PDA

View Full Version : Imagine: Java Evil: from Giorgio Maone


Longboard
August 8th, 2007, 11:42 PM
Hmm:
{QUOTE-> Imagine you’re a web advertiser.
Imagine you can open a popup window from a web page defeating any popup blocker.
Imagine this popup can invade the whole desktop, full screen.
Imagine this popup has no title bar, no menus, no toolbar, no location bar, no border and no buttons. No mean to close it.
Imagine user can’t move or minimize this popup. It will go away only when the browser is killed or your show is done…

Now imagine you’re a phisher.
Imagine you can use this almighty popup to draw anything you want. A fake browser or — why not? — a whole fake desktop to collect user’s data. <-QUOTE}:ouch:

http://hackademix.net/2007/08/07/java-evil-popups/
Get FF, get NoScript

lu_chin
August 9th, 2007, 12:32 AM
I guess there is always the PC 3-finger salute, i.e. <control-alt-delete> :D

WSFuser
August 9th, 2007, 12:47 AM
Im safe with NoScript, but without it I can just use Alt+F4 or Ctrl+W to close the offending pop-up.

Mrkvonic
August 9th, 2007, 01:46 AM
Hello,
Since I come across java applets once in never, I see no reason why use java. On the few rare occasions when I might need it, there's VM.
Mrk

Rasheed187
August 13th, 2007, 02:59 PM
I´m not using Java either, I hate it! :gack: