SecurityFocus Microsoft Newsletter #355
[email protected] 17 Aug 2007 05:54:54 -0000
| Newsgroups | gmane.comp.security.news.microsoft |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Microsoft Newsletter #355
----------------------------------------
This Issue is Sponsored by: SPI Dynamics
ALERT: Web Hacking - Attack Scenarios and Examples- White Paper
Learn how to defend against Web Application Attacks with real-world examp=
les of recent hacking methods such as SQL Injection, Cross Site Scripting=
and Parameter Manipulation. Learn step-by-step vulnerability testing met=
hods for your own Web Applications and guidelines for establishing best a=
dministration and coding practices.
Download *FREE* white paper from SPI Dynamics for a complete guide to pro=
tection!
https://download.spidynamics.com/1/ad/web.asp?Campaign_ID=3D70160000000D0=
r2
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1. Delete This!
2. Security conferences versus practical knowledge
II. MICROSOFT VULNERABILITY SUMMARY
1. EDraw Office Viewer Component ActiveX Control Arbitrary File Ov=
erwrite Vulnerability
2. IBM DB2 Universal Database Multiple Unspecified Vulnerabilities
3. Symantec Enterprise Firewall Username Enumeration Weakness
4. Cisco VPN Client for Windows Multiple Local Privilege Escalatio=
n Vulnerabilities
5. RndLabs Babo Violent 2 Multiple Vulnerabilities
6. EFS Software Easy Chat Server Authentication Request Handling R=
emote Denial Of Service Vulnerability
7. Live For Speed Multiple Vulnerabilities
8. Zoidcom Malformed Packet Denial of Service Vulnerability
9. Drupal Content Construction Kit Nodereference Module Multiple H=
TML-injection Vulnerabilities
10. Diskeeper DKService.EXE Remote Information Disclosure Vulnerab=
ility
11. Microsoft Internet Explorer Vector Markup Language VGX.DLL Rem=
ote Buffer Overflow Vulnerability
12. Microsoft Windows Media Player Remote Skin Decompression Code =
Execution Vulnerability
13. Windows Vista Weather Gadget Remote Code Execution Vulnerabili=
ty
14. Microsoft Windows Media Player Remote Skin Header Code Executi=
on Vulnerability
15. Windows Vista Contacts Gadget Remote Code Execution Vulnerabil=
ity
16. Qbik WinGate SMTP Service Command Format String Vulnerability
17. Microsoft Windows GDI Metafiles AttemptWrite Remote Code Execu=
tion Vulnerability
18. Microsoft XML Core Services SubstringData Integer Overflow Vul=
nerability
19. WengoPhone SIP Soft Phone Malformed Packet Denial of Service V=
ulnerability
20. CounterPath X-Lite SIP Soft Phone Malformed Packet Denial of S=
ervice Vulnerability
21. Microsoft Virtual PC and Virtual Server Heap Overflow Vulnerab=
ility
22. MS Visual Basic 6 Package and Deployment Wizard ActiveX Contro=
l Remote Code Execution Vulnerability
23. Microsoft Internet Explorer CSS Strings Memory Corruption Vuln=
erability
24. Windows Vista Feed Headlines Gadget Remote Code Execution Vuln=
erability
25. Microsoft OLE Automation SubstringData Function Integer Overfl=
ow Vulnerability
26. Microsoft Excel Worksheet Index Value Remote Code Execution Vu=
lnerability
27. Microsoft DirectX Media SDK DXTLIPI.DLL ActiveX Control Buffer=
Overflow Vulnerability
28. WinGate SMTP Session Invalid State Remote Denial Of Service Vu=
lnerability
29. Microsoft August 2007 Advance Notification Multiple Vulnerabil=
ities
30. Microsoft Windows Media Player AU Divide-By-Zero Denial of Ser=
vice Vulnerability
31. Symantec Altiris Deployment Solution Local Privilege Escalatio=
n Vulnerability
32. Microsoft Internet Explorer Position:Relative Denial of Servic=
e Vulnerability
III. MICROSOFT FOCUS LIST SUMMARY
1. Password complexity - improvement
2. SecurityFocus Microsoft Newsletter #354
3. SecurityFocus Microsoft Newsletter #352
IV. UNSUBSCRIBE INSTRUCTIONS
V. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Delete This!
