JavaScript Botnet Sheds Light On Criminal Activity
CowboyRobot writes "Informatica64, a security research group, demonstrated the use of cached JavaScript to control computers connecting to a malicious proxy. 'The researchers found a variety of low-level criminals using their proxy server: fraudsters posing as British immigration officials offering work permits in hopes of stealing money and sensitive documents from their victims; a man pretending to be a pretty woman on a number of dating sites to con victims into sending money for a plane ticket; and another fraudster selling nonexistent Yorkshire Terriers.'"
Now script this
FIRSTYYYYS
It is very likely that companies and governments are already using this technique to eavesdrop on criminal activity, Alonso said.
Really? How about them using it to eavesdrop on -everyone- regardless on if it is "criminal" or not. Plus, I'm sure governments have more invasive methods rather than just this.
Taxation is legalized theft, no more, no less.
Yep, this is proof... Javascript is a real programming language.
This is another case where you have to volunteer to run the malware, or it does nothing.
Nobody in their right mind runs javascript from random sites any more - the last 5 years should have taught that lesson. It's idiotic, and is objectively one of the biggest threat vectors out there. Of course, many people are not in their right mind, but you can't protect people against themselves if they volunteer to run malware. That's been a problem for as long as PCs have been around.
So for about the 489235th time, if you don't run javascript by default, which no one should be doing, you're fine. Time for people to start learning this lesson.
Oh, boohoo, somebody ripping off bantus and wogs who just want to show up and get on the dole? Looks like justice has been served.
The Gnome desktop versiont 3.x is implemented in Javascript, and all the crapware-plugins will be also. We need to really support a modern version of Gnome 2.x
"... and another fraudster selling nonexistent Yorkshire Terriers.'"
Bullshit. Yorkshire Terriers most certainly exist.
It shouldn't be a crime to sell non-existant Yorkies. Just think of the ensuing peace and quiet of neighbors, because the would-be purchaser no longer has the cash for a real one. That man owes society nothing. Yay, society should reward him for performing such a public service.
Isn't that what XFCE is for?
i saw the talk a def con this weekend.
one of my take ways from this talk is when certain sites such as youtube/imgur/slashdot/reddit are
black listed due to corporate IT guidelines people often go to proxies to circumvent
this. So the net effect of black listing popular sites (besides being a pain) is to make your
network less secure.
imho ... wasted banwidth is better than getting hacked.
Which browsers were affected?
Was IE9 one of them?
In IE9, for example, the sliders for filtering comments in this page don't work at all.
Well, it looks like organized crime has found its own Etsy and Craigslist. I suppose it just demonstrates how the power of just-in-time communication and office automation can be an assest, even on the black market.
If all the communication is encrypted using SSL, which not only encrypts but authenticates all data, I don't see how a poisoned javascript file can get passed to the client.
Fast Federal Court and I.T.C. updates
...for every nonexistent Yorkshire Terrier I'd had to chase out of my back garden I'd have millions.
Gnome 3 ? I wonder ... can a botnet of one really be called a botnet ?
Bad guys can run honeypots too!
http://www.footprintsecurity.com.au/ Looking for security cameras? Or a wireless spy camera? Footprint security carry Australia's largest range of Business and Home Security cameras and CCTV accessories, all supplied at wholesale prices! This website is continually being updated with new products and features. Feel free to browse our current selection of wireless spy cameras as well as surveillance security cameras and CCTV Digital Video Recorders.
Its called KDE ;)
Kde4 seems to have lost some weight, or gnome3 put masses on.
But they feel pretty much the same.
I just switched to KDE4 and i must say: wow, you can configure ANYTHING, thing is, you HAVE TO configure anything -.-
TFA says:
Alonso recommended that anyone who is using anonymous proxies or even the Tor network to only use servers that they trust.
If implemented on a server connected to via the Tor network, presumably this would gather traffic details. But would it reveal the end client IP? The Tor Project and others claim that Tor Button has now closed any known javascript vulnerabilities, so we have people (like Tails) claiming it is therefore ok to surf via tor with JS enabled. That doesn't smell right to me. What about unknown vulnerabilities anyway?
It's good that they're light on crime, but I'm not sure why anyone would build a shed for their javascript botnet.