<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste) in Security</title>
<link>http://www.dslreports.com/forum/r20928440</link>
<description></description>
<language>en</language>
<pubDate>Fri, 27 Nov 2009 08:33:48 EDT</pubDate>
<lastBuildDate>Fri, 27 Nov 2009 08:33:48 EDT</lastBuildDate>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,21173704</link>
<description><![CDATA[<A HREF="/useremail/u/634007"><b>SUMware</b></A> : <div class="bquote"><small>said by  swhx7 <A HREF="/useremail/u/1376598"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br>So is this now the correct thread for the clickjacking topic? I believe it is not the same as the original topic here, i.e. the clipboard exploit, but anyway.</div>It would probably better to start a new 'clickjacking' thread. This looks to be a serious and ongoing vuln that will continue for quite some time. So feel free...<br><br>Your info is very interesting. Thanks.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21173704</guid>
<pubDate>Fri, 26 Sep 2008 15:13:59 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,21173608</link>
<description><![CDATA[<A HREF="/useremail/u/766601"><b>avd706</b></A> : The only solution is #5]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21173608</guid>
<pubDate>Fri, 26 Sep 2008 15:00:29 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,21173536</link>
<description><![CDATA[<A HREF="/useremail/u/1376598"><b>swhx7</b></A> : So is this now the correct thread for the clickjacking topic? I believe it is not the same as the original topic here, i.e. the clipboard exploit, but anyway.<br><br>The discoverers have been vague about just what the "clickjacking" involves. The reason of course is the same as in the recent Kaminsky/DNS thing, to give vendors time to patch. This has led to some anxiety about how site maintainers and surfers can be safe.<br><br>In looking around however, I found a clear explanation of at least one implementation of it: &raquo;<A HREF="http://lists.whatwg.org/pipermail/whatwg-whatwg.org/2008-September/016284.html" >lists.whatwg.org/pipermail/whatw&middot;&middot;&middot;284.html</A><br><br>The above is already out there, so I'm not making it any worse by linking.<br><br>I favor Zalewski's #4, because it puts the user most in control.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21173536</guid>
<pubDate>Fri, 26 Sep 2008 14:49:52 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,21170581</link>
<description><![CDATA[<A HREF="/useremail/u/634007"><b>SUMware</b></A> : DF, thanks for posting this additional information.<br><br>From your link &raquo;<A HREF="http://blogs.zdnet.com/security/?p=1973" >blogs.zdnet.com/security/?p=1973</A> it's worth excerpting the following:   <blockquote><small>quote:</small><hr>In response to my story earlier on the cross-browser Clickjacking exploit/threat, I received the following e-mail from Giorgio Maone, creator of the popular Firefox NoScript plug-in:<br><blockquote>Hi Ryan,<br><br>I&#146;ve seen a lot of speculation and confusion in the comments to your Clickjacking article about NoScript not being able to mitigate [the issue].<br><br>I had access to detailed information about how this attack works and I can tell you the following:<br><blockquote>1. It&#146;s really scary<br>2. NoScript in its default configuration can defeat most of the possible attack scenarios (i.e. the most practical, effective and dangerous) &#151; see <A HREF="http://ha.ckers.org/blog/20080915/clickjacking/#comment-84820">this comment</a> by Jeremiah Grossman himself.<br>3. For 100% protection by NoScript, you need to check the "Plugins|Forbid [IFRAME]" option..</blockquote><br><br>Cheers,<br>Giorgio</blockquote><br><br>I also received private confirmation from a high-level source at an affected vendor about the true severity of this issue.  In a nutshell, I was told that it&#146;s indeed &#147;very, freaking scary&#148; and &#147;near impossible&#148; to fix properly.<br><br>Tod Beardsley from BreakingPoint has posted <A HREF="http://www.breakingpointsystems.com/community/blog/clickjacking">a few proof-of-concept exploits</a> with speculation around clickjacking.<hr></blockquote>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21170581</guid>
