Web 2.0 could lead to virus 2.0…



The last couple days, there’s been a virus spreading making use of yahoo mail’s interface. Usually web mail is considered a fairly safe way to get email, but in this case all that was done was the user clicking on a malicious email and the virus ran. It appears that javascript/AJAX/Web 2.0 applications are going to have to get closer scrutiny. In the Sans diary, they mention that they’ve analyzed javascript from several web applications and there are some that are vulnerable. (They’re contacting vendors.) They also point out web designers should keep this in mind as well..

The current worm could be readily modified to spread across many systems that do not escape javascript when displaying data from a foreign source. Many web developers should reexamine their code, and make sure that display functions do not deliver potentially malicious code.


The writeup on the yahoo worm gives the following details..

A Yahoo! mass-mailer is currently making the rounds with a subject of “[random word] New Graphic site”.

There is a good deal more that can be found at this link. Of course, turning of javascript kind of defeats the purpose of the mail interface. So that’s not a good workaround. They are working on a fix (already in the beta version) and are blocking many of the messages at this point.

Related Posts

Blog Traffic Exchange Related Posts
  • How to Remove Antivirus System Pro | Antivirus System Pro Removal Guide Last week I had the opportunity to remove Antivirus System Pro from not one, but two machines. Given that I was seeing it a bit more frequently I thought it might be a new rogue antivirus application, but I quickly found out that it's been out at least since June......
  • Nyxem.E virus delete files payload F-secure has some details on a dangerous payload for the Nyxem.E virus. (The Nyxem.E virus is very similar to the Email-Worm.Win32.VB.bi that was talked about earlier in the week.) In fact, this virus seems to be spreading fairly well (not the blockbuster spread of older email viruses, but it is......
  • Gmail Virus scanning and more I saw a link yesterday about Gmail adding virus scanning to their featureset. It's very good to see, they have very good junk filtering at this point and had a blanket policy that .exe's were banned (which would stop a good percentage of the bugs.) Anyway, it's good to see......
Blog Traffic Exchange Related Websites
  • Produce Visitors To Your Web Site And Lastly Start Out Earning An Income On-line Receiving readers aimed at your site is perhaps the most difficult part of internet website marketing. However, We have gave you a handful of methods you should choose to use produce targeted traffic aimed at your web. 1.       Target The Proper Keyphrases Steve Reese asserted keyword research can make or......
  • Free Vs Paid Web Hosting Options Everyone likes to get something for free. But as the existence of spam shows, free isn't always good. Sometimes, it's downright harmful. Deciding whether it's worth the cost to pay for hosting involves a number of complex considerations.Hosting companies that offer free services obviously can't stay in business from the......
  • Creating Your Personal World Wide Web Banners Makes Sense Off! Banner ads are one of the most extremely popular and effective ways of internet advertising. Advertising online is economical for businesses of most sizes and empowers you to reach audiences worldwide in a way that isn't possible with any other media. Animated Banners Deliver Greater Answer Using an animated banner......
www.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site