 |
 User: Login | Weblog covering digital business Digital Business, Live |
| Address URL | http://www.alleyinsider.com/ Registered: 22-Mar-2008 |
| Ads: | |
Send to email | Can Hackers Punish You Just For Looking At A Picture? in General | By Silicon el 03-Aug-2008 |
wargames.jpg: Paste this image in your site, Myspace, Facebook, Ebay copy this code...
Think you're unlikely to get hacked, because you only use grown-up Web sites with serious security, and never open dubious emails with mysterious attachments? Think again: A new kind of security trap -- an image format called GIFAR -- will punish people who simply look at a picture on a Web site. Computerworld:
Here's how an attack would work: A bad guy would create a profile on a popular Web site -- Facebook, for example -- and upload his GIFAR as an image on the site. Then he'd trick a victim into visiting a malicious Web site, which would tell the victim's browser to go open the GIFAR. At that point, the applet would run in the browser, providing the hacker access to the victim's Facebook account.
The attack could work on any site that allows users to upload files, potentially even on Web sites that are used to upload banking card photos or Amazon.com, they say.
So now you can get screwed just by looking at a photo? There's only one hope -- no one's actually using this hack yet. As of today, it's mostly theoretical: GIFAR has been created by a bunch of security experts, supposedly to show how insecure Web browsers are, and to question the computer industry's move away from desktop software and toward Web apps.
But since the supposed vulnerability is going to get shown off during this week's Black Hat conference, at a talk called "The Internet Is Broken", if it works at all, it won't stay theoretical for long. We may have to consider dumping our computers altogether and retreating to some kind of stick-based technology.
See Also: Facebook Tries To Fight Off International Clones. Good Luck With That Facebook's Anti-Spam Campaign Claims An Innocent Victim

Read 2 times

|
|
 |
 | Nerdblog | Blogger | Provides news about hardware, software, notebooks, laptops, PCs, Mac, PDAs Nerdblog.Net |
| Android jailbreak battle ensues; welcome to mobile, Google | Google must have known this was coming. In the ever-present battle between mobile manufacturers and hackers, it’s always a game of cat and mouse. New OS build is released, hackers attack, hackers win, manufacturer patches - lather, rinse and repeat. Apple was welcomed to the game pretty quickly and so far the cycle has been [...] [..] Read complete article |  | Published 09-Nov-2008 by Zach Epstein in AndroidSoftwarefirmwareG1googleHTCJailbreakupdate Read 2 times. More hits in  |
|
 | Nerdblog | Blogger | Provides news about hardware, software, notebooks, laptops, PCs, Mac, PDAs Nerdblog.Net |
| Wii update stops homebrew, today | Where there’s a console, there’s a battle between manufacturers and hackers. On the one side - the hacker. Always fighting to open closed doors and enable free functionality for gamers around the world. On the other side - the manufacturer. Always trying to seal holes in an effort to thwart hackers from eating into their [...] [..] Read complete article |  | Published 24-Oct-2008 by Zach Epstein in GamingNintendo WiiSoftwarehackhomebrewNintendoupdateWii Read 1 times. More hits in  |
|
 | Nerdblog | Blogger | Provides news about hardware, software, notebooks, laptops, PCs, Mac, PDAs Nerdblog.Net |
 | Kotaku`s The Gamers Guide | Blogger | XBOX 360 Gamers Weblog
Gossip, news and leaks for obsessive gamers Kotaku As if you don't waste enough of your time in a gamer's haze, here's Kotaku: a gamer's guide that goes beyond the press release. Gossip, cheats, criticism, design, nostalgia, pred |
| Palin Email Account Hackers? Carelessness Could Lead to Capture | Oops. You would think that the group of hackers who recently dug into one of Vice Presidential candidate Sarah Palin’s email accounts was smart enough to cover its trail. Unfortunately for them, it looks like you would be wrong. By now you must have read the hacker group known as Anonymous recently found its way [...]
[..] Read complete article |  | Published 18-Sep-2008 by Zach Epstein in NewsEmailhackMcCainPalinSarahYahoo Read 5 times. More hits in  |
|
 | Nerdblog | Blogger | Provides news about hardware, software, notebooks, laptops, PCs, Mac, PDAs Nerdblog.Net |
| ISPs’ Error Page Ads Let Hackers Hijack Entire Web | | ISPs, including Earthlink, that seek to make money from customers’ mistyped URLs put the entire internet at risk from hackers that steal passwords, a security researcher reveals Saturday. While the immediate vulnerability is fixed, the practice of returning ads instead of error messages raises ongoing security, Net Neutrality and security concerns.
[...] [..] Read complete article |  | Published 20-Apr-2008 by Nerdblog in General Read 12 times. More hits in  |
|
| HOPE Hacker Conference To Continue In New York In 2010. We Think | Every other year since 1994, hackers from all over the world have converged on New York City for the Hackers On Planet Earth conference. But this year's bash, held last weekend, was supposed to be the final run. HOPE's long-time home the Hotel Pennsylvania was said to be closing, and conference organizers, the editors of Long Island-based 2600 magazine, were calling it quits. They were laying [..] Read complete article |  | Published 23-Jul-2008 by Silicon in General Read 4 times. More hits in  |
|
| HTC Touch Diamond giveaway winner! | | Are you sure you want to know to know who the winner is? Well, you might have guessed from the picture above. BadChad, please stand up and claim your prize! This was really tough to decide but we wanted the most creative entry and that picture just screams creativity doesn’t it? It kind of scares [...] [..] Read complete article |  | Published 11-Jun-2008 by The Boy Genius in FeaturesgiveawayHTCn.e.r.d.touch diamondwinner Read 10 times. More hits in  |
|
|
Warning We are not responsible of information posted from external feeds. Use this website at your own risk.
Notice: We will not be liable for any direct or indirect loss or damage arising under this disclaimer or in connection with our website, whether arising in tort, contract, or otherwise.
|
|
| |