Wednesday December 3, 2008 7:52 AM AEST
Latest Comments
"trend is good antivirus software."
by jack | Dec 3, 2008 7:02 AM
 
"I feel it with you guys. These irritating interruptions on privacy MUST be stopped. It is a ..."
by Jan Wilmans | Dec 2, 2008 7:11 PM
 
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
Web

Image-applet combo hack revealed

  • Email a Friend
  • Print Page
By Andrew Charlesworth
Aug 5, 2008 9:43 AM
Tags: Image-applet | combo | hack | revealed
Security experts have developed a hybrid file type that looks like an image but can also run a Java applet surreptitiously in a browser.

The researchers, from UK-based Next Generation Security Software (NGSS) and Ernst & Young LLP's Advanced Security Centre, say it can be used to gain access to a user’s browser on any site that allows images to be uploaded, such as social networking sites or eBay.

The file – known as a Gifar – looks like a .gif image to the host website, but is also combined with a .jar Java archive file. When 'displayed' in a visitor’s browser, the JAR runs as an applet and gives the attacker the opportunity to run Java code in the infected browser.

To the browser, the Java code will look like it has come from the legitimate site. The attack would work best on sites where users stay logged in for some period of time, say NGSS officials.

Last week, a report from security firm Websense, revealed that in the last six months, six out of 10 legitimate websites had at some point inadvertently hosted malware.

NGSS unveiled the Gifar attack at the Black Hat security conference, running this week in Las Vegas. But they kept back vital details to prevent attacks from being launched immediately.

Recently, Kris Lamb, head of IBM’s X-force security outfit, criticised security researchers for publishing vulnerabilities, saying the practice was tantamount to aiding cyber criminals.

To prevent Gifar attacks from proliferating, Sun is expected to tighten security in the Java runtime environment and websites could improve their filters to spot Gifars. But this would protect only against the one attack vector, says NGSS.

Ultimately browser security will have to be improved, say security experts.

Copyright © 2008 vnunet.com

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Vulnerabilities & Exploits Whitepapers