Jump to content

4 posts in this topic

Recommended Posts

Filed: Citizen (apr) Country: Brazil
Timeline
Posted

The security firm Finjan says it has discovered a major new type of malware that has infected more than 10,000 Web sites in December alone. Deemed "random js toolkit," it is a Trojan that infects end users' PCs and sends data from the infected machine to the "master" hacker. It can be used to steal passwords, documents and other sensitive information.

The malware dynamically creates and changes JavaScript code every time it is accessed, Finjan said. Thus, traditional anti-malware programs can't identify it.

Finjan CTO Yuval Ben-Itzhak said in a release, "Signaturing a dynamic script is not effective. Signaturing the exploiting code itself is also not effective, since these exploits are changing continually to stay ahead of current zero-day threats and available patches. Keeping an up-to-date list of 'highly-trusted-doubtful' domains serves only as a limited defense against this attack vector."

"What's needed to counter this exploit is dynamic code inspection technology that can detect and block an attack in real time," Ben-Itzhak said. "This technology doesn't depend on the origin URL, signature or the site's reputation, but inspects the Web content in real time, as served. It analyzes the code's intentions before enabling it be executed on the end-user browser."

Cyber criminals are intent on undermining trusted Web sites, Ben-Itzhak said. "In mid-year 2007, studies showed there were nearly 30,000 new infected Web pages being created every day. About 80 percent of those pages hosting malicious software or containing drive-by downloads with damaging content were located on hacked legitimate sites. Today the situation is much worse."

The attack works by dynamic embedding of scripts into a Web page, Finjan said. The dynamic embedding is done so selectively that "when a user has received a page with the embedded malicious script once, it will not be referenced again on further requests," the company said, so it can't be detected in forensic analyses.

"While dynamically changing malware is nothing new, this piece of code appears to be having some success in subverting the typical malware scanning systems," said Andrew Storms, director of security operations for nCircle Network Security. "While a blacklist may help some users... it's no substitute for a good set of layered defenses."

Storms added that this development shows Web site managers can no long play "the game of Whack-A-Mole." Rather, he said, "Security managers need to take a more active role in using policy and configuration management tools to ensure their Web sites and servers aren't vulnerable to attacks in the first place."

Among the 10,000 sites that have been infected are sites run by the University of California at Berkeley and Teagames Limited. Those organizations have been alerted, Finjan said, and the compromised sites are no longer online.

link

* ~ * Charles * ~ *
 

I carry a gun because a cop is too heavy.

 

USE THE REPORT BUTTON INSTEAD OF MESSAGING A MODERATOR!

Filed: Timeline
Posted

Aye, Java and Javascript are two different things. Java is a big, old, clunky development platform and javascript is a.....script. Javascript is used for things like roll-over changes to navigation links (I use CSS for that....javascript isn't accessible to people with screenreaders), ad deployment...all kinds of stuff.

Javascript runs things on your PC without your permission all the time. Pretty much every site, actually.

I have "NoScript" installed for Firefox. It's what I use to blog javascript enabled/activated ads (such as the ones here on VJ). I allow javascript only on sites I trust.

Lady, people aren't chocolates. Do you know what they are mostly? Bastards. ####### coated bastards with ####### filling. But I don't find them half as annoying as I find naive bobble-headed optimists who walk around vomiting sunshine.
 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
- Back to Top -

Important Disclaimer: Please read carefully the Visajourney.com Terms of Service. If you do not agree to the Terms of Service you should not access or view any page (including this page) on VisaJourney.com. Answers and comments provided on Visajourney.com Forums are general information, and are not intended to substitute for informed professional medical, psychiatric, psychological, tax, legal, investment, accounting, or other professional advice. Visajourney.com does not endorse, and expressly disclaims liability for any product, manufacturer, distributor, service or service provider mentioned or any opinion expressed in answers or comments. VisaJourney.com does not condone immigration fraud in any way, shape or manner. VisaJourney.com recommends that if any member or user knows directly of someone involved in fraudulent or illegal activity, that they report such activity directly to the Department of Homeland Security, Immigration and Customs Enforcement. You can contact ICE via email at Immigration.Reply@dhs.gov or you can telephone ICE at 1-866-347-2423. All reported threads/posts containing reference to immigration fraud or illegal activities will be removed from this board. If you feel that you have found inappropriate content, please let us know by contacting us here with a url link to that content. Thank you.
×
×
  • Create New...