By Mark Rasch
A series of legal events means that companies that have no business reaso=
n to retain documents or records may be compelled to create and retain su=
ch records just so they can become available for discovery.
http://www.securityfocus.com/columnists/450
2. Security conferences versus practical knowledge
By Don Parker
While the training industry as a whole has evolved rather well to suit th=
e needs of their clients, the computer conference - specifically the comp=
uter security conference - has declined in relevance to the everyday sys-=
admin and network security practitioners.
http://www.securityfocus.com/columnists/449
II. MICROSOFT VULNERABILITY SUMMARY
------------------------------------
1. EDraw Office Viewer Component ActiveX Control Arbitrary File Overwrite=
Vulnerability
BugTraq ID: 25344
Remote: Yes
Date Published: 2007-08-16
Relevant URL: http://www.securityfocus.com/bid/25344
Summary:
The EDraw Office Viewer Component ActiveX Control is prone to an arbitrar=
y file-overwrite vulnerability.=20
An attacker can exploit this issue to overwrite files with arbitrary, att=
acker-controlled content. This will aid in further attacks.
Version 5.1 of the control is vulnerable to this issue; other versions ma=
y also be affected.
2. IBM DB2 Universal Database Multiple Unspecified Vulnerabilities
BugTraq ID: 25339
Remote: Yes
Date Published: 2007-08-16
Relevant URL: http://www.securityfocus.com/bid/25339
Summary:
IBM DB2 is prone to multiple vulnerabilities that may allow an attacker t=
o carry out a variety of attacks. It is possible that some of these issu=
es may permit an attacker to completely compromise a vulnerable computer.
These issues affect DB2 9.1 and 8 running on all supported platforms.
3. Symantec Enterprise Firewall Username Enumeration Weakness
BugTraq ID: 25338
Remote: Yes
Date Published: 2007-08-16
Relevant URL: http://www.securityfocus.com/bid/25338
Summary:
Symantec Enterprise Firewall is prone to a username-enumeration weakness.
An attacker can exploit this issue to enumerate valid user names. This ma=
y aid in further attacks.
4. Cisco VPN Client for Windows Multiple Local Privilege Escalation Vulne=
rabilities
BugTraq ID: 25332
Remote: No
Date Published: 2007-08-15
Relevant URL: http://www.securityfocus.com/bid/25332
Summary:
Cisco VPN Client for Windows is prone to multiple local privilege-escalat=
ion vulnerabilities.
Successfully exploiting these issues allows attackers with local, interac=
tive access to affected computers to gain SYSTEM-level privileges. This f=
acilitates the complete compromise of affected computers.
Versions prior to 4.8.02.0010 and 5.0.01.0600 of Cisco VPN Client for the=
Microsoft Windows platform are vulnerable to these issues.
These issues are tracked as Cisco Bug IDs CSCse89550 and CSCsj00785.
5. RndLabs Babo Violent 2 Multiple Vulnerabilities
BugTraq ID: 25329
Remote: Yes
Date Published: 2007-08-14
Relevant URL: http://www.securityfocus.com/bid/25329
Summary:
Babo Violent 2 is prone to four vulnerabilities. These vulnerabilities in=
clude a format-string and three denial-of-service issues.=20
Successful attacks could result in execution of arbitrary code or could c=
rash game servers.
6. EFS Software Easy Chat Server Authentication Request Handling Remote D=
enial Of Service Vulnerability
BugTraq ID: 25328
Remote: Yes
Date Published: 2007-08-14
Relevant URL: http://www.securityfocus.com/bid/25328
Summary:
Easy Chat Server is prone to a remote denial-of-service vulnerability.
Attackers can exploit this issue to crash the server, denying access to l=
egitimate users.
Easy Chat Server 2.2 is reported to be vulnerable; other versions may als=
o be affected.
7. Live For Speed Multiple Vulnerabilities
BugTraq ID: 25327
Remote: No
Date Published: 2007-08-14
Relevant URL: http://www.securityfocus.com/bid/25327
Summary:
Live For Speed is prone to four vulnerabilities. These vulnerabilities in=
clude buffer overflows and denial of service issues.=20
Successful exploits could result in execution of arbitrary code or could =
crash game servers.
