- Insider threat looms large in San Francisco
- Woman fired over death threat
- IT admin pleads not guilty
- Tape storage gets more dense
- Top 10 worst uses for Windows
News | Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:App Performance | On Demand Security | Networking Solution | SOA | Value of WDS
San Francisco -- Threats against browsers are getting more sophisticated and branching out into such exotic areas as gaming, experts told attendees at RSA Conference 2008.
New attacks from games and virtual-world Web sites can deliver bot-like control of browsers to attackers, said Ed Skoudis, a security consultant with Intelguardians, speaking at RSA. All that's needed is for the infected image of an avatar to appear. "The character walks into view of the screen, and I take over the box," he said.
Compromised browsers can act as a stage to launch further hacking of computers, Skoudis said. An attack could shut off corrupted machines' keyboard and mouse control, making it more difficult to stop. Or a compromised browser could escalate a machine's network privileges, and even change time stamps in registries to mask the attacks from later forensic investigation, he said. (Compare forensics tools.)
Browser attacks can be layered so an infected site might divert a browser to another site that barrages it with a broad spectrum of attacks, seeking vulnerabilities to take advantage of, said Rahit Dhamankar, head of security research for TippingPoint Technologies.
Such Web-based attacks can even be more effective than individuals banging away at machines, Dhamankar said. At a recent hacking contest, participants tried to compromise laptops running Vista, Mac and Ubuntu Linux operating systems for an entire day without success. The next day those same machines were allowed to browse the Internet and became infected by Web sites they visited, he said.
Phones with browsers are subject to similar hijacking, Dhamankar said, and he has seen vulnerabilities found in specific phones posted for sale on the Internet.
The vulnerabilities extend to applications that plug into or integrate with browsers, such as flash readers. "They become a large attack surface," said Michael Montecillo, an analyst with EMA attending the conference.
Attacks are carefully crafted, Montecillo said. For instance, a criminal seeking to take over the machines of wealthy people might hack the Web site of a well-heeled church in an affluent community so it downloads malware to vulnerable machines that connect with it. "Such a site exploit might go unnoticed for a long time," he said.
Investment of a Technology should be 'held off' because there hasn't been enough investment in it yet? Is...- Anonymous
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.
Download the white paper.
Unauthorized applications: Taking back control
Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?
Download the white paper.
Comment