On TechRepublic: 10 email scams to watch out for
BNET Business Network:
BNET
TechRepublic
ZDNet

August 18th, 2008

Adobe Flash ads launching clipboard hijack attack

Posted by Ryan Naraine @ 2:52 pm

Categories: Adobe, Anti Virus, Apple, Arbitrary Code Execution, Browsers, Exploit code, Firefox, Flash, Hackers, Metasploit, Mozilla, Patch Watch, Pen testing, Responsible disclosure, Viruses and Worms, Vulnerability research

Tags: Adobe Systems Inc., Advertisement, Attack, Security, Ryan Naraine

Clipboard hijackMalicious hackers are using booby-trapped Flash banner ads to hijack clipboards for use in rogue security software attacks.

In the Web attacks, which target Mac, Windows and Linux users running Firefox, IE and Safari, hackers are seizing control of the machine’s clipboard and using a hard-to-delete URL that points to a fake anti-virus program.

According to victims on several Web forums, the attack is coming from Adobe Flash-based advertising on legitimate sites — including Newsweek, Digg and MSNBC.com.

Here is a Mac OS X user explaining the attack:

This has happened to me twice now, on two separate computers at work. My clipboard has been hijacked with this:

[ malicious URL deleted ]

And once it’s in the clipboard, I can’t copy anything else over it until I’ve restarted the machine.

I’m only going to websites that are directly linked off the main page of digg.com, so they’re not obscure, and I’m surfing in firefox, though the system wide clipboard is getting taken over, so I can’t even copy something over that from a program like TextEdit.

The 5th post on this MSNBC.com forum shows what happens when a victim is tricked into pasting — and spamming — the malicious link to help spread the rogue security software.

Security researcher Aviv Raff has created a proof-of-concept demo to show how easy it is to use Flash with ActionScript code to load (persistently) a malicious URL into a target clipboard.   (BEWARE: If you click on the demo link, your clipboard is automatically hijacked and will only be released if the browser window is closed).

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 60 Talkback(s)
RE: Adobe Flash ads launching clipboard hijack attack
I think all of you babies need to stop crying, try Safari and then
welcome yourselves back to the world of being in control.

Then find something else to cry about. I long for the days when... (Read the rest)
Posted by: ArcticAardvark Posted on: 10/05/08 You are currently: a Guest | | Terms of Use
.....  Linux User 147560 | 08/18/08
Indeed  tracy anne | 08/19/08
woah  ZenMasta | 08/18/08
So much for "Linux == security"  LBiege | 08/18/08
re: So much for "Linux == security"  none none | 08/18/08
The same could be said of Vistas security  Intellihence | 08/19/08
Actually  tracy anne | 08/19/08
Linux is far, far more secure  drhowarddrfine | 08/20/08
Fedora Linux infrastructure pwned!  qmlscycrajg | 08/20/08
Nope. Red Hat Enterprise had some files compromised.  seanferd | 08/25/08
Is it really more secure...  fondy | 08/24/08
Oh it's more secure, but even a giant can be taken down...  JCitizen | 08/25/08
And don't run as Administrator on any OS. grin  seanferd | 08/25/08
For sure; For sure!!..(NT)  JCitizen | 08/27/08
Flash != Linux  davidr69 | 09/25/08
RE: Adobe Flash ads launching clipboard hijack attack  What_the | 08/18/08
NoScript: Thanks so much  oldbaritone | 08/19/08
yep  tracy anne | 08/19/08
it doesn't protect anything  qmlscycrajg | 08/20/08
It protects plenty  cipherepoch | 08/20/08
NoScript is great but...  npdavis@... | 08/21/08
RE: MSNBC.com forum  Romadon | 08/19/08
RE: Adobe Flash ads launching clipboard hijack attack  n0oeg | 08/19/08
RE: Adobe Flash ads launching clipboard hijack attack  marc57 | 08/19/08
This bug is harmless compared to the one...  JCitizen | 08/19/08
Dude!  seanferd | 08/22/08
I made a half hearted attempt...  JCitizen | 08/23/08
Sledgehammer. That'll do nicely. grin  seanferd | 08/23/08
I've never delt with those either...  JCitizen | 08/23/08
Sometimes  seanferd | 08/24/08
The TR post below, led to some of the best...  JCitizen | 08/24/08
Here's a TR post that will make your skin crawl!  JCitizen | 08/23/08
Aye. I did read it...and spoke too soon.  seanferd | 08/26/08
I swear! The bugs are getting bad lately...  JCitizen | 08/27/08
Yet another reason to run no-script in Firefox!  clareJ | 08/19/08
I feel sorry for the IE users  tracy anne | 08/19/08
I went there too, and the flash wouldn't load..  JCitizen | 08/23/08
firefox vulnerable  qmlscycrajg | 08/20/08
RE: Adobe Flash ads launching clipboard hijack attack  phil8656 | 08/19/08
RE: Adobe Flash ads launching clipboard hijack attack  phatkat | 08/19/08
I don't like ads  tracy anne | 08/19/08
It's almost funny  balaknair | 08/19/08
I had a buddy that caught a .bat file that...  JCitizen | 08/19/08
Oh well . . .  SFBayguy | 08/19/08
nothing wrong with firefox and yahoo  x-windows user | 08/19/08
really?  MoFoQ | 08/19/08
How to disable Flash with Internet Explorer  zdnet@... | 08/19/08
Greasemonkey with Block-Flash script ...  MisterMiester | 08/19/08
Why should Adobe flash be able to write to the clipboard?  Macropiper | 08/19/08
usefull feature with a flaw  RealityGone | 08/20/08
Exactly...  guya.net | 08/25/08
RE: Adobe Flash ads launching clipboard hijack attack  carl haag | 08/20/08
"I can't copy anything else over it until I've restarted the machine."  carl haag | 08/20/08
Flash is the problem, not the OS.  Benanov | 08/20/08
Is it able to read the clipboard? If no, this is not a flaw  qmlscycrajg | 08/20/08
RE: Adobe Flash ads launching clipboard hijack attack  daisy890 | 09/03/08
Easier than that  seanferd | 09/05/08
Middle-click in Linux not affected  davidr69 | 09/25/08
RE: Adobe Flash ads launching clipboard hijack attack  zdub | 09/26/08
RE: Adobe Flash ads launching clipboard hijack attack  ArcticAardvark | 10/05/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads