3 ms·
It seems to imply that once the link is clicked it downloads and runs the payload automatically, but this is rather hard to believe (I would guess that there is
by seles 16y ago
It seems to imply that once the link is clicked it downloads and runs the payload automatically, but this is rather hard to believe (I would guess that there is some user action required).
Is the article correct?
- InclinedPlane 16y agoDrive by download & execute vulnerabilities exist in Java for many browsers. So yes, it is possible for the "trojan" to work as described.
- bradleyland 16y agoIf "as described" includes running automatically (without user permission), then you'd be incorrect in this case. This particular trojan doesn't include any privilege escalation exploits, so the user must confirm a couple of security dialog boxes (including keying their password) before the trojan can install.
- rexyo 16y agoThis is not entirely true. There will be only 1 popup asking the user's permission to "run" java code through the browser. After that, the applet can download anything on the box it needs and execute it. The applet has full access to the local filesystem with the same priviliges the original user has. If needed the hackers can further exploit the machine, by escalating user priviliges with some corrupt scripting.. One click is enough to seriously damage your machine, be careful;) This is what the popup looks like in Firefox http://www.ussu.ca/studentgroups/JavaApplet.jpg http://www.ussu.ca/studentgroups/JavaApplet.jpg
- msbarnett 16y agoUser action is required; the applet needs permission to get outside of its sandbox, so a standard "This applet wants permission to access your computer and data, Approve or Deny?" dialogue is presented.