that piece- we worked on it over the weekend to get some dialogue started. It was like digging into a hole and finding a pool of water, the further we swam into the water the more stuff we found until we realized it wasn't water we were wading through but more like a high-stream sewer. So we took one aspect of the problem and focused on it. There are a myriad of things that can be studied and learned from that page. <br><br>The idea for this piece was taken from watching how my son (an eight year old) interacted with a web page and a discussion with my wife ( a teacher) about how kids interact with web pages in her lab.<br><br>So naturally prevention is important, if not the cornerstone of the problem, but we wanted to focus on what the user sees versus what it is actually happening and how the entire installation is mixed up with inadequate diclosure, confusing prompts, and no real attempt to tell the user what is going to happen.<br><br>regards,<br>Wayne]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13146324</guid>
<pubDate>Mon, 11 Apr 2005 21:36:27 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13146178</link>
<description><![CDATA[<A HREF="/useremail/u/1125256"><b>xblock</b></A> : The problem has been corrected and I apologize to any and all   who were affected. We have put in an extra layer of controls to ensure that doesn't happen again. As punishment I was told that Jan was going to strike me with the nearest blunt object next times he sees me. <br><br>regards,<br>Wayne]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13146178</guid>
<pubDate>Mon, 11 Apr 2005 21:20:16 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13146055</link>
<description><![CDATA[<A HREF="/useremail/u/1003137"><b>garys_2k</b></A> : Never mind, part II.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13146055</guid>
<pubDate>Mon, 11 Apr 2005 21:08:36 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13146033</link>
<description><![CDATA[<A HREF="/useremail/u/1003137"><b>garys_2k</b></A> : Never mind...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13146033</guid>
<pubDate>Mon, 11 Apr 2005 21:05:47 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13145915</link>
<description><![CDATA[<A HREF="/useremail/u/1125256"><b>xblock</b></A> : <br>On the live javascript problem. (I'll get to other comments later) It appears that was my goof. We have an internal article system, but since numerous people worked on this we used dreamweaver to collaborate on the report and took the raw HTML from DW. Because of this we could not use our normal web-based article software so the article was "hard coded" into our database. At that time all scripts were double-checked to make sure they were "dead".<br><br>Long story short I saw a typo on the report and used our internal editing system to fix the typo and that somehow made the scripts active again.<br><br>I have Jan working on fixing it ASAP and thanks for calling this to my attention!<br><br>regards,<br>Wayne ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13145915</guid>
<pubDate>Mon, 11 Apr 2005 20:53:01 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13145865</link>
<description><![CDATA[<A HREF="/useremail/u/378696"><b>eburger68</b></A> : inTulsa:<br><br>Wayne Porter tells me that the problem will be corrected shortly.<br><br>Eric L. Howes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13145865</guid>
<pubDate>Mon, 11 Apr 2005 20:47:43 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13145650</link>
<description><![CDATA[<A HREF="/useremail/u/590777"><b>inTulsa</b></A> : <div class="bquote"><SMALL>said by  Doctor Four <A HREF="/useremail/u/197199"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR>I wonder if anyone's contacted XBlock yet about it - the javascripts are very much active, ...<br> </DIV>Email was sent, a "ticket" on the issue has been opened.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13145650</guid>
<pubDate>Mon, 11 Apr 2005 20:23:10 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13145628</link>
<description><![CDATA[<A HREF="/useremail/u/817075"><b>Kiwi</b></A> : I was reading this and wondered, are people still using ActiveX & Java -Mine have always been disabled even though I maintain current updates, except for MS critical updates and the rather rare speed test on DSLR? <br><br>Using buffer overflow vulnerabilities, or if you like 'Exploits' can be minimised by third party software & surfing habits. I personally hate certificate verification, serves no purpose to the end user at all and wish companies would quit using it!<br><br>{Edit}BTW -Your first link to 'Home' seems to have been DoSd & framed to avoid backing out.<br><br>Good articles though, Eric.<br><br>Cheers<br><SMALL>--<br>2.66g/533fsb Intel CPU @ 3.48g<br>512meg Twinmos PC3700~466 DDR @ 2.8v -PCpower&Cooling 512.<br>ATI 9500 Pro @ 9700 Pro @1.6v<br>--<br>AMD ASUS A7N8X-E ~<br>2500+ @3200 ATI 9500 Pro, Corsair 512LL.-- Aristotle.net</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13145628</guid>