8. Zoidcom Malformed Packet Denial of Service Vulnerability
BugTraq ID: 25326
Remote: Yes
Date Published: 2007-08-14
Relevant URL: http://www.securityfocus.com/bid/25326
Summary:
The Zoidcom network library is prone to a denial of service vulnerability=
when handling malformed packets.=20
An attacker could exploit this to crash a network service that is impleme=
nted with the library.
9. Drupal Content Construction Kit Nodereference Module Multiple HTML-inj=
ection Vulnerabilities
BugTraq ID: 25321
Remote: Yes
Date Published: 2007-08-14
Relevant URL: http://www.securityfocus.com/bid/25321
Summary:
Drupal Content Construction Kit is prone to multiple HTML-injection vulne=
rabilities because it fails to sufficiently sanitize user-supplied input =
before displaying it in dynamically generated content.
An attacker could exploit these vulnerabilities to execute arbitrary scri=
pt code in the browser of an unsuspecting victim in the context of the af=
fected site. This may allow the attacker to steal cookie-based authentica=
tion credentials and to launch other attacks.
10. Diskeeper DKService.EXE Remote Information Disclosure Vulnerability
BugTraq ID: 25320
Remote: Yes
Date Published: 2007-08-14
Relevant URL: http://www.securityfocus.com/bid/25320
Summary:
Diskeeper is prone to an information-disclosure vulnerability because it =
fails to restrict access to a certain RPC function.
This issue can be exploited to gain access to potentially sensitive infor=
mation stored at arbitrary attacker-supplied memory addresses. Informati=
on gained could aid in further attacks. Supplying a bad memory address wi=
ll cause denial-of-service conditions.
Diskeeper 9 Professional and Diskeeper 2007 Pro Premier are vulnerable; o=
ther versions may also be affected.
11. Microsoft Internet Explorer Vector Markup Language VGX.DLL Remote Buf=
fer Overflow Vulnerability
BugTraq ID: 25310
Remote: Yes
Date Published: 2007-08-14
Relevant URL: http://www.securityfocus.com/bid/25310
Summary:
Microsoft Internet Explorer is prone to a buffer-overflow vulnerability b=
ecause it fails to perform adequate boundary checks on user-supplied data=
.
This issue occurs when rendering VML (Vector Markup Language) grpahics.
Attackers can leverage this issue to execute arbitrary code in the contex=
t of the currently logged-in user.
Successful attacks may facilitate the remote compromise of affected compu=
ters. Failed attacks will likely cause denial-of-service conditions.
12. Microsoft Windows Media Player Remote Skin Decompression Code Executi=
on Vulnerability
BugTraq ID: 25307
Remote: Yes
Date Published: 2007-08-14
Relevant URL: http://www.securityfocus.com/bid/25307
Summary:
Microsoft Windows Media Player is prone to a remote code-execution vulner=
ability when handling specially crafted compressed skin files.
Attackers exploit this issue by coercing unsuspecting users to download a=
nd open Windows Media Player skin files (WMZ or WMD files).
Successful exploits allow attackers to execute arbitrary code in the cont=
ext of the vulnerable application. This facilitates the remote compromise=
of affected computers.
13. Windows Vista Weather Gadget Remote Code Execution Vulnerability
BugTraq ID: 25306
Remote: Yes
Date Published: 2007-08-14
Relevant URL: http://www.securityfocus.com/bid/25306
Summary:
Windows Vista is prone to a remote code-execution vulnerability because i=
t fails to adequately validate certain HTML attributes.
Attackers can leverage this issue to execute arbitrary code in the contex=
t of the currently logged-in user. Successful attacks may facilitate the =
remote compromise of affected computers.
14. Microsoft Windows Media Player Remote Skin Header Code Execution Vuln=
erability
BugTraq ID: 25305
Remote: Yes
Date Published: 2007-08-14
Relevant URL: http://www.securityfocus.com/bid/25305
Summary:
Microsoft Windows Media Player is prone to a remote code-execution vulner=
ability when handling specially crafted skin files.
