JavaScript Malware Open The Door to the Intranet 169
An anonymous reader writes "C|Net is reporting that JavaScript malware is opening the door for hackers to attack internal networks. During the Black Hat Briefings conference Jeremiah Grossman (CTO, WhiteHat Security) '...will be showing off how to get the internal IP address, how to scan internal networks, how to fingerprint and how to enter DSL routers ... As we're attacking the intranet using the browser, we're taking complete control over the browser.' According the the article, the presence of cross-site scripting vulnerabilities (XSS) dramatically increase the possible damage that can be caused. The issue also not which-browser-is-more-secure, as all major browsers are equally at risk. Grossman says 'The users really are at the mercy of the Web sites they visit. Users could turn off JavaScript, which really isn't a solution because so many Web sites rely on it.'"
JavaScript Malware Open The Door to the Intranet (Score:5, Funny)
Re:JavaScript Malware Open The Door to the Intrane (Score:5, Funny)
NCSA Mosaic avoids this problem (Score:3, Funny)
Oh well, let's prevent people doing their jobs (Score:3, Funny)
The answer with all these technologies is to get away from the "everything is permitted, everything links to everything else" model that Microsoft promoted till it ran into trouble, and work out a way of implementing security policies that are comprehensible and that work.
Re:JavaScript Malware Open The Door to the Intrane (Score:1, Funny)
Re:JavaScript Malware Open The Door to the Intrane (Score:3, Funny)