<pubDate>Mon, 11 Apr 2005 20:21:09 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13145577</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : I noticed that as well. I didn't get hit by any of the<br>parasites being profiled due to the use of the MVPS hosts<br>file on my system, but others could very well have gotten<br>infected. I wonder if anyone's contacted XBlock yet about<br>it - the javascripts are very much active, and just<br>visiting the page results in HTTP GET commands in my ad<br>blocker (it logs all headers) for static.windupdates.com,<br>ct4download.com, and xxxtoolbar.com, the host URLs for the<br>parasites being profiled.<br><SMALL>--<br>"Kayura or Badamon, whichever you are, you should know that I will never give up this battle. By the will of the Ancient, I shall succeed!" - Shuten (Anubis) from the Ronin Warriors.To RIAA/MPAA - You can sue but you can't catch everyone!</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13145577</guid>
<pubDate>Mon, 11 Apr 2005 20:13:57 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13145560</link>
<description><![CDATA[<A HREF="/useremail/u/378696"><b>eburger68</b></A> : metrodust:<br><br>Education of users is important. But it's even more important that we not let adware vendors off the hook by making excuses for their substandard, deceptive installation practices.<br><br>We can do both: educate users and insist on better behavior from adware vendors.<br><br>Eric L. Howes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13145560</guid>
<pubDate>Mon, 11 Apr 2005 20:11:49 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13145526</link>
<description><![CDATA[<A HREF="/useremail/u/121311"><b>metrodust</b></A> : the bottom line is still lack of education on the end-users part. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13145526</guid>
<pubDate>Mon, 11 Apr 2005 20:09:03 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13145481</link>
<description><![CDATA[<A HREF="/useremail/u/326716"><b>redxii</b></A> : <div class="bquote"><SMALL>said by  eburger68 <A HREF="/useremail/u/378696"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>It is a myth that the spyware/adware problem has been driven primarily by installations through security exploits .... depressing story of users getting bamboozled by adware vendors into "consenting" to the installation of unwanted software through a combination of trickery, poor information, and still poorer installation processes.</DIV>I posted this in an earlier thread, about ActiveX and IST: &raquo;<A HREF="/forum/remark,13135936">Re: 180Solutions Buying Legitimacy?</A> .. Don't know if you've seen it yet. I believe it supports your claim that it is a myth.<br><br>That is the Internet Explorer equivalent of the Java/Mozilla exploit. What I posted is found on exactly the same pages where there Java/Mozilla exploit are, only when viewed in IE.<br><br>Also, I should mention the click_run_to_remove_virus.exe was unable to execute under a limited account.<br><SMALL>--<br>Asus A7N8X-X, Athlon XP 2400+ @ 2.0GHz, 1024MB DDR RAM (@ PC2100), GeForce FX 5600Ultra 128MB, Samsung SD-616T 16x DVD-ROM and Sony CRX215E1 48x24x48 CD-RW, 40GB & 120GB HDD. <br><A HREF="http://www.tuxfiles.org/antihelp/altview.html">Y I Hate L-i-n-u-x</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13145481</guid>
<pubDate>Mon, 11 Apr 2005 20:04:49 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13145465</link>
<description><![CDATA[<A HREF="/useremail/u/590777"><b>inTulsa</b></A> : Eric - My sincere apologies.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13145465</guid>
<pubDate>Mon, 11 Apr 2005 20:02:47 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13145403</link>
<description><![CDATA[<A HREF="/useremail/u/378696"><b>eburger68</b></A> : inTulsa:<br><br>Please direct your comments to the correct parties. I am not affiliated with XBlock nor do I control those pages.<br><br>Eric L. Howes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13145403</guid>
<pubDate>Mon, 11 Apr 2005 19:57:24 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13145357</link>
