From the monthly archives:

April 2007

Attorney General McKenna Settles with Movieland.com and Associates Concerning Pop-Up Payment Demands

Press release April 19, 2007

SEATTLE – Washington State Attorney General Rob McKenna today announced a settlement with three California-based businesses that resolves allegations they installed software that took control of a consumer’s computer by launching aggressive and persistent pop-ups that demanded payment for a movie download service. The software was installed after users signed up for a seemingly anonymous free trial for the service.

“Under this settlement, Movieland.com and its associated companies agree to cease offering anonymous free trials to Washington consumers for their movie download service,” said Attorney General Rob McKenna “Additionally, the defendants must receive express consent from Washington consumers before installing any billing software on the user’s computer, disclose whether the software will cause any pop-ups and clearly state all important contract terms in any advertisement.”

The state filed its original lawsuit last summer following an investigation by the Attorney General’s Consumer Protection High-Tech Unit. The suit accused the following of violating Washington’s Computer Spyware and Consumer Protection acts: Digital Enterprises of West Hills, doing business as Movieland.com; AccessMedia Networks of Los Angeles; Innovative Networks of Woodland Hills; and Alchemy Communications of Los Angeles.

Allegations against Alchemy were subsequently dismissed and the state reached a stipulated agreement with the remaining defendants that was filed today in King County Superior Court. Two company officials, Digital Enterprises’ Easton A. Herd, and Alchemy’s Andrew M. Garroni, are also parties to the settlement, which does not include a finding or admission of wrongdoing.

The defendants agreed to pay a total of $50,000 to resolve the allegations. They also agreed to provisions that limit their business practices.

According to the state’s complaint, the defendants promoted a movie download service through Web sites including movieland.com, moviepass.tv and popcorn.net that offered consumers a free three-day trial. Billing software was then downloaded onto the personal computers of consumers who accepted the offer.

After the trial period, defendants remotely activated the billing software, causing a popup window to appear that indicated the trial period had expired. Consumers who clicked on a “Continue” link on the pop-up were then shown a 40-second video that recurred hourly and told them that they were legally obligated to purchase a subscription. A statement on the company’s Web site also indicated that failure to pay “may result in an escalation of collection proceedings that could have an adverse effect on your credit status.”

“Despite the warning, defendants weren’t able to affect a consumer’s credit record because they did not have any way to personally identify a consumer,” said Senior Counsel Paula Selis, who helped lead the state’s investigation. “The software was difficult to remove and many frustrated consumers ultimately paid between $19.95 and $80 for the service in order to stop the pop-ups.”

Washington’s Computer Spyware Act prohibits, among other things, installing software on a computer without a user’s consent, taking control of a user’s computer, and interfering with the user’s ability to identify and remove that software.

Under the settlement terms, the defendants must not offer anonymous free trials in Washington for their movie download service. If they use a software-based collection method, they must:

  • Not attempt to collect payments from Washington residents unless they have a valid contract. In order for a valid contract to exist, consumers must click on a button indicating they understand and consent to the contract terms, provide a credit card number or other personal form of identification and state that they are 18 or older and authorized to download software on the computer.
  • Prominently disclose contract terms in any advertisement for goods or services. This would include the cost of any subscription service.
  • Not install any software program on the computer of a Washington resident without the express consent of the computer owner or an authorized user. Before seeking consent to install software, they must disclose whether downloading the software would cause any pop-up messages concerning payment obligations and the nature, frequently and duration of those messages. If consumers give consent, the defendants can’t send more than five pop-up messages in a day or more than one message per hour. Consumers must also be able to close the pop-up windows and silence any audio messages.

Washington’s settlement does not affect other legal actions concerning the defendants.

The Attorney General’s Office is offering a refund program for consumers who believe they have been subject to the defendants’ practices. Washington residents who believe they are eligible for a refund should file a complaint with the Attorney General’s Consumer Protection Division online at www.atg.wa.gov or call 1-800-551-4636 (number only available in-state) to request a complaint form.