<pubDate>Fri, 26 Sep 2008 00:44:03 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,21170142</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : Adobe says they are going to fix this, but there is now a much more serious threat involving clickjacking:<br><br>&raquo;<A HREF="http://blogs.zdnet.com/security/?p=1972" >blogs.zdnet.com/security/?p=1972</A><br><br> <blockquote><small>quote:</small><hr>In a nutshell, it&#146;s when you visit a malicious website and the attacker is able to take control of the links that your browser visits.  The problem affects all of the different browsers except something like lynx.  The issue has nothing to do with JavaScript so turning JavaScript off in your browser will not help you.  It&#146;s a fundamental flaw with the way your browser works and cannot be fixed with a simple patch.  With this exploit, once you&#146;re on the malicious web page, the bad guy can make you click on any link, any button, or anything on the page without you even seeing it happening.<br><hr></blockquote><br><br>Firefox and NoScript can give a degree of protection against this, according to an email the creator, Giorgio Maone, sent the ZDNet blogger.<br><br>&raquo;<A HREF="http://blogs.zdnet.com/security/?p=1973" >blogs.zdnet.com/security/?p=1973</A><br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21170142</guid>
<pubDate>Thu, 25 Sep 2008 22:50:27 EDT</pubDate>
</item>

<item>
<title>Re: To Be Fixed in Flash Player 10</title>
<link>http://www.dslreports.com/forum/remark,21148022</link>
<description><![CDATA[<A HREF="/useremail/u/352846"><b>antdude</b></A> : <div class="bquote"><small>said by  SUMware <A HREF="/useremail/u/634007"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>From <A HREF="http://blogs.zdnet.com/security/?p=1948">ZDNet</a><br>September 19th, 2008 -   <blockquote><small>quote:</small><hr><b>Adobe moves to nuke &#145;clipboard hijack&#146; attacks</b><br><br>Adobe has announced plans to modify the next version of its Flash Player to use an &#147;allow/deny&#148; system to mitigate <A HREF="http://blogs.zdnet.com/security/?p=1733">clipboard hijack</a> attacks.<br><br>The change will be fitted into the final version of Flash Player 10 to demand user interaction when a Shockwave (.swf) file attempts to set data on a user&#146;s clipboard. It follows news that malicious hackers are using booby-trapped Flash banner ads to hijack clipboards for use in rogue security software attacks.<br><br>(See Aviv Raff&#146;s  <A HREF="http://raffon.net/research/flash/cb/test.html">proof-of-concept demo</a> to show how easy it is to use Flash with ActionScript code to persistently load a malicious URL into a target clipboard).<br><br>Here&#146;s the skinny on the Flash Player 10 changes:<br><blockquote>In Flash Player 9, ActionScript could set data on the system Clipboard at any time. With Flash Player 10 beta, the <small><b>System.setClipboard()</b></small> method may be successfully called only through ActionScript that originates from user interaction. This includes actions such as clicking the mouse or using the keyboard. This user interaction requirement also applies to the new ActionScript 3.0 <small><b>Clipboard.generalClipboard.setData()</b></small> and <small><b>Clipboard.generalClipboard.setDataHandler()</b></small> methods.<br><br>This change can potentially affect any SWF file that makes use of the <small><b>System.setClipboard()</b></small> method. This change affects SWF files of all versions played in Flash Player 10 beta and later. This change affects all non-application content in Adobe AIR&#151;however, AIR application content itself is unaffected.<br><br>Any existing content that sets data on the system Clipboard using the <small><b>System.setClipboard()</b></small> method outside of an event triggered by user interaction will need to be updated. Setting the Clipboard will now have to be invoked through a button, keyboard shortcut, or some other event initiated by the user.</blockquote><br>Adobe already uses an allow/deny mechanism when a SWF file attempts to access a user&#146;s camera or microphone using the <small><b>Camera.get()</b></small> or <small><b>Microphone.get()</b></small> methods.<hr></blockquote><br> </div>Will it be fixed in newer Flash v9? Or do we have to update to v10? :(<br><small>--<br>Ant @ &raquo;<A HREF="http://antfarm.ma.cx" >antfarm.ma.cx</A> and &raquo;<A HREF="http://aqfl.net" >aqfl.net</A>. Please do not IM/e-mail me for technical support. Use the forum! Disclaimer: The views expressed in this posting are mine, and do not necessarily reflect the views of my employer</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21148022</guid>
<pubDate>Mon, 22 Sep 2008 03:00:43 EDT</pubDate>
</item>

<item>
<title>To Be Fixed in Flash Player 10</title>
<link>http://www.dslreports.com/forum/remark,21143053</link>
