By Sean PurdyPosted Friday 15th February 2008 10:31 GMT
"Research by Google's anti-malware team on three million unique URLs on more than 180,000 websites automatically installed malware onto vulnerable PCs."
Why is Google's research installing malware onto PCs?
By Colin WilsonPosted Friday 15th February 2008 14:06 GMT
Try reading the line again - Google aren't installing malware, they're telling you that three million unique web addresses are pushing it onto unwary users who happen to visit them.
By Ken HaganPosted Friday 15th February 2008 16:48 GMT
"Google's team also reports that two per cent of malicious websites are delivering malware via tainted banner ads. Israeli security firm Finjan has also observed a rise in the tactic over recent months, noting that many malicious ads are served from legitimate websites."
So whilst Google's research may not be to blame, at part of Google's business model *is* an offender. Call it "virus laundering" if you will. Of course, the solution is for the browser to screen out content that doesn't come from the domain in the address bar. That also punishes sites that steal bandwidth by linking to pictures on other sites, which is nice.
<- I couldn't find a picture of Sergei or Larry with horns, so this will have to do.
By StevePosted Friday 15th February 2008 17:15 GMT
IE has a history of being hammered, yet people insist on using it. I guess they get what they deserve. Check Secunia for info. Plenty good browsers out there, Opera, Konqueror, the list goes on.
By Anonymous CowardPosted Friday 15th February 2008 23:26 GMT
A War on Malware (TM).
Extrapolating the increase in infection rates of PCs and web sites leads to an unpleasant conclusion - that eventually, if strategy does not change, a critical mass will be reached where the probability of compromise to most hosts will be unacceptable and could cause firms, public organisations and individuals to significantly limit connectivity or even disconnect altogether. In such a situation, the 'internet' could ultimately be broken into a myriad of heavily throttled subnets in an attempt to prevent the worst malware from entering these 'gated community subnets'. As a result, the internet would lose much of its appeal.
So, IMHO, we need a War on Malware (TM) to prevent the internet regressing to a mid-90s level of connectivity outside of stifling 'gated community subnets'.
Of course, one might also consider that The Powers That Be (TM) arranged this predicament in the first place, to achieve control over the internet in a brazen thrust to limit 'free speech'. That most botnets send spam is not surprising when you consider that one solution to spam, already put forward, is to charge a nominal fee for e-mail (e.g. one cent) thus neatly linking each and every e-mail sent to a credit card or charge account and therefore to the sender's real identity.
By Andrew NortonPosted Saturday 16th February 2008 01:30 GMT
i just turned on my 'staysecure' widget for Opera - It gives a tiny little window that shows the current unpatched vulns for IE, FireFox, Opera, Safari and Konqueror through secunia
Safari and FireFox are showing 2 bars (less critical) with 3 and 4 holes respectively, whislt IE and konqueror have 3 bars (moderately critical) with 7 and 2 holes.
opera meanwhile, as usual has none... Guess which one is the smart choice.
By zombiniPosted Monday 18th February 2008 08:30 GMT
Norton Antivirus signatures may be slow, but the Browser Defender signatures and the feature in general are excellent. I've yet to see it let something through. Kaspersky lets quite a few exploits through since they trigger on the shell code which is easily polymorhped or some strings in the HTML/Jscript which is easily obfuscated without using a document.write (which btw they hook). Kaspersky sucks.
By lee daviesPosted Monday 18th February 2008 09:24 GMT
Given the demands on Browsers to provide better multimedia and interactivity, browsers attract more holes than ever before. AJAX exploits have only just begun as well, for all browser variants.
I disagree with Zombini though (sorry), personally I have had to force remove spyware from 3-4 Norton PC's (Smitfraud, trojans, etc), I installed Comodo instead and the users have had no problems.
Comments on: Web browsers on the front line of exploitation
Malware #
By Sean Purdy Posted Friday 15th February 2008 10:31 GMT
RE: Malware #
By Ben Schofield Posted Friday 15th February 2008 11:37 GMT
RE: Malware #
By Colin Wilson Posted Friday 15th February 2008 14:06 GMT
Re: Malware #
By Ken Hagan Posted Friday 15th February 2008 16:41 GMT
Syntax aside... #
By Ken Hagan Posted Friday 15th February 2008 16:48 GMT
use a better browser #
By Steve Posted Friday 15th February 2008 17:15 GMT
What we need is ... #
By Anonymous Coward Posted Friday 15th February 2008 23:26 GMT
@What we need is ... #
By BitTwister Posted Saturday 16th February 2008 00:21 GMT
@steve #
By Andrew Norton Posted Saturday 16th February 2008 01:30 GMT
Browser Defender in NIS2008 is excellent #
By zombini Posted Monday 18th February 2008 08:30 GMT
urgh #
By lee davies Posted Monday 18th February 2008 09:24 GMT