Newsletters Welcome, Guest Log In | Register

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • CTO Edge Update
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments

0

Javascript New Language of Malware?

Posted by Kara Reeder Oct 30, 2008 9:35:26 AM

Javascript may be the next language of choice for malware, according to security researcher Itzik Kotler of Radware.

 

Kolter demonstrated an attack, dubbed Jinx, that takes advantage of a hole in Javascript that allows a hacker to copy any file from a user's PC. The attack is virtually undetectable because no browser binary is altered, but rather plain HTML code is added into just one specific file, reports vnunet.com.

 

While Kolter says the Jinx hack is not yet in the wild, HP's Billy Hoffman says attackers have been using JavaScript apps to capture keystrokes. And a JavaScript tool called Middler lets hackers bypass Web security authentication on certain banking, e-mail and social networking sites.

Add a comment Leave a comment on this blog post.

There are no comments on this post

ITIL V3 Foundation - Complete Certification Kit

Enhance your IT career by getting your ITIL Foundation Certificate. It's fast and easy with this complete resource. The 186-page eBook and companion online training course is guaranteed to help you pass the ITIL exam.

Learn more >

Six Sigma Framework for IT

This collection of tutorials, calculators, and templates will show you how to apply six sigma thinking to IT service management.

Learn more >

Seven Design Requirements for Web 2.0 Threat Prevention

This white paper outlines the new Web 2.0 threats, explains why most existing security solutions can't provide adequate protection, and proposes seven design requirements for Web 2.0 threat protection.

Should You Install Messaging Security Software on Your Exchange Server?

This white paper discusses the detailed results of an Osterman Research survey on messaging security software and conclusions about administrators' attitudes regarding installing third-party software on the Exchange server.

Cost Cutting through Server Consolidation

Products, management tools, and industry insights that enhance the value of virtualization for your business.

Responding to Change

The technology tips and tools to enhance your ability to respond to business change with ease and success.

Data Deduplication

Data manipulation strategies that make data stores more manageable and reduce the need for storage capacity and its associated costs.

Mobile Computing Optimization

Mobile computing solutions, tips, and expert commentary that increases the usability and bottom-line benefits of your mobile computing assets.