<description><![CDATA[<A HREF="/useremail/u/634007"><b>SUMware</b></A> : From <A HREF="http://blogs.zdnet.com/security/?p=1948">ZDNet</a><br>September 19th, 2008 -  <blockquote><small>quote:</small><hr><b>Adobe moves to nuke &#145;clipboard hijack&#146; attacks</b><br><br>Adobe has announced plans to modify the next version of its Flash Player to use an &#147;allow/deny&#148; system to mitigate <A HREF="http://blogs.zdnet.com/security/?p=1733">clipboard hijack</a> attacks.<br><br>The change will be fitted into the final version of Flash Player 10 to demand user interaction when a Shockwave (.swf) file attempts to set data on a user&#146;s clipboard. It follows news that malicious hackers are using booby-trapped Flash banner ads to hijack clipboards for use in rogue security software attacks.<br><br>(See Aviv Raff&#146;s  <A HREF="http://raffon.net/research/flash/cb/test.html">proof-of-concept demo</a> to show how easy it is to use Flash with ActionScript code to persistently load a malicious URL into a target clipboard).<br><br>Here&#146;s the skinny on the Flash Player 10 changes:<br><blockquote>In Flash Player 9, ActionScript could set data on the system Clipboard at any time. With Flash Player 10 beta, the <small><b>System.setClipboard()</b></small> method may be successfully called only through ActionScript that originates from user interaction. This includes actions such as clicking the mouse or using the keyboard. This user interaction requirement also applies to the new ActionScript 3.0 <small><b>Clipboard.generalClipboard.setData()</b></small> and <small><b>Clipboard.generalClipboard.setDataHandler()</b></small> methods.<br><br>This change can potentially affect any SWF file that makes use of the <small><b>System.setClipboard()</b></small> method. This change affects SWF files of all versions played in Flash Player 10 beta and later. This change affects all non-application content in Adobe AIR&#151;however, AIR application content itself is unaffected.<br><br>Any existing content that sets data on the system Clipboard using the <small><b>System.setClipboard()</b></small> method outside of an event triggered by user interaction will need to be updated. Setting the Clipboard will now have to be invoked through a button, keyboard shortcut, or some other event initiated by the user.</blockquote><br>Adobe already uses an allow/deny mechanism when a SWF file attempts to access a user&#146;s camera or microphone using the <small><b>Camera.get()</b></small> or <small><b>Microphone.get()</b></small> methods.<hr></blockquote>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21143053</guid>
<pubDate>Sat, 20 Sep 2008 19:59:43 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,21101245</link>
<description><![CDATA[<A HREF="/useremail/u/1112464"><b>MeanPeepsSuk</b></A> : Removed my response/question from last night as no longer relevant.<br><br>Just realized this was an old thread brought to the top again.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21101245</guid>
<pubDate>Fri, 12 Sep 2008 18:33:58 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,21100361</link>
<description><![CDATA[<A HREF="/useremail/u/1580965"><b>Jayhawk21</b></A> : I would just like to point out that this happened to me in Vista with Google Chrome today.<br><br>Damn!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21100361</guid>
<pubDate>Fri, 12 Sep 2008 15:48:46 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20981142</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : <div class="bquote"><small>said by  therube <A HREF="/useremail/u/1107429"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Using <A HREF="http://noscript.net">NoScript</a> (& assuming that Flash is blocked) thwarts the exploit.  And even if you were to Temporarily Allow the Flash, once you Revoke Temporary Persmissions, the exploit again ends.<br><br>So it looks like my earlier thoughts were partially correct.  It does involve Flash & JavaScript, but it is not dependent upon IE or ActiveX.<br> </div>Indeed it does thwart the hijacking. From the NoScript homepage: &raquo;<A HREF="http://noscript.net/?ver=1.7.9&prev=1.7.8#contentblocking" >noscript.net/?ver=1.7.9&prev=1.7&middot;&middot;&middot;blocking</A><br><br>Looks like third party flash is blocked by default unless specifically allowed.<br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20981142</guid>
<pubDate>Wed, 20 Aug 2008 17:47:49 EDT</pubDate>
</item>

<item>
<title>Adobe Product Security Incident Response Team (PSIRT)</title>
<link>http://www.dslreports.com/forum/remark,20980329</link>
<description><![CDATA[<A HREF="/useremail/u/634007"><b>SUMware</b></A> : From Adobe August 19, 2008:<br><br><A HREF="http://blogs.adobe.com/psirt/2008/08/clipboard_attack.html">Clipboard attack</a><br>"<i>We are aware of recent press reports about a potential &#147;Clipboard attack&#148; issue that involves Flash Player. Adobe is currently investigating potential solutions to this issue and will update customers as soon as we have more information to provide.</i>"]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20980329</guid>
<pubDate>Wed, 20 Aug 2008 15:14:00 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20979193</link>
