4 ms·
I'm a little confused how a webpage can infect a machine with malware? Is this typically through Java Applets/other plugins?
by Jamie452 13y ago
I'm a little confused how a webpage can infect a machine with malware?
Is this typically through Java Applets/other plugins?
- yaur 13y agoOn a mainstream site like wired its almost always flash ads. It can also be jpegs (see http://www.checkpoint.com/defense/advisories/public/2004/cpai-2004-42.html http://www.checkpoint.com/defense/advisories/public/2004/cpa...) but this is rare/patched.
- emeraldd 13y agoTake a look at http://en.wikipedia.org/wiki/Drive-by_download http://en.wikipedia.org/wiki/Drive-by_download There are in number of ways for nasty things to happen just by visiting a page.
- barkingcat 13y agohaving hacked websites serve infected or specially crafted files that exploit 0 day bugs is a very common vector actually. like 0 day PDF reader bugs - they spread by being linked to in phishing emails for example. people click on them and boom they load a bad PDF and are drive by infected. specially crafted jpgs and gifs have also been used to exploit overflows in image handling code.
- zurn 13y agoExploiting programming errors in the browser is one way. Because browsers are written in very unsafe programming languages (C++), bugs are regularly exploitable so that by specially crafting the bug-triggering input data they can be fooled to scribble content-controlled data inside the browser's memory space. For example, a memory handling bug might let the page overwrite some of the browser's code with data coming from the web page. This lets the web page break into your computer, running arbitrary code of its choosing on your box. Browser plugins can be similarly targeted instead of the browser itself.
- shortstuffsushi 13y agoWhile some of the vectors you've mentioned could potentially be exploitable, blaming a "very unsafe programming language," isn't really a good explanation. These issues could occur in any program and any programming language -- it's not a problem specific to C languages.
- comex 13y agoMost(?) browser vulnerabilities are caused by errors in C++ code which would not be exploitable in memory safe languages. One of the goals of Mozilla's Servo is to write a browser that's memory safe without compromising performance.
- shortstuffsushi 13y agoI think Servo's "safety" is ultimately due to the fact that it's built on Rust. Rust, however, seems to be ultimately built on C, unless I'm mistaken (having a hard time telling by briefly glancing through their Github, but it looks that way). My point was that it's not a C specific problem, though. Most browsers are in fact built on C, I agree. This is due primarily to the speed and performance of the language that is harder to reach with other languages. It is definitely a more difficult language to write, as it is much more "raw," but that doesn't make it inherently unsafe to use, or any more unsafe than other languages.
- chromatic 13y agoRust is self-hosted, so the compiler's written in Rust.
- shortstuffsushi 13y agoCare to comment down voters? If you're voting because of my rust comment, maybe read the part where I said "not sure, haven't read much about it." If you vote because you think C is unsafe, carry on. You're wrong, though.
- 13y ago