The Register® — Biting the hand that feeds IT

Comments on: McAfee spies malware in legit JavaScript apps

Sandbox 

Posted Friday 4th January 2008 17:56 GMT

allegedly a safe place to play ... ahah ... the Java crap is to be blamed, not McAfee. Sandbox without a proper tarp end up filled with cat pooh. Can't blame McAfee trying to pick one pooh too many.

Please! 

Posted Friday 4th January 2008 19:24 GMT

Alert

Do not confuse Java with Javascript. The only evident relationship between the two is the four letters in "java."

I'm not entirely certain that anything calling Friendster "malware" is incorrect, however. It seems to me to be a bit less dangerous than a bio-engineered version of anthrax, and a bit more malicious than a kiss from your auntie; somewhere in between, but leaning towards anthrax.

Sandbox... 

Posted Sunday 6th January 2008 08:00 GMT

Is not always effective. Do you know just how much software they'd need to test? Many different versions of Java, Flash, etc. -- and that's just counting the "popular" software.

SCREAMING SCRIPT 

Posted Sunday 6th January 2008 16:43 GMT

Dead Vulture

javaSCRIPT is unrelated to java and never gets into the (cat-turded) sandbox.

No such thing as heuristic detection 

Posted Sunday 6th January 2008 17:29 GMT

and they copy each others signatures.

Webcast: Jumpstart your Application Security initiatives