<description><![CDATA[<A HREF="/useremail/u/1107429"><b>therube</b></A> : Ha!  That is only too funny.<br><br>I'm trying to figure out why I can't get the testcase to work?  It was not until I went to copy/paste a URL into another window that I see it DID work.  Crafty.<br><br>If that happened to me out of the blue, it would be disconcerting to say the least.<br><br>Using <A HREF="http://noscript.net">NoScript</a> (& assuming that Flash is blocked) thwarts the exploit.  And even if you were to Temporarily Allow the Flash, once you Revoke Temporary Persmissions, the exploit again ends.<br><br>So it looks like my earlier thoughts were partially correct.  It does involve Flash & JavaScript, but it is not dependent upon IE or ActiveX.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20979193</guid>
<pubDate>Wed, 20 Aug 2008 11:47:17 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20978864</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : I decided last night to see if I could duplicate this<br>hijack, so I did something dangerous, security-wse:<br>I disabled my hosts file temporarily.<br><br>I then went to several of the sites where the hijack was<br>being reported, while using IE and Fiddler, and not once<br>did I see it - no fraudware URLs showed up in Fiddler's<br>capture logs.<br><br>I'll try again tonight, but I have to wonder if the ad<br>network that was a vector for this hijack caught onto it<br>and got rid of it.<br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20978864</guid>
<pubDate>Wed, 20 Aug 2008 10:43:01 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20977559</link>
<description><![CDATA[<A HREF="/useremail/u/1357530"><b>Bink</b></A> : I swear, Flash is becoming the scourge of the Internet.  If you use Internet Explorer, do yourself a favor and leave Flash disabled&#151;&raquo;<A HREF="http://flash.melameth.com" >flash.melameth.com</A>.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20977559</guid>
<pubDate>Wed, 20 Aug 2008 01:01:52 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20977555</link>
<description><![CDATA[<A HREF="/useremail/u/634007"><b>SUMware</b></A> : Hijack demo prevented by NoScript and Proxo via Flash control (read about the demo at bottom of page <A HREF="http://blogs.zdnet.com/security/?p=1733">here</a>) .<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20977555?c=1340866&ret=L2ZvcnVtL3IyMDkyODQ0MC54bWw%3D"><IMG TITLE="9478 bytes" BORDER=0 WIDTH=420 HEIGHT=344 SRC="/r0/download/1340866~a1df4903b508ce1dc2dc4dcb8873c77c/noscript.png"></A><br>NoScript</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20977555?c=1340869&ret=L2ZvcnVtL3IyMDkyODQ0MC54bWw%3D"><IMG TITLE="5095 bytes" BORDER=0 WIDTH=417 HEIGHT=77 SRC="/r0/download/1340869~6ea5485d2dd4b42a5e35ebd561244a01/proxo2.png"></A><br>Proxomitron</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20977555</guid>
<pubDate>Wed, 20 Aug 2008 00:59:59 EDT</pubDate>
</item>

<item>
<title>Pwning the clipboard - latest trick in FakeAlert distribution</title>
<link>http://www.dslreports.com/forum/remark,20977507</link>
<description><![CDATA[<A HREF="/useremail/u/634007"><b>SUMware</b></A> : &raquo;<A HREF="http://www.sophos.com/security/blog/2008/08/1671.html?_log_from=rss" >www.sophos.com/security/blog/200&middot;&middot;&middot;from=rss</A><br><br>"The fact that victims report experiencing these issues after browsing legitimate, popular sites, suggests that malicious Flash is the culprit. The attackers are probably using the <b>setClipboard()</b> method within ActionScript embedded in Flash content. Maybe the attackers have poisoned some ad-stream as a way of hitting large volumes of users?<br><br>I guess we should be glad the Adobe folks were wise enough to not provide the corresponding <b>getClipboard()</b> method!"]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20977507</guid>
<pubDate>Wed, 20 Aug 2008 00:39:42 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20977357</link>
<description><![CDATA[<A HREF="/useremail/u/634007"><b>SUMware</b></A> : Try setting Firefox's <A HREF="http://kb.mozillazine.org/Clipboard.autocopy"><i>clipboard.autocopy</i></a> to 'false' in about:config.<br><br>Also, check setting <i>noscript.allowClipboard</i> to see if it is set to 'false'.<br>NoScript Options > Advanced > Trusted tab - uncheck the 'Allow rich text copy and paste from external clipboard' preference.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20977357</guid>
<pubDate>Tue, 19 Aug 2008 23:59:01 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20977168</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : This is getting to be a hot topic, as Sandi notes. <strike>Also,<br>Firefox and NoScript <b>do not</b> block the clipboard<br>hijack.</strike> So far, the only ways to prevent it are either to<br>block flash, or close the browser when it occurs.<br><br>&raquo;<A HREF="http://msmvps.com/blogs/spywaresucks/archive/2008/08/20/1645130.aspx" >msmvps.com/blogs/spywaresucks/ar&middot;&middot;&middot;130.aspx</A><br><br>Seems having a hosts file does work, though. I have tried<br>several of the sites in question, and not once have I seen<br>this occur. <br><br>I did try Newsweek's site, and quantserve/quantcast showed<br>up again in the page's source. I didn't see it on either <br>MSN or MSNBC's home page, though.<br><br>Edit: I tested FF and NoScript on the proof-of-concept<br>site Sandi mentioned. It doesn't work unless you allow<br>the site in NoScript. Seems that would still be effective<br>at preventing the hijack as it is coming from a third party<br>(and one which is likely to be marked as untrusted).<br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20977168</guid>
