Re: Malicious programs that are installed via HTML.



Lew wrote:
AIUI, it was not all that long ago when the threat to personal users, was attachments that when executed compromised machines with keyloggers, trojans, etc.

Now it seems that the big problem is reading a webpage or an HTML e-mail and getting affected through the scripting. My understanding is that the script downloads the malicious program from the web and sets it to run on start up through the start-up folder or in the registry.

I don't know much about this; can someone suggest a good web site to start learning a bit more about these threats. I have googled, but I am not quire sure of the best search terms, and since there is so much information out there, a site that experienced people endorse would be a lot of help.

Thanks.
Lew,

Scripting is one method of code injection to the local host. When code runs on the local machine there is the potential of compromise to the local host. To date there are no scripting languages I am aware of for webpages where an exploit has not existed at one time or another.

Some vulnerabilities do not even require scripts to run, for example the recent WMF vulnerability can execute on viewing the graphic. Another method uses mime to compromise the mail host.

There is a worm (Nyxem_e) currently making the rounds that executes in MIME (mail) format, no clicking or graphics required.

Every plug-in (such as macromedia, quicktime, media player etc) allows more code types to run within the browser, thereby expanding exploit potential.

Some methods to compromise a system require a series of code to run to break down the system defenses, these are layered threats and have a much higher probability of evading antivirus or other defenses.

I know of no single site that defines all of the methods that might be used to access/compromise a system. New methods are seen almost daily.

Understanding that running any untrusted code on the local machine opens the exploit window. Allowing some code varieties (activeX comes to mind) is more dangerous (generally) than, for example, java scripting.

Email clients that allow code to run within the email when opened (outlook express) is "generally" more dangerous than clients which do not run scripts.

Typically I do not run scripts of any sort in my browser unless the site I am visiting requires scripts and my need is greater than my concern for security, in which case I allow only the activity required for the site in question and turn off scripting functionalities once they are no longer required. Just because the script is being run from, for example Yahoo, does not mean the code is safe to run. Trust no one.

Downloading files from the net and installing programs be it games toolbars or other code is extremely dangerous unless you are sure of the code source.

Some very good reading can be found in the SANS reading room. SANS does a reasonable job keeping abreast of the compromise de' jour (handlers diary). The SANS site is: http://isc.sans.org/ (note link to reading room on top menu on page)

Looking at vulnerabilities in commercial/production software I frequently use http://secunia.com/

Both these sites support RSS which is useful to stay appraised of on-going threats on a regular basis.

http://www.eff.org/ has a number of topics that are good reading. While this is not generally considered a "computer" site, they have a number of articles and papers that address various threats.

This is a start, I am curious to see other folks advice on your question. I hope to find a good single answer.

Winged




.



Relevant Pages

  • Re: Some websites not detecting Flash
    ... Thanks for taking the time to read my thread, I look forward to reading your ... Initialize and Script ActiveX controls marked as safe for scripting ... > response. ... >>>>> still not detecting it. ...
    (microsoft.public.windowsxp.general)
  • Re: Learn LDAP Query using ADUC GUI
    ... Start on page 280 of your book in the section titled "Reading and Writing ... > I'm onboard with the concept of using ADSI after reading the ADSI ... > Scripting Primer and Active Directory Users chapters in the "MS Windows ... >>> lastlogontimestamp with accountinfo.dll which is a downloadable module ...
    (microsoft.public.windows.server.active_directory)
  • Re: reading files line by line & getting user input
    ... > I know reading a file line by line in a Bash script isn't quite as simple as ... > But reading from one file and getting user input after each line really gets ... scripting language. ...
    (comp.os.linux.misc)
  • Re: Can anyone make heads or tails of what this is saying?
    ... All the reading that I have done references the ... > autoexec.nt file as the one providing support to 16 BIT apps. ... -- torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway Administration scripting examples and an ONLINE version of the 1328 page Scripting Guide: ...
    (microsoft.public.windowsxp.configuration_manage)
  • Re: Hi
    ... >>That's what I like about Reading, it a good compromise if you ... >>Green Park is in South Reading. ... >>to London I can see where the idea of shithole crossed your mind. ...
    (microsoft.public.cert.exam.mcsd)