Attackers exploit this issue by coercing unsuspecting users to download a=
nd open Windows Media Player skin files (WMZ or WMD files). Note that use=
rs must attempt to apply the skin files.
Successful exploits allow attackers to execute arbitrary code in the cont=
ext of the vulnerable application. This facilitates the remote compromise=
of affected computers.
15. Windows Vista Contacts Gadget Remote Code Execution Vulnerability
BugTraq ID: 25304
Remote: Yes
Date Published: 2007-08-14
Relevant URL: http://www.securityfocus.com/bid/25304
Summary:
Windows Vista is prone to a remote code-execution vulnerability because i=
t fails to adequately sanitize user-supplied data.
Attackers exploit this issue by coercing unsuspecting users to add or imp=
ort malicious contact files.
Attackers can leverage this issue to execute arbitrary code in the contex=
t of the currently logged-in user. Successful attacks may facilitate the =
remote compromise of affected computers.
16. Qbik WinGate SMTP Service Command Format String Vulnerability
BugTraq ID: 25303
Remote: Yes
Date Published: 2007-08-13
Relevant URL: http://www.securityfocus.com/bid/25303
Summary:
Qbik WinGate is prone to a remote format-string vulnerability because the=
application fails to properly sanitize user-supplied input before includ=
ing it in the format-specifier argument of a formatted-printing function.
A remote attacker may execute arbitrary code with the privileges of the u=
ser running the affected application. Failed exploit attempts will result=
in a denial of service.
=20
This issue affects Qbik WinGate 6.2.1; other versions may also be affecte=
d.
17. Microsoft Windows GDI Metafiles AttemptWrite Remote Code Execution Vu=
lnerability
BugTraq ID: 25302
Remote: Yes
Date Published: 2007-08-14
Relevant URL: http://www.securityfocus.com/bid/25302
Summary:
Microsoft Windows is prone to a remote code-execution vulnerability becau=
se it fails to properly bounds-check user-supplied metafile data.
Successfully exploiting this issue allows remote attackers to execute arb=
itrary machine code in the context of users viewing malicious files. This=
facilitates the remote compromise of affected computers.
18. Microsoft XML Core Services SubstringData Integer Overflow Vulnerabil=
ity
BugTraq ID: 25301
Remote: Yes
Date Published: 2007-08-14
Relevant URL: http://www.securityfocus.com/bid/25301
Summary:
Microsoft XML Core Services is prone to an integer-overflow vulnerability=
. This issue occursw because the application fails to ensure that integer=
values are not overrun.
Attackers can exploit this issue by enticing unsuspecting users to view m=
alicious web content. Specially crafted scripts could issue requests to M=
SXML that trigger memory corruption.
Successfully exploiting this issue allows remote attackers to corrupt hea=
p-memory and execute arbitrary code in the context of the affected applic=
ation. Failed exploit attempts will result in a denial-of-service conditi=
on.
19. WengoPhone SIP Soft Phone Malformed Packet Denial of Service Vulnerab=
ility
BugTraq ID: 25300
Remote: Yes
Date Published: 2007-08-13
Relevant URL: http://www.securityfocus.com/bid/25300
Summary:
WengoPhone is prone to a denial-of-service vulnerability because the appl=
ication fails to properly handle malformed data.
Successful exploits can allow remote attackers to crash the application, =
resulting in denial-of-service conditions.
This issue affects WengoPhone 2.1; other versions may also be affected.
20. CounterPath X-Lite SIP Soft Phone Malformed Packet Denial of Service =
Vulnerability
BugTraq ID: 25299
Remote: Yes
Date Published: 2007-08-13
Relevant URL: http://www.securityfocus.com/bid/25299
Summary:
CounterPath X-Lite is prone to a denial-of-service vulnerability because =
the application fails to properly handle malformed data.
Successful exploits can allow remote attackers to crash the application, =
resulting in denial-of-service conditions.
This issue affects X-Lite 3.0; other versions may also be affected.