<pubDate>Tue, 19 Aug 2008 23:16:17 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20970560</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : More on this from Sandi:<br><br>&raquo;<A HREF="http://msmvps.com/blogs/spywaresucks/archive/2008/08/18/1644914.aspx" >msmvps.com/blogs/spywaresucks/ar&middot;&middot;&middot;914.aspx</A><br><br>Also, according some comments on The Register, this is<br>happening on Monster, as well as Digg and Facebook, which<br>were previously mentioned. And one reader got hit while <br>browsing Ars Technica.<br><br>Taking a look at several pages' source code, I believe I<br>might have found the vector for the clipboard hijack: <br>edge.quantserve.com. In each case, it is pulling a bit of<br>javascript. It might be time to temporarily disable the<br>hosts file, run Fiddler (an HTTP debugging utility) and<br>see if this can be confirmed.<br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20970560</guid>
<pubDate>Mon, 18 Aug 2008 18:36:35 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20964500</link>
<description><![CDATA[<A HREF="/useremail/u/1376598"><b>swhx7</b></A> : At first I was sure this couldn't be done Javascript alone in Mozilla browsers. On following some links, I found one poster saying he did it with 20 lines of Javascript but only if a default was changed in <tt>about:config</tt>.<br><br>The only source for a claim that it happened on Firefox is <A HREF="http://discussions.apple.com/thread.jspa?messageID=7768848">this post ( &raquo;<A HREF="http://discussions.apple.com/thread.jspa?messageID=7768848" >discussions.apple.com/thread.jsp&middot;&middot;&middot;=7768848</A> )</a> on a Mac forum. As other posters suggested there, it probably relied on a plugin such as Java or Flash. Only Microsoft counts it as a positive "feature" that web pages can overwrite the clipboard. At least IE now has a more nearly explanatory label on the means to turn it off (it used to be "Allow paste operations via script"). <br><br>Is it on by default in IE7 or 8?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20964500</guid>
<pubDate>Sun, 17 Aug 2008 15:07:55 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20959256</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Try disabling the "Clipbook" service and see if it works...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20959256</guid>
<pubDate>Sat, 16 Aug 2008 08:18:40 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20958798</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : Thanks for the link.<br><br>Meanwhile, a search around the internet reveals that various codes for this "feature" or "exploit" have been around for a long time. <br><br>As a "feature" people put code into their web pages with buttons to activate the copy/paste. Or to auto-copy text in a form.<br><br>As an "exploit" where you force something to be copied to the clipboard, here is one I found for IE5/6:<br><br><textarea name="code" class="text" cols=50 rows=10>&lt;script&gt;&#012; &#012;// Place your text in a variable&#012;var strMyText = "some test text";&#012; &#012;// Copy to clipboard&#012;window.clipboardData.setData( "Text", strMyText );&#012; &#012;&lt;/script&gt;&#012;</textarea><!--end code block--><br>I tried it even with that feature disabled in Options as mentioned by <b> therube <A HREF="/useremail/u/1107429"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A></b> or even if Scripting is disabled, but it works anyway. I might not be doing something right in Options -- I don't know IE that well.<br><br>As far as exploiting other browsers -- unfortunately no one in the Mac forum kept the URL for the offending page, and theories ranged from Java and Flash to Ajax as being able to write continuously to the clipboard, forcing the user to reboot to clear the clipboard.<br><br>By the way - what do you suppose was copied to the clipboard of the Mac user mentioned on the Apple forum? If you guessed the WinAntiVirus2009 freescan site URL, you win a prize!<br><br>EDIT:<br><br>Here is a site which tests IE for capturing your last clipboard entry. The code is different, and the paste fails if I have scripting disabled, or "Allow paste operations via script" disabled.<br><br>&raquo;<A HREF="http://www.sourcecodesworld.com/special/clipboard.asp" >www.sourcecodesworld.com/special&middot;&middot;&middot;oard.asp</A><br><br><br><br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20958798</guid>