Additional Materials:

Movieland Settlement (PDF)

Movieland Complaint (PDF)

Microsoft April 2007 Monthly Bulletin Release

by certifiedbug on April 11, 2007

in Microsoft, Security

Published Tuesday, April 10, 2007
Microsoft Security Response Center Blog

Today we released 5 bulletins: 4 have a maximum severity rating of Critical, and one has a maximum severity rating of Important. The bulletins are as follows:

Microsoft Content Management Server (MS07-018)

  • Maximum severity rating of Critical
    Could Allow Remote Code Execution

Universal Plug and Play (MS07-019)

  • Maximum severity rating of Critical
    Could Allow Remote Code Execution

Microsoft Agent (MS07-020)

  • Maximum severity rating of Critical
    Could Allow Remote Code Execution

CSRSS (MS07-021)

  • (Maximum severity rating of Critical
    Could Allow Remote Code Execution

Windows Kernel (MS07-022)

  • Maximum severity rating of Important
    Could Allow Remote Elevation of Privilege

As Christopher mentioned in his blog on Friday, in addition to today’s bulletins, we’ve also released a hotfix to help resolve the known issues related to MS07-017 with applications detailed in Microsoft Knowledge Base Article 925902. This update is available through Windows Update (WU), Microsoft Update (MU), and Automatic Updates (AU) as a High Priority non-security update and will be offered to customers who have installed MS07-017 and also have any of the applications listed in the article.

Microsoft TechNet
Updated: April 5, 2007

On 10 April 2007 Microsoft is planning to release:

Security Updates

  • Four Microsoft Security Bulletins affecting Microsoft Windows. The highest Maximum Severity rating for these is Critical. These updates will be detectable using the Microsoft Baseline Security Analyzer. These updates will require a restart.
  • One Microsoft Security Bulletin affecting Microsoft Content Management Server. The highest Maximum Severity rating for these is Critical. These updates will be detectable using the Microsoft Baseline Security Analyzer. These updates may require a restart.

Microsoft Windows Malicious Software Removal Tool

  • Microsoft will release an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services and the Download Center.

Note that this tool will NOT be distributed using Software Update Services (SUS).

Non-security High Priority updates on MU, WU, WSUS and SUS

  • Microsoft will release 2 NON-SECURITY High-Priority Updates for Windows on Windows Update (WU) and Software Update Services (SUS).
  • Microsoft will release 4 NON-SECURITY High-Priority Updates on Microsoft Update (MU) and Windows Server Update Services (WSUS).

Although we do not anticipate any changes, the number of bulletins, products affected, restart information and severities are subject to change until released.

Original Author: © 2007 Microsoft Corporation. All rights reserved.

Microsoft TechNet
Updated: April 1, 2007

On Tuesday 3 April 2007 Microsoft is planning to release:

Security Updates

  • One Microsoft Security Bulletin affecting Microsoft Windows. The highest Maximum Severity rating for these is Critical. These updates will require a restart. These updates will be detectable using the Microsoft Baseline Security Analyzer.

Microsoft Windows Malicious Software Removal Tool

  • Microsoft will not release an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services and the Download Center on Tuesday 3 April 2007.

Non-security High Priority updates on MU, WU, WSUS and SUS

  • Microsoft will not release any NON-SECURITY High-Priority Updates for Windows on Windows Update (WU) and Software Update Services (SUS) on Tuesday 3 April 2007.
  • Microsoft will not release any NON-SECURITY High-Priority Updates on Microsoft Update (MU) and Windows Server Update Services (WSUS) on Tuesday 3 April 2007.

Although we do not anticipate any changes, the number of bulletins, products affected, restart information and severities are subject to change until released.

We have some new information tonight on the status of the security update that we’re working on that addresses the vulnerability in Windows Animated Cursor Handling.

From our ongoing monitoring of the situation, we can say that over this weekend attacks against this vulnerability have increased somewhat. Additionally, we are aware of public disclosure of proof-of-concept code. In light of these points, and based on customer feedback, we have been working around the clock to test this update and are currently planning to release the security update that addresses this issue on Tuesday April 3, 2007.

I want to note that we are testing still and will be up until the release, to ensure the highest quality possible. So, it’s possible that we will find an issue that will force us to delay the release. If we do find an issue, though, we will let you know through the MSRC weblog as soon as we know.

Microsoft Security Response Center Blog!