Fix Old Flaws to Stop New Attacks

By Erik Larkin, PC World |  Security Add a new comment

In further confirmation that Internet crooks tend to grab for the low-hanging fruit, a new Microsoft report reveals that the most common browser-based attacks tend to go after old software flaws. Making sure you've closed those holes can go a long way towards keeping your PC safe.

Browser-based exploits form the basis for some of the sneakiest and most dangerous attacks out there today. Crooks insert hidden attack code on a hijacked Web site that searches for a software vulnerability whenever anyone views the poisoned site. If the attack code finds a flaw, it will attempt to surreptitiously download and install a Trojan or other malicious software. If an antivirus app doesn't manage to catch it, the malware gets installed with nary a clue for the hapless victim.

These drive-by-download attacks sometimes go after the latest software flaws, but as revealed by Microsoft's new Security Intelligence Report v7, most of the attacks against Windows XP go after old Windows and third-party software flaws going as far back as 2006. Of the top 10 attacks, only one was from 2009. That's good news, since it means that basic maintenance and security measures will go a long way towards keeping your PC safe.

These are the most common browser-based exploits, as determined from Microsoft's analysis of "data from customer-reported incidents, submissions of malicious code, and Microsoft Windows error reports."

Third-party software:

CVE-2008-2992 - flaw in Adobe Acrobat and ReaderCVE-2006-5198- WinZipCVE-2007-0015- QuickTimeCVE-2007-5659- Adobe Reader

Windows holes:

MS08-041- Microsoft Office Snapshot ViewerMS09-002- Internet ExplorerMS06-057- Internet ExplorerMS08-078- Internet ExplorerMS06-01- Microsoft Data Access ComponentsMS06-055- Microsoft VMLThe names here tell when the flaw was discovered (MS06 = 2006, for example), and as you can see, crooks love the golden oldies. Many of these attacks probably go after pirated Windows installs that never get updates.

Enabling Automatic updates in Windows will guard from attacks against any of the listed Windows flaws, and to protect against the third-party software flaws, make sure you have the latest software versions available. For vulnerable older software such as the vulnerable, three-year-old WinZip, that might require a manual version check and update. Or you can take the easy route and use the free Secunia PSI software, which will scan your system for outdated vulnerable software and provide simple links to update it.

For Vista attacks, only one of the most common exploits listed went after a Windows flaw (Internet Explorer). The rest targeted third-party software such as Adobe Reader or RealPlayer, with old flaws again providing a common target. As with XP, running Automatic updates and Secunia PSI should safeguard any PC from the most common exploits.

Another good protection step is to apply the patch to turn off AutoRun for USB drives. As noted by the Washington Post, Microsoft's report also shows that some of the most common malware will infect thumb drives and wait to be connected to another PC. When that happens, the malware takes advantage of AutoRun to run automatically and attempt to infect the new PC.

A Microsoft patch - which doesn't distribute via Automatic Updates, per the Washington Post - will turn off AutoRun for USB drives and guard against this infection vector. You'll need to download and install this patch yourself.

And finally, for other simple security steps that can go a long way towards keeping you safe, see The Five Most Dangerous Security Myths.

    Add a comment

    Post a comment using one of these accounts
    Or join now
    At least 6 characters

    Note: Comment will appear soon after you have activated your account.
    Obscene/spam comments will be removed and accounts suspended.
    The information you submit is subject to our Privacy Policy and Terms of Service.

    ITworld LIVE

    SecurityWhite Papers & Webcasts

    White Paper

    Overcome Top 7 Admin Challenges of Active Directory

    As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

    White Paper

    Insiders Can Ruin Your Company. Take Action.

    Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

    White Paper

    Top Solutions and Tools to Prevent Devastating Malware

    Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

    White Paper

    Streamline Compliance and Increase ROI

    Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

    White Paper

    X-Ray of the PCI Process-4 Proactive Steps

    This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

    See more White Papers | Webcasts

    Ask a question

    Ask a Question