<pubDate>Sat, 16 Aug 2008 01:50:07 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20957888</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : And it isn't just Windows/IE users that are being hit<br>by this. Here's a nail in the coffin for those who think <br>Apple and Firefox are more secure:<br>&raquo;<A HREF="http://msmvps.com/blogs/spywaresucks/archive/2008/08/15/1644705.aspx" >msmvps.com/blogs/spywaresucks/ar&middot;&middot;&middot;705.aspx</A><br><br>The incident Sandi describes involves a Mac user and the<br>Firefox browser.<br><br>Apparently this copy/paste malware is also hitting Facebook<br>and Digg users, as posters to Apple Discussions have noted.<br>I don't know about Facebook, but looking at the source of<br>Digg's home page indicates something might be in common with<br>MSN and MSNBC: Microsoft advertising.<br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20957888</guid>
<pubDate>Fri, 15 Aug 2008 21:29:07 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20948014</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : Thanks for the information. Unfortunately, links from this site explaining the script code for cut, copy, paste, bring up "Content not found"<br><br>&raquo;<A HREF="http://msdn.microsoft.com/en-us/library/bb250473(VS.85).aspx" >msdn.microsoft.com/en-us/library&middot;&middot;&middot;85).aspx</A> <br><br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20948014</guid>
<pubDate>Wed, 13 Aug 2008 23:34:58 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20943860</link>
<description><![CDATA[<A HREF="/useremail/u/1107429"><b>therube</b></A> : And it looks like we're coming back to ActiveX too.  And IE.  IE being a "trusted" application, of course.<br><br>Why might one have "Clipboard access" enabled?  Well, because MS tells you to do so.<br><br>   <blockquote><small>quote:</small><hr>ActiveX controls are used for certain functionality in Microsoft Office Project Professional 2007 and in Microsoft Office Project Web Access. In order for the ActiveX controls to work properly, the Office Project Web Access Web site must be added to the list of trusted sites in Internet Explorer. There are additional security settings that can be configured, but they are optional.<br><br>&raquo;<A HREF="http://technet.microsoft.com/en-us/library/cc197703.aspx" >technet.microsoft.com/en-us/libr&middot;&middot;&middot;703.aspx</A><br><hr></blockquote><br><br> <br> <br>Perhaps this cannot even be disabled in IE6?<br><br><A HREF="http://www.mydigitallife.info/2006/09/25/disable-allow-this-webpage-to-access-your-clipboard-pop-up-warning-message-in-ie7/">Disable Allow This Webpage to Access Your Clipboard Pop-Up Warning Message in IE7</a><br><br>Picture here of what the prompt would look like, &raquo;<A HREF="http://msdn.microsoft.com/en-us/library/bb250473(VS.85).aspx" >msdn.microsoft.com/en-us/library&middot;&middot;&middot;85).aspx</A><br><br>Appears you can disable this in IE6 too, &raquo;<A HREF="http://forums.spybot.info/archive/index.php/t-2665.html" >forums.spybot.info/archive/index&middot;&middot;&middot;665.html</A>.<br><br>That post includes a link to a site that retrieves your clipboard information, &raquo;<A HREF="http://www.sourcecodesworld.com/special/clipboard.asp" >www.sourcecodesworld.com/special&middot;&middot;&middot;oard.asp</A>.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20943860</guid>
<pubDate>Wed, 13 Aug 2008 10:45:53 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20943806</link>
<description><![CDATA[<A HREF="/useremail/u/1107429"><b>therube</b></A> :   <blockquote><small>quote:</small><hr>This should be blocked by setting Internet Options, Security, Internet Zone, Scripting, "Allow programmatic Clipboard access" to Disable.<br><br>I would be curious if this setting failed to block this vector.<br><br>&raquo;<A HREF="http://msmvps.com/blogs/spywaresucks/archive/2008/08/09/1644062.aspx" >msmvps.com/blogs/spywaresucks/ar&middot;&middot;&middot;062.aspx</A><br><hr></blockquote><br><br>So it appears this would be a vector in IE that is being exploited?  In my case (& I don't use IE) Clipboard access is set to "prompt".  (Wonder what a prompt looks like or how I would respond to it if I were prompted?)<br><br>And then this, <A HREF="http://sunbeltblog.blogspot.com/2007/11/rogue-ads-on-ad-networks.html">Rogue ads pushing malware -- how it works</a>, describes simply Refreshing the MLB web page & the popups start appearing?  Which kind of doesn't make sense?<br><br>So combine the two & perhaps Flash related?  JavaScript related?  JS being allowed to run in Flash?<br><br>And there must be some code somewhere on an infected web site that allows the clipboard overwrite to take place.  Again perhaps via Flash & JavaScript?<br><br>(How can anyone say that using a Mozilla browser & NoScript does not have the potential to help is browsing safely.)<br><br><b>EDIT:</b><br>So perhaps MLB was injected with code, using a META tag to force malware page to open.  Something like this:<br><textarea name="code" class="text" cols=50 rows=10>&lt;META NAME="Keywords" CONTENT="handycamz, videos, pictures, camz, adult, porn, bla, bla, bla"&gt;&lt;meta http-equiv="Refresh" content="0; url=http://winantivirus2008.org/freescan/?id=68"&gt;&#012;</textarea><!--end code block-->]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20943806</guid>
