Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!


Forgot your password?
Check out the new SourceForge HTML5 internet speed test! No Flash necessary and runs on all devices. ×

Submission + - New Attack Binds Malware in Parallel to Software Downloads (threatpost.com)

msm1267 writes: Researchers from Ruhr University in Bochum, Germany, have developed a proof-of-concept attack in which they are able to inject malicious code into a download that runs in parallel to the original application, without modifying the code.

The attack targets free and open source software, in particular those where code signing verification and other integrity checks are lacking in the download process.

Rather than spike the original application with malware, the researchers use a binder that links the binder application, malware and original download.

This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.

New Attack Binds Malware in Parallel to Software Downloads

Comments Filter:

I cannot believe that God plays dice with the cosmos. -- Albert Einstein, on the randomness of quantum mechanics