search technology reviews, news, features, group tests
Popular Searches:   windows , asus ,
 |  Register
 |  Newsletters  | 
Sitemap  |  RSS
RSS
Monday November 9, 2009 12:48 AM AEST
Skip Navigation LinksPC Authority > News > Hackers may push Javascript as the next weapon of choice
Hackers may push Javascript as the next weapon of choice
NEWS

Hackers may push Javascript as the next weapon of choice

by  on Oct 31, 2008
Web 2.0 could be driving browser vulnerabilities and entice hackers to create new security exploits using Javascript code..
The demand that the development of web 2.0 has placed on browsers to become more interactive and act as a portal rather than just a viewing platform is opening up new vulnerabilities to unsuspecting users, Itzik Kotler, team leader of the Security Operation Center at Radware, has warned.

As well as developing new signatures and analytics tools for Radware scanning software, Kotler also works on finding new classes of vulnerabilities before they appear in the wild.

One such security hole is in Javascript, which would allow a hacker to copy any file from a user's PC with little chance of detection – something many have considered to be impossible.

Koter demoed the hack, dubbed 'Jinx' at this week's RSA security show in London. He showed how the process was done from within the browser itself, not by altering the browser binary, which can be detected by most anti-virus systems, but rather by adding plain HTML code into just one specific file.

According to Koter, this new class of attack will be attractive to cyber-criminals whose existing techniques are increasingly vulnerable to detection because the approach is cross platform and cross browser, allowing the hackers to access systems previously unavailable to them, such as Linux, Mac and mobile.

The problem stems from the fact that internet browsers have quickly moved from being passive text and picture viewers to essentially an operating system in their own right, through interactive services such as user-generated content, hosted applications, web mail and social networks.

"HTML is now like a batch file for everything," said Koter.

"It's only down to shaping and redirecting it from this intended purpose."

He concluded that, although these types of attack are not yet in the wild, security firms and browser developers need to ensure that the increased demand for a more flexible browser does not open the door to hackers.

Copyright © 2009 v3.co.uk
Email a Friend Email this
Print Page Print this
Tweet This Tweet this
Feedback Send us your tips


Ads by Google

Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Login or register to submit a comment.
 

Top Stories

New York launches antitrust investigation into Intel
The New York Attorney General Andrew M. Cuomo has announced it is launching an anti-trust investigation into Intel after allegations that the chip giant abused its market position.
 
5 More Free PC Apps You Can't Do Without
More digital Swiss Army knife software, including utilities and tools that are so useful you won't know how you ever did without them
 
Movie tech: The science behind the film 2012
The Mayan prophecy might be counting down, but the science behind the new film 2012 might leave a few people confused. We look at what the film got right and what is best left to conspiracy theorists.
 


 
LogMeIn
 
 
HP
 
 
Amazing Dell Coupons now available