The Channel logo


By | John Leyden 21st September 2006 11:44

Smut sites use IE exploit to spread spyware

Drive-by downloads

Hackers are taking advantage of a new, unpatched Internet Explorer vulnerability to infect users visiting pornographic websites.

There's a number of unpatched (or so called 0-day) flaws around at the moment, but this one takes advantage of a flaw within the Vector Markup Language (VML) component of IE.

VML is an XML file that allows vector drawings to be delivered to surfers. The security bug is unrelated to a (still unpatched) flaw in Microsoft's Direct Animation Path (daxctle.ocx) ActiveX control discovered last week.

Security researchers at Sunbelt Software report the latest exploit is being used to install spyware on vulnerable systems visiting hostile sites.

To avoid such drive-by downloads, users are advised to avoid visiting pr0n sites. In the circumstances, use of an alternative browser such as Firefox or Opera is also to be advised.

A full write-up of the problem can by found in an advisory be the SANs Institute's Internet Storm Centre here. ®

alert Send corrections


Frank Jennings

What do you do? Use manual typwriters or live in a Scottish croft? Our man advises
A rusty petrol pump at an abandoned gas station. Pic by Silvia B. Jakiello via shutterstock

Trevor Pott

Among other things, Active Directory needs an overhaul
Baby looks taken aback/shocked/affronted. Photo by Shutterstock

Kat Hall

Plans for 2 million FTTP connections in next four years 'not enough'
Microsoft CEO Satya Nadella


League of gentlemen poster - Tubbs and Edward at the local shop. Copyright BBC
One reselling man tells his tale of woe