Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.internet.wireless
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 08-06-2006, 05:56 PM
John Navas
Guest
 
Posts: n/a
Default NEWS: Researchers warn over web worms

<http://www.securityfocus.com/news/11405>

Exploiting a lack of security checks in browsers and Web servers, Web
worms and viruses are likely to become a major threat to surfers,
security researchers speaking at the Black Hat Briefings warned on
Thursday.

In separate presentations, researchers showed off techniques for
using Javascript code on Web pages to grab browser histories and scan
internal networks as well as using AJAX--a technology that adds
interactive features to Web sites--to create Web viruses that can
steal personal information. The threats are not only theory, but have
been used to attack MySpace users and Yahoo users, said Billy
Hoffman, lead research and development researcher for Web security
firm SPI Dynamics.

"This isn't a proof of concept; this isn't academic," Hoffman told
attendees at the Black Hat Briefings. "People are already doing
this."

...

Grossman showed off techniques for detecting which of a list of
popular sites that a victim has visited and demonstrated a way to
port scan an internal network to which the victim is connected, all
through Javascript and without exploiting vulnerabilities.

"We don't need to hack the operating system anymore--everything you
need to attack is online," Grossman said.

...

There are few other defenses against the attacks, aside from turning
off Javascript, Hoffman said.

Secure Sockets Layer (SSL) encryption, far from helping secure
against such attacks, could instead aid them in dodging detection by
intrusion detection, or prevention, systems, he said. If the Web site
from which the attack is launched uses SSL, then the
traffic--encrypted between the site and the user--cannot be parsed by
a network-based IDS system.

The most permanent fix would be for browser makers to find ways to
confirm that AJAX code is indeed running in the context of the
current Web site being visited by a user, while marking Web requests
with the source of the request--whether a human or a script--could
limit attacks on high-value sites, such as brokerage firms and banks.

"We have made a call out to the browsers makers to fix the problems,"
Grossman said. "We hope it comes soon before the bad attacks happen."

[MORE]

--
Best regards,
John Navas

Reply With Quote
  #2 (permalink)  
Old 08-06-2006, 06:35 PM
Duane Arnold
Guest
 
Posts: n/a
Default Re:It's Johnny-Boy-G-Man NEWS: Researchers warn over web worms

What? Is this another one of your Jr. G-Man *Alerts* Johnny-Boy-G-Man?

Duane :(

Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
WiMAX Forum News, Weekly Clip Report March 22-29, 2007 badger_b@hotmail.com alt.internet.wireless 0 03-31-2007 02:14 AM
NEWS: Physics promises wireless power John Navas alt.internet.wireless 80 11-18-2006 07:18 PM
NEWS: Physics promises wireless power John Navas alt.cellular.cingular 74 11-18-2006 07:18 PM
NEWS: Nokia unveils new short-range wireless tech (Wibree) John Navas alt.internet.wireless 0 10-11-2006 09:01 PM
attn: nicolas - highly aesthetic news groups - ep - (1/1) alt.comp.hardware 0 09-04-2005 02:28 PM


All times are GMT. The time now is 08:53 AM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45