SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Government >> Policy

System vulnerabilities being sold in online auctions

System vulnerabilities being sold in online auctions

By:  Nestor E Arellano  On: 12 Jul 2006 For: IT World Canada Creator

Online scammers turned entrepreneurs have found a new commodity to auction off: system and software vulnerabilities.

As part of a court-ordered settlement, SonyBMG was recently directed to compensate consumers who purchased Sony audio CDs that installed a rootkit when they were played on a PC. The compensation amounts to US$7.50 and a free album download from Sony’s catalogue for each CD purchased.

"What is common to all these threats is that they are driven by active content (such as Java Script, VB Script, ActiveX, or Java Applets)--those same technologies that enable users to browse Web sites and run common business applications," the study said.

Yuval Ben-Itzhak, chief technology officer of Finjan said a great deal of malicious code is able to bypass traditional anti-virus and anti-spam software in the market today because these products are signature-based.

"These software products search for virus signatures. But if a virus is new or unknown, the software will not be able to recognize it."

Ben-Itzhak said Finjan software blocks malicious code based on its behaviour. The moment the NG 51000 detects questionable behaviour on the part of a visited site it blocks that site.

"If a site begins installing executable cod








Sign up for our Newsletters












Print |  Views: 1616   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Nestor E Arellano Nestor E Arellano Nestor Arellano – Newswire Specialist Nestor edits and posts newswire content for ITWorldCanada’s online publications and e-newsletters. Nestor joined ITWC in 2006 as a senior writer and ... more

Related Content

Unpatched IE7 exploit imperils millions of computers
Unpatched IE7 exploit imperils millions of computersVulnerability affects computers running IE7 on Windows XP regardless of the service pack version, Windows Server 2003 running Service Pack 1 or 2, Windows Vista and Windows Vista with Service Pack 1 as well as Windows Server 2008
Canadian business coalition speaks out on copyright reform
Canadian business coalition speaks out on copyright reformThe Conservative government's long-delayed copyright reform bill has hit yet another roadblock, this time in the form of a powerful business coalition comprised of corporate giants such as Google Inc., Yahoo Inc., Rogers Communications Inc. and Telus Corp.
Online advertisers attacked by hackers
Online advertisers attacked by hackersWeb surfers could download malicious code from hacked banner ads, even if they are posted to legitimate sites. How the hacking gang uses JavaScript
Advantage Apple – Saves face with timely iPhone patch
by joaquim p. menezes - whew!  that was a close one…for apple. 
Entrust claims its SSL is secure
entrust inc. has announced its secure sockets layer certificates are not affected by a security hole discovered last month at the chaos communication congress.on dec. 30, a team of european researchers demonstrated they were able to exploit a weakness in the md
blog comments powered by Disqus