Do you use IE and Google Search?
@owlwings (43897)
Cambridge, England
June 5, 2009 6:20pm CST
I received this notification from ZoneAlarm today:
"[i]Gumblar is named after the Gumblar.cn exploit, which so far targets users of Internet Explorer and Google search, delivering malware through compromised sites that infects a user's PC and subsequently intercepts traffic between the user and the visited sites. This means that once infected, anything the victim types could be monitored and used to commit identity theft, such as stealing credit card numbers, Web passwords or other sensitive data. Visitors encountering the compromised website also risk having their subsequent search results replaced with links that point to other malicious websites. The malware can also steal FTP credentials from the victim's computer and use them to infect more sites, thus increasing the spread of this threat. So far, more than 3,000 websites have been attacked including Tennis.com, Variety.com and Coldwellbanker.com.
[/i]
Who is at risk?
Users of Internet Explorer and Google's search engine."
If you are running the ZoneAlarm free firewall (or, worse still, no firewall at all), you could be at risk, since it does not include virtualization technology which protects from these types of stealth Web browser attacks.
The recommendation is to use Firefox and Yahoo or another search engine for the time being and to make sure that your Antivirus program is fully up to date.
More information on Gumblar here: http://news.softpedia.com/news/Gumblar-Exploit-is-the-Most-Prevalent-Web-Threat-111701.shtml
Information on how to check whether you are already infected here: http://www.zonealarm.com/security/en-us/support/gumblar.htm under the heading "How do I know if I've been infected?"
4 people like this
3 responses
@owlwings (43897)
• Cambridge, England
13 Jun 09
I agree that the checking procedure is somewhat obtuse but provided you have been accepting Windows updates and installing them and have kept your antivirus product and Java up to date, you should be OK. I don't know what the state of play is at the moment but there have been several Windows updates recently and also a new Java version. I suspect that they both incorporate changes to make browsing a little safer.
I hardly ever use Internet Explorer and also use another search engine (that pays me to search), so I haven't come across any infected sites I believe ... or, rather, if I have, they haven't been able to do anything.
1 person likes this