<description><![CDATA[<A HREF="/useremail/u/590777"><b>inTulsa</b></A> : <div class="bquote"><SMALL>said by  eburger68 <A HREF="/useremail/u/378696"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR>Anatomy of a Drive-By Install- Even on Firefox<br>&raquo;<A HREF="http://www.spywareguide.com/articles/anatomy_of_a_drive_by_install__72.html" >www.spywareguide.com/articles/an&middot;&middot;&middot;_72.html</A><br> </DIV><STRIKE>Caution - referenced malware scripts are EXECUTING in browsers viewing that spywareguide.com page!<br><br>Fortunately I block those domains ... but others won't be so lucky.</STRIKE><br><br>The earlier problem has been fixed.<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/13145357?c=806332&ret=L2ZvcnVtL3IxMzE0NDAwMC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="3302 bytes" WIDTH=600 HEIGHT=232 SRC="/r0/download/806332.thumb600~ce673c23d7ade9e6967afee2bd7e1f7c/spaz_1.gif/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/13145357?c=806333&ret=L2ZvcnVtL3IxMzE0NDAwMC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="12413 bytes" WIDTH=600 HEIGHT=295 SRC="/r0/download/806333.thumb600~9cf2921c8f307a489a6b8c8e2766a6ce/spaz_2.gif/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/13145357?c=806334&ret=L2ZvcnVtL3IxMzE0NDAwMC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="6555 bytes" WIDTH=600 HEIGHT=100 SRC="/r0/download/806334.thumb600~27b58d9423888f99900788348a6f6411/spaz_3.gif/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13145357</guid>
<pubDate>Mon, 11 Apr 2005 19:53:22 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13144918</link>
<description><![CDATA[<A HREF="/useremail/u/937383"><b>TeMerc</b></A> : Thanks for the great reading Eric, I had already read and linkde Bens article the other nite on my site, this of course expands things quite a bit.<br><br><I>Moreover, where Suzi was testing primarily on Mozilla 1.7, Wayne and Jan test on Firefox and Internet Explorer. The site in question serves up different install packages based on the browser being used to visit the site.</I><br><br>I guess it was just a matter of time before these lowlifes started writting dual coding to infect whichever browser your running at the time. Just goes to show, no matter which browser your runninng, your always at risk. :huh:<br><SMALL>--<br>Remember............You can NEVER be OVERPROTECTED!!&raquo;<A HREF="http://temerc.com/" >temerc.com/</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13144918</guid>
<pubDate>Mon, 11 Apr 2005 18:57:23 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13144686</link>
<description><![CDATA[<A HREF="/useremail/u/1058588"><b>bpm3k</b></A> : Deleted.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13144686</guid>
<pubDate>Mon, 11 Apr 2005 18:28:45 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13144621</link>
<description><![CDATA[<A HREF="/useremail/u/570051"><b>novaflare</b></A> : hmm i dled the url.zip and looked at the url list my god theres lots of them in there. <br><br> Not to long ago i was fortunate enough (unfortunatly for cool web search) able to log in to and delete the entire contents of a ftp site of theres. Maybe they should have had the installer delete the .cmd file after install. I deleted aprox 18gigs from the ftp. Images adds links html and on the way out i changed the pass word. Corse the domain it was on was probably going to disapear in a couple days any how. Like the one in the .cmd file from a week earlyer.<br><SMALL>--<br>DSLR security chat at us.ausirc.net chanel #dslr_sec lets pack this channelopen source dns server for *nix and windows &raquo;<A HREF="http://powerdns.com" >powerdns.com</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13144621</guid>
<pubDate>Mon, 11 Apr 2005 18:19:50 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13144438</link>
<description><![CDATA[<A HREF="/useremail/u/378696"><b>eburger68</b></A> : metrodust:<br><br><div class="bquote"><SMALL>said by  metrodust <A HREF="/useremail/u/121311"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR>the simple answer to aviod infection would be to not click OK on the box that has the big yellow signs and the words INVALID and NOT TRUSTED all over it. </DIV>It's purely a convenient coincidence that Integrated Search Technologies happens to be using an expired certificate from a CA not yet "trusted" by users (most of whom won't understand what it would take to "trust" a CA/issuer in the first place). <br><br>The fact that the user has not elected to trust the CA has NOTHING to do with the trustworthiness of the Java applet itself. IST could have just as