21. Microsoft Virtual PC and Virtual Server Heap Overflow Vulnerability
BugTraq ID: 25298
Remote: No
Date Published: 2007-08-14
Relevant URL: http://www.securityfocus.com/bid/25298
Summary:
Microsoft Virtual PC and Virtual Server are prone to a local heap-overflo=
w vulnerability.
To exploit this issue, attackers must have administrative privileges for =
the guest operating system.
Attackers may exploit this issue to execute arbitrary code in the conte=
xt of the host operating system or another guest operating system. Succes=
sful exploits can result in a compromise of vulnerable computers.
22. MS Visual Basic 6 Package and Deployment Wizard ActiveX Control Remot=
e Code Execution Vulnerability
BugTraq ID: 25295
Remote: Yes
Date Published: 2007-08-14
Relevant URL: http://www.securityfocus.com/bid/25295
Summary:
The Microsoft Visual Basic 6 Package and Deployment Wizard ActiveX contro=
l is prone to a remote code-execution vulnerability.
An attacker may exploit this issue by enticing victims into opening a mal=
iciously crafted HTML document.
Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the application using the ActiveX control (=
typically Internet Explorer). Failed exploit attempts will likely result =
in denial-of-service conditions.
23. Microsoft Internet Explorer CSS Strings Memory Corruption Vulnerabili=
ty
BugTraq ID: 25288
Remote: Yes
Date Published: 2007-08-14
Relevant URL: http://www.securityfocus.com/bid/25288
Summary:
Microsoft Internet Explorer is prone to a remote code-execution vulnerabi=
lity because the application fails to properly handle certain CSS data.
An attacker may exploit this issue by enticing victims into opening a mal=
iciously crafted HTML document.
Successful exploits may allow an attacker to execute arbitrary code in th=
e context of the user running the vulnerable application.
This issue affects Internet Explorer 5.01 SP4 running on Microsoft Window=
s 2000 SP4.
24. Windows Vista Feed Headlines Gadget Remote Code Execution Vulnerabili=
ty
BugTraq ID: 25287
Remote: Yes
Date Published: 2007-08-14
Relevant URL: http://www.securityfocus.com/bid/25287
Summary:
Windows Vista is prone to a remote code-execution vulnerability because i=
t fails to adequately sanitize user-supplied data.
Attackers exploit this issue by coercing unsuspecting users to subscribe =
to a malicious RSS feed using the affected gadget.
=20
Attackers can leverage this issue to execute arbitrary code in the conte=
xt of the currently logged-in user. Successful attacks may facilitate the=
remote compromise of affected computers.
25. Microsoft OLE Automation SubstringData Function Integer Overflow Vuln=
erability
BugTraq ID: 25282
Remote: Yes
Date Published: 2007-08-14
Relevant URL: http://www.securityfocus.com/bid/25282
Summary:
Microsoft OLE Automation is prone to an integer-overflow vulnerability. t=
his issue occurs because the application fails to ensure that integer val=
ues are not overrun.=20
Successfully exploiting this issue allows remote attackers to corrupt hea=
p memory and execute arbitrary in the context of the affeced application.=
Failed exploit attempts will result in a denial-of-service condition.
26. Microsoft Excel Worksheet Index Value Remote Code Execution Vulnerabi=
lity
BugTraq ID: 25280
Remote: Yes
Date Published: 2007-08-14
Relevant URL: http://www.securityfocus.com/bid/25280
Summary:
Microsoft Excel is prone to a remote code-execution vulnerability.
Attackers may exploit this issue by enticing victims into opening a malic=
iously crafted Excel file (.xls).
Successful exploits may allow attackers to execute arbitrary code with th=
e privileges of the user running the application. This may facilitate a c=
ompromise of vulnerable computers.
27. Microsoft DirectX Media SDK DXTLIPI.DLL ActiveX Control Buffer Overfl=
ow Vulnerability
BugTraq ID: 25279
Remote: Yes
Date Published: 2007-08-10
Relevant URL: http://www.securityfocus.com/bid/25279
Summary:
Microsoft DirectX Media SDK 'DXTLIPI.DLL' ActiveX control is prone to a b=
uffer-overflow vulnerability because it fails to perform adequate boundar=
y checks on user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the application using the ActiveX control (=
typically Internet Explorer). Failed exploit attempts likely result in de=
nial-of-service conditions.
