SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Enterprise Business Applications >> Online Retailing and Ecommerce

Bloggers vulnerable to embedded malware, expert says

Bloggers vulnerable to embedded malware, expert says

By:  Eric Lai  On: 03 Aug 2006 For: Computerworld (US online) Creator

Internet users who employ Web-based services such as Bloglines or Web browsers such as Firefox to read Web site feeds and blogs are vulnerable to embedded malicious code that can install spyware, log users' passwords, scan PCs and corporate networks for open ports and more.

"It could be as simple as adding a few lines of extra code," he said. Creating this filter would not cause feeds to arrive much slower, either, he said. But as far as he knows, no blog-reading software or service re-encodes the JavaScript as he suggests to de-fang it.

In the absence of blog readers filtering their feeds, Sima recommends that CIOs and chief information security officers start treating individual PCs as potential attack points.










Sign up for our Newsletters












Print |  Views: 982   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Eric Lai Eric Lai is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

How to not have your Web site hacked like Sony's
How to not have your Web site hacked like Sony'sA SQL injection attack was used to plant malicious code on pages of two popular Sony Playstation games - SingStar Pop and God of War, reports security company Sophos. Hundreds of Web pages from other businesses have also been compromised.
Bhutto assassination brings out worst in hackers
Bhutto assassination brings out worst in hackers Malware makers exploit the breaking news about the killing of the former Pakistani prime minister by "requiring" users to download a codec before watching videos about it
IBM executive targets online criminals
IBM executive targets online criminalsKris Lamb, director of X-Force, IBM's primary security research organizaiton talks about what he sees as the most critical challenges and opportunities facing enterprise IT security managers today.
Entrust claims its SSL is secure
entrust inc. has announced its secure sockets layer certificates are not affected by a security hole discovered last month at the chaos communication congress.on dec. 30, a team of european researchers demonstrated they were able to exploit a weakness in the md
Calling all CIO bloggers
we're now ramping up the cio canada blog site, and we're looking for canadian cios to blog for us on a variety of topics of interest to it executives.each blog topic area will have at least three or four regular contributors, so it shouldn't be too much work for any individual. a new post every week or two will keep the topic updated with sufficient frequency - and posts needn't be more
blog comments powered by Disqus