On GameSpot: So-called 'Halo killer' gets 23 to life
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: May 10, 2007 10:57:00 PM

Cybercrooks are trying to breach PCs through previously unexploited security holes in QuickTime and WinZip, security firm Symantec warned on Thursday.

The attacks involve malicious Web sites rigged with multiple exploits, Symantec said in a security alert. The sites appear to be that of a trusted financial institution, but instead attempt to silently install keystroke-logging software, according to Symantec. Links to the sites are likely advertised in spam, it said.

Symantec discovered the attacks when one of the PCs that it uses as bait was breached earlier this week.

"This compromise was especially interesting, because the site made use of a QuickTime vulnerability discovered in January 2007 and a WinZip vulnerability discovered in November 2006," Symantec said. "Before our analysis, it was not known that these issues were being exploited in the wild."

QuickTime is Apple's widely used media player software, WinZip is a popular tool for compressing and decompressing files.

In addition to the QuickTime and WinZip flaws, the miscreants tried to breach the Symantec system via a pair of holes in Microsoft software, Symantec said. Fixes for all the vulnerabilities are available. Symantec's compromised machine was not patched, running Windows XP with Service Pack 1.

Online criminals typically use a variety of vulnerabilities in an attempt to break into a computer. There are even toolkits available to help attackers create malicious Web sites with a few mouse clicks.

"This discovery highlights both the importance of having a prompt patching schedule and the fact that attackers are keeping up with the times and constantly updating their attack strategies to help ensure ongoing success," Symantec said.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 10 Talkback(s)
Is the Mac a PC?
The Answer is yes and no. The Mac is a personal computer in the original meaning. When PC Magazine came out, the meaning of PC changed to mean IBM PC and it's clones and compatibles. Most people mean ... (Read the rest)
Posted by: rogerburd00@... Posted on: 05/18/07 You are currently: a Guest | | Terms of Use
Vista users are safe, OSX users are not  NonZealot | 05/10/07
Come on now, OSX is way more secure than Vista  Boot_Agnostic | 05/11/07
You're both deluding yourselves...  Azrael808 | 05/11/07
I said more secure  Boot_Agnostic | 05/12/07
Would you like some caffeine to enhance your hysteria?  Zeppo9191 | 05/11/07
Macs are not PCs?  rapson | 05/11/07
The Apple Mac commercials seem to make a case  Boot_Agnostic | 05/12/07
Is the Mac a PC?  rogerburd00@... | 05/18/07
LOL  Badgered | 05/11/07
You didn't read the article close enough  NonZealot | 05/11/07

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

advertisement
Click Here