easily used a cert from Thawte/Verisign, which would be trusted by default through the user's browser. <br><br>In fact, we see this all the time with ActiveX controls installed by spyware/adware through Internet Explorer, almost all of which are signed with certs issued by Thawte/Verisign. The fact that the ActiveX control has been signed with a cert issued by a trusted CA says absolutely *nothing* about the trustworthiness of the ActiveX control itself, because Thawte/Verisign will issues certs to just about anyone under any name. See Ben Edelman's recent discussion of this problem for more information:<br><br>&raquo;<A HREF="http://www.benedelman.org/news/020305-1.html" >www.benedelman.org/news/020305-1.html</A><br><br>And what if IST were to get a new signing cert from Thawte/Verisign? Would you then advise users that the app was "trustworthy"?<br><br>Of course not, because the real problem lies elsewhere. The real problem with Java applet Warning box is that it provides no useful information whatsoever to the user. None. Most users aren't going to be familiar with "Integrated Search Technologies," which sounds like an innocuous enough company. Still worse, there's not even a link, such as the much maligned ActiveX Security Warning box provides, for the user to get more information or read the EULA associated with the program. <br><br>And given that users will encounter these Java applet Warning boxes (or similar looking ones) frequently in the surfing around the Net, it's a serious problem that they don't have any useful method for distinguishing between trustworthy and non-trustworthy Java applets. The same holds true for ActiveX controls, though at least users can get to a EULA of some sort and Microsoft has implemented some changes in XP SP2 to take those Security Warning boxes out of users' faces.<br><br>It is a myth that the spyware/adware problem has been driven primarily by installations through security exploits. Always has been. In fact, those kinds of exploit-based installations really only took off in the last year or so. Since the beginning in 2000, the spyware/adware problem has largely been the depressing story of users getting bamboozled by adware vendors into "consenting" to the installation of unwanted software through a combination of trickery, poor information, and still poorer installation processes.<br><br>Eric L. Howes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13144438</guid>
<pubDate>Mon, 11 Apr 2005 17:55:57 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13144320</link>
<description><![CDATA[<A HREF="/useremail/u/403861"><b>Mele20</b></A> : I'd love to read the article, but the webmaster needs to fix that site. It sprawls so badly that I have a horizontal scroll bar there and cannot see the article without long horizontal scrolling of each line. If I make the zoom below 100% then the horizontal scroll bar disappears but I can't read the tiny print. This is on Firefox and usually 100% to 120% text zoom is what I use on sites, but that site needs 150% or higher text zoom to be comfortably readable. <br><br>ON IE, with the text set to "medium" I get an even WORSE horizontal scroll bar! So, that site really needs to fix things. Do they expect everyone to use "smallest" font size on IE? That is the only one that doesn't produce the horizontal scroll bar. I have a 19" flat panel LCD at 1280x1024. I think that site is designed for 800x600. Maybe I can read it with out the horizontal scroll bar appearing if I used my 17" Trinitron connected to my older computer.<br><br>I suppose I can copy the article to Word when I have time and read it that way. <br><SMALL>--<br>The first and foremost function of our jurors is to protect private citizens from a tyrannical and intrusive government...Jurors are the last line of defense for liberty. Thomas Jefferson 1789</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13144320</guid>
<pubDate>Mon, 11 Apr 2005 17:41:39 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13144227</link>
<description><![CDATA[<A HREF="/useremail/u/121311"><b>metrodust</b></A> : <div class="bquote"><SMALL>said by  B <A HREF="/useremail/u/229804"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>The Porter/Hertens article seems to omit a rather important little detail -- what does the user have to <B>do</B>, if anything, in order to allow the spyware to install?<br><br>They show what the users SEE under each browser, but don't seem to discuss what the user would do or click next, or what he or she could do at that point to <B>avoid</B> the infections...?<br><br>-- B<br> </DIV>the simple answer to aviod infection would be to not click OK on the box that has the big yellow signs and the words INVALID and NOT TRUSTED all over it. <br><SMALL>--<br>When you are leaving.. heaven is a distance not a place. --Carissas Weird</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13144227</guid>