<pubDate>Wed, 13 Aug 2008 10:37:03 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20943440</link>
<description><![CDATA[<A HREF="/useremail/u/793106"><b>doppler</b></A> : <div class="bquote"><small>said by  avd706 <A HREF="/useremail/u/766601"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br><div class="bquote"><small>said by  doppler <A HREF="/useremail/u/793106"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br><div class="bquote"><small>said by  Doctor Four <A HREF="/useremail/u/197199"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>   :</small><br><br>Windows - by default, the home page for IE 7 is MSN.<br> </div>And this is the reason why I hate windows IE (pick any version)<br>The Default page should be about:blank.  If the homepage<br>is taken over in some way, everybody is in danger.  If I<br>wish to be dangerous.  I don't need microsofts help.<br> </div>I don't get it. Every browser has a home page. All you have to do is shut off your internet and you can change a bad home page without opening it. (You might have to clear your cache first though.)<br> </div>What you don't realize is every new computer rolling off<br>the countless assembly lines.  Has MSN website as the<br>default.  Only .01% of users of computers these days<br>know enough about using them.  Let alone using them<br>correctly.  If it wasn't for the other 99.99% I would<br>not be in the nice side business of fixing microsofts<br>dumb marketing decisions.<br><br>Yes, the homepage default of MSN.COM is a marketing driven<br>decision.  What better way to get eyes on your website<br>than to make the default page be yours.<br><br>Look at how many people ask for help.  In fixing there hijacked<br>browsers.  HIJACKTHIS, would not exsist if the browser<br>default was hard to change, from your preferred  setting.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20943440</guid>
<pubDate>Wed, 13 Aug 2008 09:22:31 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20943127</link>
<description><![CDATA[<A HREF="/useremail/u/766601"><b>avd706</b></A> : <div class="bquote"><small>said by  doppler <A HREF="/useremail/u/793106"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br><div class="bquote"><small>said by  Doctor Four <A HREF="/useremail/u/197199"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br>Windows - by default, the home page for IE 7 is MSN.<br> </div>And this is the reason why I hate windows IE (pick any version)<br>The Default page should be about:blank.  If the homepage<br>is taken over in some way, everybody is in danger.  If I<br>wish to be dangerous.  I don't need microsofts help.<br> </div>I don't get it. Every browser has a home page. All you have to do is shut off your internet and you can change a bad home page without opening it. (You might have to clear your cache first though.)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20943127</guid>
<pubDate>Wed, 13 Aug 2008 07:59:29 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20942992</link>
<description><![CDATA[<A HREF="/useremail/u/793106"><b>doppler</b></A> : <div class="bquote"><small>said by  Doctor Four <A HREF="/useremail/u/197199"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Windows - by default, the home page for IE 7 is MSN.<br> </div>And this is the reason why I hate windows IE (pick any version)<br>The Default page should be about:blank.  If the homepage<br>is taken over in some way, everybody is in danger.  If I<br>wish to be dangerous.  I don't need microsofts help.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20942992</guid>
<pubDate>Wed, 13 Aug 2008 06:57:51 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20940945</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : <div class="bquote"><small>said by  Doctor Four <A HREF="/useremail/u/197199"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Sandi Hardmeier, in her Spyware Sucks blog, is warning of a<br>new type of malvertisement that overwrites Windows' clipboard,</div><br>Has anyone seen the source code that shows how this is done?<br><br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20940945</guid>
<pubDate>Tue, 12 Aug 2008 19:06:30 EDT</pubDate>
</item>

<item>
<title>Virus Warning</title>
<link>http://www.dslreports.com/forum/remark,20939721</link>
