Page 1 of 1

Java Flaw Enables Cross-Browser Attack

Posted: Tue Mar 15, 2005 9:03 pm
by Tami
What if there was an infection out there that could bypass Firefox and still get its grubby little paws on IE, and from there, the heart of your OS? What if that same infection could get past not only FF, but a whole raft of other (supposedly more secure) browsers too?

What if, of all people, Neil Diamond was indirectly involved in this craziness?

Unfortunately, this has now become a reality and woe betide anyone looking for lyrics from Neil's latest hit. You're more likely to end up with a nasty case of browseritis. After hearing rumours of a Firefox Adware bundle from this thread, I thought I'd go check it out. The results were, as they say, a right kick in the pants.

But how could this happen?

The answer is, some sneaky coding is being used to get around your browser of choice. Upon visiting the target website, nothing happens. Nothing that is, unless you have Sun Java Runtime Environment installed on the host machine. And seeing how everyone is being urged to turn away from Microsoft's Java in favour of Sun's version, this could spell problems for browsers currently lording it over IE.

Think you're safe because you're not actually using IE? Think you're safe because you have IE locked down tight with HOST files, Spywareblaster and the inbuilt security settings cranked up to the max? Wrong.

This is a shot of IE with the infection domain already added to the "Restricted Sites" zone in Internet Options. Note the "ironic" affiliate banner for Firefox.
attachment
So far, so good. Using IE, nothing is getting through. And using Firefox to browse will keep me totally secure, yes?...

...well, not exactly. Visit the same page in FF and, with the JRE up and running, the below happens:
attachment
Being a curious soul, I agreed to the install - and quickly wished I hadn't! In a flurry of remote downloads, numerous changes to the registry took place and a sizeable amount of IE specific installs began downloading. Amongst the assortment was DyFuCA, Internet Optimizer, ISTsvc, Kapabout, sais (180 Solutions), SideFind, Avenue Media and something called djtopr1150.exe lurking in the Temp folder.

Imagine my surprise when, unnanounced, IE then suddenly opens up without me doing anything and looks like this:
attachment
Congratulations! Your PC is boned!

It goes without saying that, apart from Webrebates opening up adverts in the bottom right hand corner, whole swathes of entries in my favourites advertising "Adware removers" that also sell popup blockers (with popups!), Powerscan which loads at startup, yelling "DON'T GET CAUGHT WITH PORN ON YOUR PC!", a Sidefind bar that doesn't actually do very much and an MTV toolbar to keep the kids quiet, there was my jaw being slowly scraped off the floor as I realised in that instant that for all Firefox's bravado, it had been cut down dead in an instant by what would normally be a bunch of rather average Adware installs.

The problem is, IE shouldn't have been hit in this way - especially as it was locked down so tightly, and wasn't even being used at the time. Vaguely worried by this, I tried some other browsers...the results aren't exactly fantastic reading for the Mozilla Foundation.

Firefox 1.0.1 - The install works.
Mozilla - The install works.
Avant browser 10.0 (build 153) - The install works.
Netscape 7.2 - The damn thing kept crashing, but eventually I was able to discover that the install works.
NetCaptor 7.5.4 - The install is blocked.
Opera 7.5.4 - The install is blocked.

Only two out of six had the good sense to steer clear of even asking the user if they wanted to install the applet. Not exactly a dazzling result.

(And it's since been confirmed by Daniel Veditz, owner of the Security Group over at the Mozilla Foundation, that this will indeed work in Opera with the right permissions enabled - though to date, I still haven't been able to get this to work. More here).

So how is this happening? The developers of this install are using the Java Runtime Environment, the initial installer taking the form of a Java applet rather than an Active X component inherent to IE alone. In this way, if the browser being used can recognise and install the applet, then it doesn't seem to matter what browser you're using, or (more worryingly) how tight your IE security is. And for those of you at the back, here's the .Jar file in all its cached glory (you'll have to put up with a clickable link for this one, it wouldn't fit on the page!) I should also point out that deleting the .Jar file from the Cache using the Java console will not remove the numerous IE Spyware and system infections now loaded onto your PC. This will only remove the initial installer.

Does this mean the Emperor's new clothes syndrome has hit Firefox? Possibly not, though it doesn't take a genius to work out that if "The Browser you Can Trust" now has to keep one eye on its older, slightly clumsier brother as well as watch its own back then there's a very good chance its tail could be getting ready for the mother of all burnings.

Update - to prevent any more people posting the same thing in the "comments" section, I'd like to point out that the main point of the above article is to highlight the fact that a new kind of exploit is infecting IE / the OS through Java when using an alternative browser such as FF / Netscape.

Yes, I am aware that "bad things will happen" when you click "yes" to something - that was kind of the whole point of the test, because most spyware installs occur when someone clicks "yes" to something they shouldn't have. The article is illustrating what happens when an end-user blindly agrees to something, however the point is IE being infected when not in use at the time, not the social engineering aspects of the install.

(I've had to switch off comments to conserve bandwidth - normal service resumed soon!)

source: VitalSecurity