Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

Download.ject

From Wikipedia, the free encyclopedia
Malware program
"Scob" redirects here. For the skating club, seeSkating Club of Boston.
"Toofer" redirects here. For the 30 Rock character 'Toofer', seeJames "Toofer" Spurlock.

Incomputing,Download.ject (also known asToofer andScob) is amalware program forMicrosoft Windows servers. When installed on an insecure website running onMicrosoftInternet Information Services (IIS), it appends maliciousJavaScript to all pages served by the site.

Download.ject was the first noted case in which users ofInternet Explorer for Windows could infect their computers with malware (abackdoor andkey logger) merely byviewing a web page. It came to prominence during a widespread attack starting June 23, 2004, when it infected many servers including several that hosted financial sites. Security consultants prominently started promoting the use ofOpera[1] orMozilla Firefox instead of IE in the wake of this attack.

Download.ject is not avirus or aworm; it does not spread by itself. The June 23 attack is hypothesised to have been put into place by automatic scanning of servers running IIS.

Attack of June 23, 2004

[edit]

Hackers placed Download.ject on financial and corporate websites running IIS 5.0 onWindows 2000, breaking in using a known vulnerability. (Apatch existed for the vulnerability, but many administrators had not applied it.) The attack was first noticed June 23, although some researchers think it may have been in place as early as June 20.

Download.ject appended a fragment of JavaScript to all web pages from the compromised servers. When any page on such a server was viewed withInternet Explorer (IE) forWindows, the JavaScript would run, retrieve a copy of one of various backdoor and key logging programs from a server located in Russia and install it on the user's machine, using two holes in IE — one with a patch available, but the other without. These vulnerabilities were present in all versions of IE for Windows except the version included inWindows XP Service Pack 2,[2] which was only in beta testing at the time.

Both the server and browser flaws had been exploited before this.[citation needed] This attack was notable, however, for combining the two, for having been placed upon popular mainstream websites (although a list of affected sites was not released) and for the network of compromised sites used in the attack reportedly numbering in the thousands, far more than any previous such compromised network.

Microsoft advised users on how to remove an infection and to browse with security settings at maximum. Security experts also advised switching off JavaScript, using aweb browser other than Internet Explorer, using anoperating system other than Windows, or staying off the Internet altogether.

This particular attack was neutralised on June 25 when the server from which Download.ject installed a backdoor was shut down. Microsoft issued a patch for Windows 2000, 2003 and XP on July 2.

Although not a sizable attack compared to email worms of the time, the fact that almost all existing installations of IE — 95% of web browsers in use at the time — were vulnerable, and that this was the latest in a series of IE holes leaving the underlying operating system vulnerable, caused a notable wave of concern in the press. Even some business press started advising users to switch to other browsers, despite the then-prerelease Windows XP SP2 being invulnerable to the attack.

See also

[edit]

References

[edit]
  1. ^Brenner, Bill (October 4, 2004)."Schneier: Microsoft still has work to do".Schneier on Security.Archived from the original on 2004-10-10. Retrieved2007-01-08.
  2. ^"Changes to Functionality in Microsoft Windows XP Service Pack 2: Enhanced Browsing Security".Microsoft. March 22, 2004. Archived fromthe original on 2004-04-30.

External links

[edit]

Technical information

[edit]

Press coverage

[edit]
Versions
Main
Other
Overview
Technologies
Software and engines
Implementations
Events
People
Retrieved from "https://en.wikipedia.org/w/index.php?title=Download.ject&oldid=1244687547"
Categories:
Hidden categories:

[8]ページ先頭

©2009-2025 Movatter.jp