<description><![CDATA[<A HREF="/useremail/u/766601"><b>avd706</b></A> : <div class="bquote"><small>said by  Doctor Four <A HREF="/useremail/u/197199"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>It appears to be hitting people who visit MSNBC.com:<br><br>&raquo;<A HREF="http://msmvps.com/blogs/spywaresucks/archive/2008/08/09/1644062.aspx" >msmvps.com/blogs/spywaresucks/ar&middot;&middot;&middot;062.aspx</A><br><br>The fraudware site is xp-vista-update.net, which is in the <br>MVPS hosts file (probably a recent addition as it is near<br>the bottom when I searched for it).<br> </div>I hope you copied that link by hand... you didn't use cut/paste did you??]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20939721</guid>
<pubDate>Tue, 12 Aug 2008 15:07:03 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20928440</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : This could be happening with one of Microsoft's ad providers,<br>which means MSN might also have the malvertisement. This<br>could explain one of the forum posts Sandi linked that said<br>this kept coming back even after a reformat and reinstall of<br>Windows - by default, the home page for IE 7 is MSN.<br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20928440</guid>
<pubDate>Sun, 10 Aug 2008 11:43:01 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20927823</link>
<description><![CDATA[<A HREF="/useremail/u/485678"><b>Kayrac</b></A> : PLEASE DO NOT CLICK THESE LINKS UNLESS YOU KNOW WHAT YOUR DOING<br>-----------------------------------------------------------<br><br>Okay so basically the website listed goes like so<br>(this is currently they could very easily change the redirects at any given time)<br><br><textarea name="code" class="text" cols=50 rows=10>http://xp-vista-update.net/?id=91873534231&#012;---&gt;http://webscweb-scannerfree.com/soft.php?aid=011807&amp;d=2&amp;product=XPA&#012;-------&gt;http://windows-defense.com/2009/1/freescan.php?aid=77011807&#012;</textarea><!--end code block--><br>this variant has almost 0 detection btw<br><br>&raquo;<A HREF="http://www.virustotal.com/analisis/48bb1c19196fc5712c5f187457e443d0" >www.virustotal.com/analisis/48bb&middot;&middot;&middot;57e443d0</A><br><br>-Brian]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20927823</guid>
<pubDate>Sun, 10 Aug 2008 06:57:31 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20927732</link>
<description><![CDATA[<A HREF="/useremail/u/122916"><b>amysheehan</b></A> : NOTE:  Link in post at MSNBC has recently been edited and made viewable in post -  I expect it to be removed soon.<br><br>-amy-<br>:)<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20927732?c=1336932&ret=L2ZvcnVtL3IyMDkyODQ0MC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="128750 bytes" WIDTH=600 HEIGHT=375 SRC="/r0/download/1336932.thumb600~7e134f85c6cd3e48bf2ef2d0a61ab85e/link now visible URL.jpg/thumb.jpg" ALT="Click for full size"></A><br>Post has been recently edited</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20927732</guid>
<pubDate>Sun, 10 Aug 2008 04:44:50 EDT</pubDate>
</item>

<item>
<title>Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20927658</link>
<description><![CDATA[<A HREF="/useremail/u/122916"><b>amysheehan</b></A> : Here's a screenshot of what happens when you try the link posted in the MSNBC forum.<br><br>Note:  I notified MSNBC webmaster div contact about this post and added the URL to Sandi's warning and to your topic here as well.<br><br>Thanks for posting this info, too !!!<br>-amy-<br>:)<br><small>--<br>Proud Member of <A HREF="http://asap.maddoktor2.com">ASAP</a><br><A HREF="http://www.dslreports.com/phishtrack">DSLR Phishtracker</a></small><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20927658?c=1336930&ret=L2ZvcnVtL3IyMDkyODQ0MC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="142754 bytes" WIDTH=600 HEIGHT=375 SRC="/r0/download/1336930.thumb600~4b660d6464abc3964a0168fa6ea6db4f/MSNBC ALERT.jpg/thumb.jpg" ALT="Click for full size"></A><br>Norton alert</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20927658</guid>
<pubDate>Sun, 10 Aug 2008 03:15:33 EDT</pubDate>
</item>

<item>
<title>Malvertisement on MSNBC.com using clipboard (copy/paste)</title>
<link>http://www.dslreports.com/forum/remark,20925461</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : Sandi Hardmeier, in her Spyware Sucks blog, is warning of a<br>new type of malvertisement that overwrites Windows' clipboard,<br>hoping that its URL will be pasted into blog entries, email and<br>so on. It appears to be hitting people who visit MSNBC.com:<br><br>&raquo;<A HREF="http://msmvps.com/blogs/spywaresucks/archive/2008/08/09/1644062.aspx" >msmvps.com/blogs/spywaresucks/ar&middot;&middot;&middot;062.aspx</A><br><br>The fraudware site is xp-vista-update.net, which is in the <br>MVPS hosts file (probably a recent addition as it is near<br>the bottom when I searched for it).<br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20925461</guid>
<pubDate>Sat, 09 Aug 2008 15:26:45 EDT</pubDate>
</item>

</channel>
</rss>
