Jamie Oliver's Website Serving Malware
jones_supa writes While routinely checking the latest exploited websites, Malwarebytes came across a strange infection pattern that seemed to start from the official site of British chef Jamie Oliver. Contrary to most web-borne exploits we see lately, this one was not the result of malicious advertising but rather carefully placed malicious JavaScript injection in the site itself. This, in turn, has been used to serve visitors a delicious meal consisting an exploit kit downloading the Dorkbot trojan. Malwarebytes has contacted the administrators immediately upon discovery of this infection.
Ah, yes, that gospel of truth, The Daily Mail.
http://www.thetimes.co.uk/tto/...
http://www.independent.co.uk/n...
http://www.telegraph.co.uk/foo...
http://www.standard.co.uk/news...
http://www.theguardian.com/lif...
http://www.news.com.au/enterta...
I gave up with the idea of an useful sig...
Your post is a hot mess.
So, you want Javascript to be secure, but not allow the user downloading it to be able to see what they are running? Do you even understand how Javascript works in a browser beyond "hitting F12?" For the love of WTF, they are not "seeing the Javascript on your site", you are letting them DOWNLOAD the Javascript to their computer and then run it.
How, precisely, do you expect an interpreted text file to be hidden from a web browser that downloads and executes an interpreted text file? And more importantly, WHY would a browser want to let you do that, unless to obscure what you are trying to run on a user's computer?!?
The sum total of Javascript exploits is a browser that allows Javascript exploits. If they were implemented correctly there would be no problem.
Oh and I even have a car analogy: the GPS guidance system [JS] in your car [OS] has no much power - it cannot impact directly your speed, wheel direction, breaks, etc... However if someone happens to inject some code into your GPS, and have it give wrong directions, your car is still not directly impacted by that hacking. However, the system may change your itinerary and guide you to a dangerous place you were not supposed to go would the GPS work normally.
Slashdot, fix the reply notifications... You won't get away with it...
Browser Javascript is already limited in what it can do and access.
And in this case even if you had NoScript installed (which is different from turning Javascript off entirely in your browser) and the main Jamie Oliver website whitelisted you'd still have been protected because what the JS was doing was creating an iframe to another site and loading Flash/Silverlight/Java exploits inside of that.
And note that even with a compromised site where they were able to inject their own JS that they still had to rely on Flash/Silverlight/Java rather than just Javascript to download and run the trojan.
So to answer your question: No, Javascript isn't really dangerous. Poorly written browser plugins are.
Jamie Oliver's butcher's forced to close after hygiene inspection
Key bits from the article: "the score for the January 8 inspection is listed as of 1 out of five with the comment: 'major improvement necessary'." and "one of only 19 out of 1,659 food outlets in the City to receive an 'A hazardous' rating".
This sounds pretty damning and pretty embarrassing. That said, there are some odd things. One of the complaints was mold on aging beef, but - depending on what you are doing - mold is part-and-parcel of the process (and the butchery claims that this was the case). Another funny point: the butchery voluntarily closed following the inspection to fix the issues mentioned. It reopened "several hours" later. If the issues could be fixed in a few hours, they were pretty much cosmetic problems.
So what to think? I figure it's 50/50 whether there were real problems, or whether this was a politically motivated inspection. Or maybe the inspector didn't get his free steak.
Enjoy life! This is not a dress rehearsal.
No, what's dangerous is software that doesn't silently auto update.
JavaScript vs Java vs ActionScript is largely irrelevant. Web browsers routinely ship fixes for dozens of JS sandbox escapes in every update they release. Web sandboxes aren't made of magic that is unavailable to other technologies. The reason most exploit kits still target Flash and Java is that modern web browsers keep themselves up to date a lot more aggressively than those plugins do/did - typically not asking for permission any more. If you dig in you'll usually find these exploit kits are exploiting bugs that were found and patched years ago. But they still work because some non-trivial fraction of the userbase always dismisses auto update requests.
In case you don't believe me, consider that in 2014 Java had no zero day exploits at all. But some people are still vulnerable to bugs from 2012. The ask forgiveness not permission auto update policy was pioneered by Google and unfortunately took a long time to become accepted as the standard due to the old mindset, especially amongst tech geeks, of "my computer is my castle".
Great, no support for Mac and Linux. Again.
Get free satoshi (Bitcoin) and Dogecoins