Tuesday, June 29, 2004

New IE Malware Captures Passwords Ahead Of SSL

New IE Malware Captures Passwords Ahead Of SSL
Internet Explorer
Microsoft
Technology/IT
Businesses
The Internet
Posted by simoniker on Tuesday June 29, @03:53PM
from the tricky dept.
Ken Treis writes "SANS Internet Storm Center is reporting on a new strain of IE Malware. This one targets bank customers, which in itself is nothing new. But the catch is in the way it does it: it installs a Browser Help Object (BHO) that can capture login information before it is encrypted, and 'watches for HTTPS (secure) access to URLs of several dozen banking and financial sites in multiple countries.'."

[Slashdot]


6:34:53 PM    

Microsoft Targets Nonprofessional Programmers. A new, stripped-down versions of Visual Studio and SQL Server can be used to write simple Web applications. [InternetWeek]

"The products are aimed at "the next generation of IT professionals," said Eric Rudder, Microsoft senior VP of servers and tools, in a statement. The products will be available for download later this week on Microsoft's Web site. "

Apparently the next generation of IT professionals are expected to be dumber than the current crop and therefore less likely to question the MSFT lock-in that comes with these sorts of things.  IMHO, anyone who uses a 'stripped-down' version of anything isn't very professional and probably knows little about IT.


2:21:27 PM    

InformationWeek > Security > Microsoft Blames Hackers, Not Vulnerability, For Web Attack > June 28, 2004 "The Web attack that was stopped dead in its tracks on Friday when a Russian Web site was taken offline remained under investigation Monday by a host of security firms still puzzled over the method used to infect a number of Microsoft Internet Information Services servers. But the evidence now is leading them to accept Microsoft's explanation that the IIS 5.0 servers were hacked manually and that the server software doesn't have an unknown vulnerability. "
12:17:37 PM