<pubDate>Mon, 11 Apr 2005 17:29:18 EDT</pubDate>
</item>

<item>
<title>Re: Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13144087</link>
<description><![CDATA[<A HREF="/useremail/u/229804"><b>B</b></A> : <br>The Porter/Hertens article seems to omit a rather important little detail -- what does the user have to <B>do</B>, if anything, in order to allow the spyware to install?<br><br>They show what the users SEE under each browser, but don't seem to discuss what the user would do or click next, or what he or she could do at that point to <B>avoid</B> the infections...?<br><br>-- B<br><SMALL>--<br>In a realm outside causality and function</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13144087</guid>
<pubDate>Mon, 11 Apr 2005 17:15:05 EDT</pubDate>
</item>

<item>
<title>Anatomy of a Drive-by-Install</title>
<link>http://www.dslreports.com/forum/remark,13144000</link>
<description><![CDATA[<A HREF="/useremail/u/378696"><b>eburger68</b></A> : Hi All:<br><br>Wayne Porter and Jan Hertens of XBlock have just posted a fascinating analysis of a collection of drive-by-installs of spyware and adware that occur at a dubious web site:<br><br>Anatomy of a Drive-By Install- Even on Firefox<br>&raquo;<A HREF="http://www.spywareguide.com/articles/anatomy_of_a_drive_by_install__72.html" >www.spywareguide.com/articles/an&middot;&middot;&middot;_72.html</A><br><br>Included in their write-up are videos, packet logs, and an extended traffic analysis of the site itself. Although this write-up is more than a little technical, it's well worth your time to have a look, as it offers real insight into how this kind of unethical, deceptive installation practice occurs.<br><br>It should be noted that Wayne and Jan are analyzing the same site that Suzi of Spyware Warrior did in her recent blog entry on 180solutions & CDT, Inc.:<br><br>Oh, What A Tangled Web We Weave...<br>&raquo;<A HREF="http://netrn.net/spywareblog/archives/2005/04/09/oh-what-a-tangled-web-we-weave/" >netrn.net/spywareblog/archives/2&middot;&middot;&middot;e-weave/</A><br><br>Like Wayne and Jan, Suzi also has videos (look at the end of the blog entry for the second). Where Wayne and Jan devote most of their attention to the underlying mechanics of the drive-by-installs, though, Suzi focuses on the behavior of the 180search Assistant from 180solutions, which is one of the adware programs installed by the site.<br><br>Moreover, where Suzi was testing primarily on Mozilla 1.7, Wayne and Jan test on Firefox and Internet Explorer. The site in question serves up different install packages based on the browser being used to visit the site.<br><br>Once you're finished reading these new articles from Wayne, Jan, and Suzi, you also ought to have a look at Ben Edelman's new series of articles on unethical installation methods being employed to install adware and spyware:<br><br>New Series on Spyware Installation Methods<br>&raquo;<A HREF="http://www.benedelman.org/news/041105-1.html" >www.benedelman.org/news/041105-1.html</A><br><br>Spyware Installation Methods (table)<br>&raquo;<A HREF="http://www.benedelman.org/spyware/installations/" >www.benedelman.org/spyware/installations/</A><br><br>3D Desktop's Misleading Installation Methods (write-up)<br>&raquo;<A HREF="http://www.benedelman.org/spyware/installations/3d-screensaver/" >www.benedelman.org/spyware/insta&middot;&middot;&middot;ensaver/</A><br><br>There's some overlap between all these new articles, which complement each other very well. Each offers some unqiue insight into the problem of spyware, adware, and how these unwanted software programs are pushed on unsuspecting consumers, despite the profuse professions of innocence by the companies involved.<br><br>For those desiring still more reading on the same subject, you might take a look at one of my submissions to the FTC from last year (right about this time, in fact):<br><br>The Anatomy of a Drive-by-Download<br>&raquo;<small>https</small>://<A HREF="https://netfiles.uiuc.edu/ehowes/www/dbd-anatomy.htm">netfiles.uiuc.edu/ehowes/www/dbd-anatomy.htm</A><br><br>In any case, happy reading.<br><br>All the best,<br><br>Eric L. Howes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13144000</guid>
<pubDate>Mon, 11 Apr 2005 17:03:56 EDT</pubDate>
</item>

</channel>
</rss>
