Download the Tom's Hardware App from the App Store
The reference for current tech news
Yes No
Ads

McAfee Blames IE Hole for Google-China Hack

by - source: Tom's Hardware US

McAfee said that the Google hackers used an unknown exploit in Internet Explorer.

Thursday McAfee said that Operation Aurora, the attack that hit Google and multiple companies early in the week, was the result of a new, "not publicly known" vulnerability found in Microsoft's web browser, Internet Explorer. McAfee said that it has informed Microsoft with its findings, and that Microsoft is expected to publish an advisory on the matter soon.

"As with most targeted attacks, the intruders gained access to an organization by sending a tailored attack to one or a few targeted individuals," said McAfee's George Kurtz in this official blog. "We suspect these individuals were targeted because they likely had access to valuable intellectual property. These attacks will look like they come from a trusted source, leading the target to fall for the trap and clicking a link or file. That’s when the exploitation takes place, using the vulnerability in Microsoft’s Internet Explorer."

Kurtz said that the malware opens a back door once it's downloaded and installed, allowing the attacker to "perform reconnaissance" and gain complete control of the compromised system. Once that takes place, the attacker can identify "high value targets" and siphon off valuable data from the targeted company.

Kurtz also said that although McAfee identified the Internet Explorer vulnerability as one of the attack vectors, he said that there could be additional vectors not yet discovered. According to their findings, Adobe Reader is not one of these vectors despite other reports blaming Adobe as a culprit. More information on the Internet Explorer vulnerability and Operation Aurora can be found on the McAfee blog.

Share:
22
Comments
X
Submit

Comments
Add your comment
WinningDreams 01/15/2010 12:47 PM
Hide
--2+

good thing I use Chrome!

alextheblue 01/15/2010 12:55 PM
Hide
-14+

"Kurtz also said that although McAfee identified the Internet Explorer vulnerability as one of the attack vectors, he said that there could be additional vectors not yet discovered."

Translation: McAfee (maker of the most bestest security software EVAR that wouldn't have even prevented this): "We're blaming IE 100% even though we don't really know exactly what happened."

Not much anyone could have done though in any case, if they were using a previously unknown exploit.

jhansonxi 01/15/2010 12:58 PM
Show
tenor77 01/15/2010 1:09 AM
Hide
-8+

Quote :These attacks will look like they come from a trusted source, leading the target to fall for the trap and clicking a link or file. That’s when the exploitation takes place


Wow so the user opened up the file, anti-virus didn't pick up the mal-ware..........and it's IE's fault?

twu 01/15/2010 1:21 AM
Hide
-6+

Cheap advertisement.

sceen311 01/15/2010 1:33 AM
Show
back_by_demand 01/15/2010 1:43 AM
Hide
-7+

The user was coaxed into clicking a link or executing a file.
Since when is stupidity an IE exploit?
Cos no Linux user has ever clicked an unknown executable they shouldn't...ever...not in a million years

gammaraptor 01/15/2010 1:45 AM
Hide
-0+

firefox ftw!

doc70 01/15/2010 2:23 AM
Hide
-12+

The best computer/OS is only as smart as it's user...

Anonymous 01/15/2010 2:45 AM
Hide
-2+

back_by_demand:
"Since when is stupidity an IE exploit?
Cos no Linux user has ever clicked an unknown executable they shouldn't...ever...not in a million years"

These were high value target with access to confidential IP, ive got a feeling they are not going to be just clicking on any old link/file, on the other hand should the e-mail genuinely appear to be and signed as from HR chances are your going click that link especially if it says your not going get paid, don't fool yourself this was a concerted and sophisticated attack probably using advance reconnaissance to identify high value targets as well as procuring samples of official communication to counterfeit, which the exploited used to make appear to come from Google internally

even linux users need to get paid too....

fflam 01/15/2010 2:50 AM
Hide
-0+

well considering we know nothing of the exploit other then it is based in IE, doesn't mean the user was using another browser clicked the link and the program used IE to preform the deeds (yes unlikely i know but possible). until we know what happened there is not reason to spout out with stupid unproductive comments.

and for the record no i don't use IE.

False_Dmitry_II 01/15/2010 3:10 AM
Hide
--1+

Meh, I either use opera or firefox

ch42832n 01/15/2010 4:10 AM
Hide
--2+

Lucky I use firefox

anamaniac 01/15/2010 8:13 AM
Hide
-2+

Buck off McAfee, get a antivirus that works, then I just might, just maybe, actually take you seriously for once...

eddieroolz 01/15/2010 8:43 AM
Hide
--1+

Oh awesome, let's blame IE.

rantoc 01/15/2010 11:12 AM
Hide
-0+

Mc Affe enterprice = 139 MB memory wasted from only the antivirus task alone... then add all the autoupdate crap ect. And most workstations at companies have weak memory.... do the math!

Hatecrime69 01/15/2010 3:01 PM
Hide
-1+


rantoc :
Mc Affe enterprice = 139 MB memory wasted from only the antivirus task alone... then add all the autoupdate crap ect. And most workstations at companies have weak memory.... do the math!



but that's the genius behind their security, a system can't be compromised if it's bogged down too much by the software made to prevent it from being compromised!

Thouh not to defend them, antivirus and firewalls can only do so much to protect a computer if it's full of programs that are full of securiy holes

jblack 01/15/2010 4:48 PM
Hide
-1+

WinningDreams :
good thing I use Chrome!




I think the question should be.... Why weren't they?

pcavv 01/15/2010 5:55 PM
Hide
--3+

Wait does this means that people at google use IE?! isnt Chrome the best thing out there?! strange

hluna52180 01/15/2010 6:03 PM
Hide
-1+

Firefox has been my default browser now for over a year now. Only time I now use IE is when I do a manual Microsoft Update every so often. Mozilla 3.6 is brutally fast compared to IE8 on my midrange laptop. These targeted attacks on IE8 is just another reason I have abandoned Microsoft's browser.

winner4455 01/15/2010 8:15 PM
Hide
-1+

tenor77 :
Wow so the user opened up the file, anti-virus didn't pick up the mal-ware..........and it's IE's fault?



I bet their anti-virus is McAfee.

wayneepalmer 01/15/2010 10:27 PM
Hide
-1+

Sometimes you have no choice on OS's, browsers, or AV-ware.

Some employers have their PC's locked and don't allow their staffs to download anything so if you get on at work it's all you have.

Some companies ESPECIALLY CERTAIN BANKS AND CREDIT UNIONS don't play nice with Chrome or Firefox when you are banking online.

Certain programs that run thru browsers have issues with different browsers or won't work with Linux (it's been a while since I last checked, but as far as I know QUICKEN won't run on Linux).

Sometimes you just have to live with IE, Windows, and McAfee if you want a paycheck, or to get things done.

Ads

Best offers

Newsletters


OK
Ads