Web 2.0 could lead to virus 2.0…



The last couple days, there’s been a virus spreading making use of yahoo mail’s interface. Usually web mail is considered a fairly safe way to get email, but in this case all that was done was the user clicking on a malicious email and the virus ran. It appears that javascript/AJAX/Web 2.0 applications are going to have to get closer scrutiny. In the Sans diary, they mention that they’ve analyzed javascript from several web applications and there are some that are vulnerable. (They’re contacting vendors.) They also point out web designers should keep this in mind as well..

The current worm could be readily modified to spread across many systems that do not escape javascript when displaying data from a foreign source. Many web developers should reexamine their code, and make sure that display functions do not deliver potentially malicious code.


The writeup on the yahoo worm gives the following details..

A Yahoo! mass-mailer is currently making the rounds with a subject of “[random word] New Graphic site”.

There is a good deal more that can be found at this link. Of course, turning of javascript kind of defeats the purpose of the mail interface. So that’s not a good workaround. They are working on a fix (already in the beta version) and are blocking many of the messages at this point.

Related Posts

Blog Traffic Exchange Related Posts
  • FBI / CIA virus Well... the media has taken the drab name of w32sober.X@mm or w32sober.x or w32sober.y, W32/Sober.AD-mm or any of those other drab names that we've been looking at the last week and dubbed the latest big virus, the FBI/CIA virus.... and it's gotten a lot of press the last few days.......
  • Gmail Virus scanning and more I saw a link yesterday about Gmail adding virus scanning to their featureset. It's very good to see, they have very good junk filtering at this point and had a blanket policy that .exe's were banned (which would stop a good percentage of the bugs.) Anyway, it's good to see......
  • The press covering the WMF bug It's always a strange mix between comedy and frustration to see the main media outlets cover a tech news item. I usually wince and brace myself when I see any tv news outlet take on a computer issue and likewise when I read newspapers and non-tech publications take on anything......
Blog Traffic Exchange Related Websites
  • Warning: Visiting This Site May Harm Your Computer Removal So you've just noticed that when you search for your website in Google, along with your standard listing you also have a message which reads "Warning Visiting This Site May Harm Your Computer". This article is all about *why* this warning appears, how to correct any issues with your......
  • Creating Your Personal World Wide Web Banners Makes Sense Off! Banner ads are one of the most extremely popular and effective ways of internet advertising. Advertising online is economical for businesses of most sizes and empowers you to reach audiences worldwide in a way that isn't possible with any other media. Animated Banners Deliver Greater Answer Using an animated banner......
  • Protecting Yourself On The Internet Since its beginning in 1990 the online market place has revolutionised the way the world shares info. Unfortunately, it in addition has opened up a whole new world with bad people doing bad things. Illegal material hasn't been so easily available Big Dog Formula to tempt probably the most innocent......
www.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site