Microsoft DirectX Media SDK 6.0 with DXTLIPI.DLL 6.0.2.827 is reported vu=
lnerable.
28. WinGate SMTP Session Invalid State Remote Denial Of Service Vulnerabi=
lity
BugTraq ID: 25272
Remote: Yes
Date Published: 2007-08-10
Relevant URL: http://www.securityfocus.com/bid/25272
Summary:
WinGate is prone to a denial-of-service vulnerability because the applica=
tion fails to sanitize user-supplied input before including it in the for=
mat-specifier argument of a formatted-printing function.
An attacker can exploit this issue to crash the affected application, den=
ying service to legitimate users.=20
This issue affects versions prior to WinGate 6.2.2.
29. Microsoft August 2007 Advance Notification Multiple Vulnerabilities
BugTraq ID: 25247
Remote: Yes
Date Published: 2007-08-09
Relevant URL: http://www.securityfocus.com/bid/25247
Summary:
Microsoft has released advance notification that the vendor will be relea=
sing nine security bulletins on August 14, 2007. The highest severity rat=
ing for these issues is 'Critical'.
Successful exploits can result in privilege escalation and remote code e=
xecution.
Further details about these issues are not currently available. Individua=
l BIDs will be created for each issue; this record will be removed when t=
he security bulletins are released.
30. Microsoft Windows Media Player AU Divide-By-Zero Denial of Service Vu=
lnerability
BugTraq ID: 25236
Remote: Yes
Date Published: 2007-08-08
Relevant URL: http://www.securityfocus.com/bid/25236
Summary:
Microsoft Windows Media Player is prone to a denial-of-service vulnerabil=
ity when processing a malformed AU file.=20
A remote attacker can exploit this issue to crash the affected applicatio=
n, denying service to legitimate users.
This issue affects Microsoft Windows Media Player 11; other versions may =
also be affected.
31. Symantec Altiris Deployment Solution Local Privilege Escalation Vulne=
rability
BugTraq ID: 25232
Remote: No
Date Published: 2007-08-13
Relevant URL: http://www.securityfocus.com/bid/25232
Summary:
Symantec Altiris Deployment Solution is prone to a local privilege-escala=
tion vulnerability.
An attacker can exploit this issue to execute arbitrary commands with SYS=
TEM-level privileges. Successfully exploiting this issue will result in t=
he complete compromise of affected computers.
32. Microsoft Internet Explorer Position:Relative Denial of Service Vulne=
rability
BugTraq ID: 25222
Remote: Yes
Date Published: 2007-08-07
Relevant URL: http://www.securityfocus.com/bid/25222
Summary:
Microsoft Internet Explorer is prone to a denial-of-service vulnerability=
because the application fails to handle certain HTML code.
This issue is triggered when a remote attacker entices a victim user to v=
isit a malicious website.
Attackers may exploit this issue to crash Internet Explorer, effectively =
denying service to legitimate users.
This issue affects Internet Explorer 6.
III. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Password complexity - improvement
http://www.securityfocus.com/archive/88/476610
2. SecurityFocus Microsoft Newsletter #354
http://www.securityfocus.com/archive/88/476463
3. SecurityFocus Microsoft Newsletter #352
http://www.securityfocus.com/archive/88/476453
IV. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to ms-secnews-unsubscribe@securityf=
ocus.com from the subscribed address. The contents of the subject or mess=
age body do not matter. You will receive a confirmation request message t=
o which you will have to answer. Alternatively you can also visit http://=
www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and a=
sk to be manually removed.
V. SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: SPI Dynamics
ALERT: Web Hacking - Attack Scenarios and Examples- White Paper
Learn how to defend against Web Application Attacks with real-world examp=
les of recent hacking methods such as SQL Injection, Cross Site Scripting=
and Parameter Manipulation. Learn step-by-step vulnerability testing met=
hods for your own Web Applications and guidelines for establishing best a=
dministration and coding practices.
Download *FREE* white paper from SPI Dynamics for a complete guide to pro=
tection!
https://download.spidynamics.com/1/ad/web.asp?Campaign_ID=3D70160000000D0=
r2