internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Norton AntiVirus 2008

Most Popular Software Downloads
Ad-Aware 2008 Free
Windows XP Service Pack 3
Internet Explorer 7
QuickTime for Windows
Adobe Flash Player
AVG Anti-Virus Free
Paint Shop Pro
Windows Live Suite
CCleaner (Crap Cleaner)
Winamp

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Those Nifty Widgets Can Pack a Rather Rude Surprise
Desktop Widgets the Latest Target for Malware
Andy Patrizio

The latest target for the malware criminal element is those popular widget-driven applications, both desktop and browser-based, thanks to their explosion in popularity and relatively insecure model.

Security firm Finjan issued a recent report that found that widgets (or gadgets) are exposing computer users to a whole host of attacks because they were designed as these cool little innocuous applets without any real security model but have all the power of a full-blown app.

Worse, this vulnerability is not limited to Yahoo Widgets or the Windows Vista sidebar applets. Finjan also found sample exploit code to insert malicious widgets into Microsoft's Live.com and Google's iGoogle pages.

"It's an environment that's designed to look really cool and provide some basic functionality, but no one thought about basic security," said Istach Amit, director of security research at Finjan's malicious code research center. "There are inherent problems in the security model of those widget engines."

There's a lot of widgets out there. Finjan found 3,720 widgets available on Google.com, 3,197 on Apple.com, and 3,959 on Facebook.com. The companies offer their own, but they also host thousands of third-party widgets for users to install and there's no guarantee they will catch a widget with malicious code in it.

The problem is widgets are full-blown apps that the hosting environment, whether it's iGoogle or Yahoo Widgets, doesn't take into account and they should be restricted or scrutinized a lot more than they are now, said Amit. "They should not access the file system or access the network if they do not need to," he said.

Already Microsoft and Yahoo have had to make fixes to their widgets and Google is also updating its Desktop and portal pages. Microsoft had to fix the Vista Sidebar after Finjan found a vulnerability in the contacts widget. It also had to fix a problem in the RSS reader used on Live.com.

Finjan also found a problem in Yahoo Widgets Contacts and one in iGoogle that installed itself without user approval or knowledge. It could then access their contents, GMail mailbox, and browser history. Yahoo was unavailable for comment, while Google said this:

"Javascript is a supported part of Google Gadgets, which many developers use to provide unique functionality to users. We recognize the potential for misuse of this feature and we mitigate this risk by putting it in a domain of its own.

"This area of vulnerability research is a moving target and we are currently working to find innovative solutions to these problems. Google takes security issues very seriously and will respond swiftly to fix known security issues," said a Google spokesperson in a statement to InternetNews.com.

"They are fixing the vulnerability pretty quickly, but I can't say what they are doing with the security model. It's more than just fixing a widget that has been coded badly," Amit said.

It's a matter of following a World Wide Web Consortium (W3C) object model for security involving objects and widgets. Only two companies have embraced the W3C object model, according to Amit: Apple and Opera.

The Opera browser uses the W3C widget policy on security and policies. Firefox and Microsoft's Internet Explorer don't have a widget environment so there is no comparison, although in its most recent security report, Symantec found that browser plug-ins are also becoming popular malware targets.

Mac OS is more secure since it was one of the participants in the W3C committee that developed the object security recommendations and Apple's security policy is based on an Apple object model that already exists in Mac OS X.

With some malware issues, it's often a case of not opening an e-mail from an unknown source. A widget presents a much tougher proposition because it basically means not using the product altogether. But that's exactly what Amit recommends until the security model in these products improves.

"If you really don't need it, don't use it. I know it looks nifty, but you have to remember it's a full-fledged app, and like any app it does have its security problems," he said.

News courtesy of internetnews.com

September 27, 2007

View All Anti-Malware Software

View All Anti-Virus Software

Contents:
1. Desktop Widgets the Latest Target for Malware






JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
Microsoft Article: 7.0, Microsoft's Lucky Version?
Microsoft Article: Hyper-V--The Killer Feature in Windows Server 2008
Avaya Article: How to Feed Data into the Avaya Event Processor
Microsoft Article: Install What You Need with Windows Server 2008
HP eBook: Putting the Green into IT
Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
Avaya Article: Setting Up a SIP A/S Development Environment
IBM Article: How Cool Is Your Data Center?
Microsoft Article: Managing Virtual Machines with Microsoft System Center
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Video: Are Multi-core Processors Here to Stay?
On-Demand Webcast: Five Virtualization Trends to Watch
HP Video: Page Cost Calculator
Intel Video: APIs for Parallel Programming
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Sun Download: Solaris 8 Migration Assistant
Sybase Download: SQL Anywhere Developer Edition
Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
Red Gate Download: SQL Compare Pro 6
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
IBM Article: Collaborating in the High-Performance Workplace
HP Demo: StorageWorks EVA4400
Intel Featured Algorhythm: Intel Threading Building Blocks--The Pipeline Class
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES