"A researcher at Ernst and Young has developed a clever hybrid "Nate points out that this is not a Facebook-MySpace issue, it is
of a Gif image and a Java Archive that is being dubbed a GIFAR, which
could conceivably be uploaded to any site that allows file uploads and
then anyone who "viewed" it and was simultaneously logged in to their
Facebook, Myspace, or Flickr ( or Xanga! - my edit) account could have their credentials
stolen. Kudos to Nate McFeters
for discovering /demonstrating such a sophisticated attack. He is
presenting his technique at BlackHat this week (the premier computer security conference, in Las Vegas this week - my edit and emphasis) with the usual
frustrating omission of "key elements". In other words, just enough is
left out so determined hackers can figure it out but developers at
Facebook and Myspace (and Xanga! - my edit) will struggle until a working exploit is
deployed. Nate suggests that web application sites should be
filtering uploads to prevent GIFARs from getting deployed, although he
claims this will be extremely hard to do. I sure hope the content
filtering and Web Application Firewall vendors are working on simple
tools to make this possible."
true of all sites that allow image uploads. Hmm, that is ALL blogs (Xanga, too? no.... yes. -my edit).
We are talking hundreds of millions of sites. It will be a long time
(as in never) before that many sites are fixed."
Day: August 7, 2008
-
Tell Me It Ain't True, Xanga
Recent Posts
- One of the first… November 9, 2024
- I can't believe... August 27, 2016
- 8173 April 30, 2015
- In the Good Ole Xanga Daze . . . February 28, 2015
- 8165 February 21, 2015
- 8162 September 23, 2014
- 8160 July 2, 2014
- Dream better dreams, good-bye. April 25, 2014
- musical chairs April 5, 2014
- released January 4, 2014
Recent Comments