First reported by Florida-based Sunbelt Software Tuesday, the bug has already been used to compromise PCs and load them with scores of adware and spyware programs, as well as other malicious code. Users surfing with IE 6 and earlier can be infected simply by viewing the wrong site.
"We've seen a new version of WebAttacker on some sites, along with older versions," said Hubbard, "so we know that they've updated their kit."
WebAttacker is a modular hacker toolkit that uses a simple Web interface to let attackers choose from numerous exploits -- the VML exploit only the most recent -- to "serve" any visitor of a malicious site. The kit even identifies the operating system, say Windows XP SP2; browser used; and presence of anti-virus software, then chooses the best exploit to run, Symantec said in an entry on its security team's blog Wednesday.
WebAttacker, added Symantec's Amado Hidalgo, even generates statistics on successful exploits by host, OS, and browser; it also calculates an "exploit efficiency" ratio, said Hidalgo.
"One thing we haven't found yet," said Websense's Hubbard, " is a stat page that will tell us how many systems have been compromised."
In April, Websense discovered a WebAttacker stats page that showed just one malicious site had compromised more than 3,000 computers using just two of the kit's seven exploits.
"There are close to 10,000 sites either hosting WebAttacker or pointing to sites that do," Hubbard estimated. Although only about 20 sites are currently serving up the exploit, if more WebAttacker users decide to download the newest version, Hubbard expects that the numbers of malicious sites will quickly climb.
Page 2:
![]()
1
|
2
Next Page »
Stay connected and informed by visiting our Enterprise IT Community!

Become a member today for instant access to free InformationWeek research, expert advice, peer perspectives, and more on the following topics:
- Application Performance Management (APM)
- Security Management
- Mainframe 2.0
- IT Automation
- Service Assurance
Also, visit our Government, Retail and Financial Services groups to see how these technologies apply specifically to those industries.
NOTE: Offer valid for U.S., U.S. possessions, & Canada only.