Please support our Tech Talk advertiser:
Apr 13th, 2007, 7:49 am
IT security and control firm Sophos is urging computer users once again to patch against a critical bug in how Microsoft Windows handles animated cursors (ANI files) as hackers exploit the problem by sending out emails related to professional party girl Paris Hilton and hardcore actress Jenna Jameson.
This latest attack is believed to be by the same group of hackers that last week spammed out scantily clad pictures of Britney Spears to exploit the Microsoft vulnerability. It follows news that Paris Hilton and Jenna Jameson were seen celebrating the latter's birthday party together at a trendy LA club last weekend.
The spammed email messages have subject lines such as "Hot pictures of paris hilton nude" and contain an embedded image not of the celebrity hotel heiress but of pornographic actress Jenna Jameson. When clicked on, the image links to a website containing the malicious Iffy-B Trojan horse. The Trojan horse in turn points to another piece of malware which tries to exploit the Microsoft vulnerability.
"The problem is that consumers and businesses may not yet have patched themselves against this vulnerability, and clicking on unsolicited emails like these could lead them to a nasty malware infection," Graham Cluley, senior technology consultant for Sophos told DaniWeb, continuing “Microsoft issued a patch for the problem last week, but determined hackers are still trying to lure computer users with promises of nude pictures and look set on taking advantage of the security flaw for some time to come."
This is not the first time that Paris Hilton has been used as bait in an attempt to trick innocent computer users into viral infection. Two mass-mailing worms that masqueraded as X-rated videos of Hilton were released in February 2005. The promise of glimpses of other pin-ups like Britney Spears, Halle Berry, Avril Lavigne, Anna Kournikova, Julia Roberts, Angelina Jolie and Brad Pitt, Jennifer Lopez and the stars of 'Sex and the City' have previously been used to help viruses spread.
This latest attack is believed to be by the same group of hackers that last week spammed out scantily clad pictures of Britney Spears to exploit the Microsoft vulnerability. It follows news that Paris Hilton and Jenna Jameson were seen celebrating the latter's birthday party together at a trendy LA club last weekend.
The spammed email messages have subject lines such as "Hot pictures of paris hilton nude" and contain an embedded image not of the celebrity hotel heiress but of pornographic actress Jenna Jameson. When clicked on, the image links to a website containing the malicious Iffy-B Trojan horse. The Trojan horse in turn points to another piece of malware which tries to exploit the Microsoft vulnerability.
"The problem is that consumers and businesses may not yet have patched themselves against this vulnerability, and clicking on unsolicited emails like these could lead them to a nasty malware infection," Graham Cluley, senior technology consultant for Sophos told DaniWeb, continuing “Microsoft issued a patch for the problem last week, but determined hackers are still trying to lure computer users with promises of nude pictures and look set on taking advantage of the security flaw for some time to come."
This is not the first time that Paris Hilton has been used as bait in an attempt to trick innocent computer users into viral infection. Two mass-mailing worms that masqueraded as X-rated videos of Hilton were released in February 2005. The promise of glimpses of other pin-ups like Britney Spears, Halle Berry, Avril Lavigne, Anna Kournikova, Julia Roberts, Angelina Jolie and Brad Pitt, Jennifer Lopez and the stars of 'Sex and the City' have previously been used to help viruses spread.
This blog entry was written by Bill Andad, staff writer aka newsguy. It has received 9,647 views, 2 comments, and 132 linkbacks. 2 voters have rated this entry an average of 5 out of 5 stars. It was promoted to featured status Apr 13th, 2007.
•
•
•
•
advertising apple botnet browser business crime daniweb data development email environment europe facebook firefox forensic gaming google hacking hardware help ibm internet iphone ipod it law legal linux malware microsoft mobile mozilla news phishing privacy research search security social networking software spam survey technology trojan virus vista web windows yahoo youtube
All Recent Tags Comments (Newest First)
happygeek | He's The Daddy | Apr 14th, 2007
•
•
•
•
I was thinking that it meant most people would not be at risk from the exploit. I cannot say that I would want Paris Hilton, naked or otherwise, anywhere near my computer
jwenting | duckman | Apr 14th, 2007
•
•
•
•
did you have to ruin my sleep with nightmares about a naked Paris Hilton doing something with my PC?
Post Comment
•
•
•
•
Only community members can start a blog or comment on blog entries. You must register or log in to contribute.
•
•
•
•
•
•
•
•
DaniWeb Tech Talk Marketplace
Related Blog Entries
- How to put in a new motherboard without losing your Operating System (3 Days Ago)
- Implementing a *Real* Internet Highway (6 Days Ago)
- Even prayer cannot help Jesus Phone owners today (8 Days Ago)
- Why bother with an Apple iPhone 3G? (9 Days Ago)
- Steve Ballmer Needs to Grow A Spine (12 Days Ago)
- UK runs out of iPhone 3G handsets four days before launch (12 Days Ago)
- Viacom defends itself over YouTube data log disclosure (14 Days Ago)
- Apple slow to patch iPhone security holes (14 Days Ago)
- Microsoft 'Equipt' to Battle Free Software (14 Days Ago)
- Need an online dictionary? Just ask Ask. (15 Days Ago)
Related Forum Threads
- Paris Hilton behind bars...er, jail bars (Geeks' Lounge)
Featured Entry