Feeds:
Posts
Comments

Posts Tagged ‘JavaScript’


Muammar al-Gaddafi

Image via Wikipedia

The mass pro-Gaddafi street demonstration of one million Libyans held in the capital Tripoli has gone unreported by Western media as has news of civilians killed for the past three months.

CONTINUED HERE

Read Full Post »


Image representing Alexa as depicted in CrunchBase

Image via CrunchBase

Boffins from Southern California have caught YouPorn.com and 45 other sites pilfering visitors’ surfing habits in what is believed to be the first study to measure in-the-wild exploits of a decade-old browser vulnerability.

YouPorn, which fancies itself the YouTube of smut, uses JavaScript to detect whether visitors have recently browsed to PornHub.com, tube8.com and 21 other sites, according to the study. It tracked the 50,000 most popular websites and found a total of 46 other offenders, including news sites charter.net and newsmax.com, finance site morningstar.com and sports site espnf1.com.

“We found that several popular sites – including an Alexa global top-100 site – make use of history sniffing to exfiltrate information about users’ browsing history, and, in some cases, do so in an obfuscated manner to avoid easy detection,” the report states. “While researchers have known about the possibility of such attacks, hitherto it was not known how prevalent they are in real, popular websites.”

To cover its tracks, YouPorn encodes its JavaScript to hide the sites it searches for and decodes it only when used. Other websites dynamically generate the snoop code to prevent detection by simple inspection. Still others rely on third-party history-stealing libraries from services that include interclick.com and meaningtool.com.

CONTINUED HERE

Read Full Post »


Facebook logo

Image via Wikipedia

Facebook is littered with a worm, seemingly the same one under different names, created by randomly generated developers, which is spreading links all over the site.

Applications like S22BZ5 created by randomly assigned pseudonym ‘Jackson Lasseter’ has nearly 300 people under the grips of the worm. Others, such as replicated application B5DA8G9IHJ35 and AU0ZVEhave just under 1,000 people inadvertently spreading the worm.

Just in the last 24 hours, I have seen my own friends’ list infiltrated by these worm applications which set status messages via the application without the knowledge of the profile owner, through a shortened link service with an infected GIF file.

A quick Facebook search for ‘tiny.cc‘ and ‘is.gd‘, two link shortening services, shows a great deal of worry and concern over

Read Full Post »


Image representing Twitter as depicted in Crun...

Image via CrunchBase

Malicious code is being inserted into hundreds of Twitter feeds. And if you visit the Twitter.com site today, you could easily spread the malicious code yourself.

If your mouse simply passes over the link, it triggers a JavaScript code which automatically retweets the link to all of your followers. In addition, it “grays out” your entire home page, so your mouse is also prevented from clicking the link to “undo” that retweet. Hundreds of pages now contain the tweet with the malicious code. And below it, Twitter’s standard text for a massively popular update: “Retweeted by yourself and 100+ others…”

CONTINUED HERE

Read Full Post »

Follow

Get every new post delivered to your Inbox.

Join 589 other followers

%d bloggers like this: