Slashdot is powered by your submissions, so send in your scoop

 



Forgot your password?
typodupeerror
×

Comment Re:What the fuck (Score 1) 192

Drive-by downloads are not typically downloaded by your browser (except in the case of exploits targeting vulnerabilities in the browser itself). They are usually downloaded by browser plugins (such as Flash, Adobe Reader, various ActiveX controls, etc.) that contain vulnerabilities that are exploited (either via JavaScript or by specially crafted media files), and the payload of the exploit (the "shellcode") downloads and executes some Trojan EXE. It has absolutely nothing to do with downloads that are initiated by your browser via Java Script (which must always be authorized by the user in all major browsers, generally via a Save/Open/Cancel dialog).

Comment Re:AV Detection (Score 2, Informative) 186

according to TFA:

Malware description

Threatname: Backdoor.Win32.Buzus.croo

Aliases: Trojan-PWS.Win32.Lmir (Ikarus, a-squared); TR/Hijacker.Gen (AntiVir); Trojan/Win32.Buzus.gen (Antiy-AVL); W32/Agent.S.gen!Eldorado (F-Prot, Authentium); Win32:Rootkit-gen (Avast); Generic15.CBGO (AVG); Trojan.Generic.2823971 (BitDefender, GData); Trojan.Buzus.croo (Kaspersky, QuickHeal); Trojan.NtRootKit.2909 (DrWeb); Trj/Buzus.AH (Panda).

That's the trojan that's being installed by the exploits served up by the injected IFRAME. It is not the vulnerability that is allowing the IFRAME to be injected to begin with.

Comment Re:Too small a staff (Score 1) 226

ISP contacts customer, says "you appear to have a virus that is doing bad things on the network. Please fix it." or pops a web page with the same message and probably a link to an antivirus solution.

Popping up a web page would be an extraordinarily bad idea, given how many popup/banner ads, malicious web pages, and adware are already out there selling fake antivirus software.

Comment Re:bullshit (Score 1) 438

They can define the term "bit" to mean whatever they want for that legal document. However, if they make any promises about bandwidth, the same definitions apply. So, if, for example, they are guaranteeing you 10 megabits/second bandwidth, that had better mean you can download a 100MB file in 10 seconds.

Comment Re:What do you mean? (Score 4, Interesting) 172

Less than a minute? Wow! That's almost as fast as the four seconds it takes in my browser!

I've always been fascinated by the fact that disabling scripting in FireFox requires a plugin. In Opera, all you do is click a checkbox in a drop-down menu (or to do it per-site, a checkbox in a dialog window). The same goes for enabling/disabling plugins, applets, sound, cookies, animated images, popups (actually a set of radio buttons and not a checkbox), proxy servers, and sending referer information. It seems to me to be an excessive amount of work to have to install additional software just to get basic security features.

And yes, I'm an Opera fanboy. ;-)

Slashdot Top Deals

The hardest part of climbing the ladder of success is getting through the crowd at the bottom.

Working...