Microsoft Outlook Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, 23 June 2009

Could "Opera Unite" be a Botmaster's best friend?

Posted on 11:33 by Unknown
By Michael Smith (Veshengro)

Now this is about all we needed...

Opera has added a lot of cool new features to its upcoming Opera 10 browser. One of them, however, is almost certainly going to catch the eye of cyber criminals.

That feature is called “Opera Unite”, and while Opera promotes it as an exciting new platform for next-generation Web development, some security experts say it could become the botmaster's best friend.

“Opera Unite” allows anyone run a Web server from their desktop. The browser connects to an Opera proxy server, which in turn then allows the browser to serve content to the rest of the Internet. This simplifies things for home users who want to host their own Web pages; with Opera's architecture, they don't have to configure firewalls or worry about their Internet service providers blocking Web server traffic.

But it also makes a precious resource more readily available to the bad guys.

In recent years, hacked Web sites have become the fastest-growing way for criminals to spread their malicious software. They have developed automated Web-hacking code, such as the recently reported Gumblar program, that can quickly hack into tens of thousands of Web pages in just a short period of time.

With “Opera Unite”, those selfsame cyber criminals may suddenly have a whole new crop of computers to attack.

“Unite” was just introduced as part of the Opera 10 beta this month, but it is only a matter of time until the criminals start playing with it, according to Don Jackson, a researcher with SecureWorks. "Bad guys always need Web servers," he said. "Anything that runs a Web server is prone to attack."

Because “Opera Unite” runs on the desktop, it may be easier to hack than most Web servers. "In this case it's a little worse, because instead of a machine that's managed in a data center, you may have someone on a machine in a hotel network that has no firewall on it," Jackson said.

Opera attack code is already included in the majority of browser attack tools that Jackson has studied. With “Unite”, he expects the hackers who write browser attack software to pay even more attention to Opera. "I think there will be a push to keep your exploit kit in marketable condition by developing exploits for Opera 10," he said.

Opera says it will monitor sites for malicious or inappropriate content, but Jackson says it will prove extremely difficult to police content that's being served by smart hackers. They may, for example, send Opera sanitized versions of their Web pages and reserve the malicious stuff for all other visitors.

Botmasters might start using Unite as a platform for saving data, or for running the command-and-control servers that are the brains of their networks of hacked computers, Jackson said.

Opera claims that it runs “Unite” within a "sandboxed" environment, which should make it hard for people to jump from “Unite” into other parts of the PC's file system, but the company doesn't say what steps it's taking to prevent hacked PCs from misusing the service.

Do we really need any more problems and make it easier for the cyber criminals? I think I shall stick with Firefox for it is I who then can control the add ons.

While such bells and whistles that are added to some browsers now by default that are supposed to make things so much better for the user are, in fact, dangerous additions that could make it easier for cyber criminals to either use PCs as bots or, probably worse still, to gain access to personal or business information.

Sometimes the good old adage of “if it ain't broken don't fix it” is still a good one.

© 2009
<>
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Open Source Software in Business & Government
    by Michael Smith (Veshengro) Lots of Open Source in use in mainland Europe, including EU member states, very little in the UK and less still...
  • Infosecurity Europe 2011 Hall of Fame nominations now open
    London UK, February  2011 – The time is ripe to elevate the greatest movers and shakers in the world of information security as nominations ...
  • Tufin unveils new functionality & updated PCI DSS 2.0 compliance reporting
    TUFIN TECHNOLOGIES UNVEILS enhanced firewall operations management functionality and UPDATEd pci dss 2.0 compliance reporting New Perm...
  • Web 2.0 services are the next security hurdle says 360°IT – The IT Infrastructure Event
    Planning is are now well under way for the first 360°IT – The IT Infrastructure Event, due to take place at London's Earls Court this co...
  • Safer Internet Day - The role of Security within Social Networks
    Amichai Shulman – CTO and co-founder of Imperva Last week researchers unveiled a “ dating database ” consisting of 250,000 users. This was...
  • ISACA’s EuroCACS Examines Data Protection, Cloud Computing and Social Networking
    ISACA’s EuroCACS Examines Data Protection, Cloud Computing and Social Networking 20-23 March 2011, Manchester, UK Rolling Meadows, IL,...
  • Experts warn about risks of multi-tasking on new iPhone 4.0 OS
    Fortify Software warns companies to beware multi-tasking aspects of new iPhone 4.0 operating system Following a rash of news reports about...
  • Experts says trashed hard drive fiasco at Pfizer could have been avoided with Encryption
    Credant says trashed hard drive at Pfizer would not have happened if data had been encrypted Credant Technologies says that a security gaffe...
  • IT services provider, FORT, brings AVG to Irish market
    by Michael Smith (Veshengro) ISP customers to benefit from complete Internet security solution London, UK – AVG, the world’s most downloaded...
  • Lieberman Software and Q1 Labs Partner to stop insider threats
    Joins Q1 Labs Security Intelligence Partner Program London – February 1, 2011 Organisations seeking to eliminate the potential for anony...

Categories

  • ASUS
  • AVG Link Scanner
  • BeCrypt
  • book review
  • Brocade
  • Codenomicon
  • Columbian USB stick loss
  • computer recycling
  • Conficker worm
  • Credant Technologies
  • cyber crime
  • Cyber-Ark
  • Cyber-Ark®
  • Data Center
  • data encryption
  • DeviceLock
  • Digital Pathways
  • diskGenie
  • Eclypt
  • Eee PC
  • Eee PC Seashell 1008HA
  • F5 Networks
  • Facebook
  • Finjan
  • Finjan Inc.
  • Finjan MCRC
  • Firewall Management
  • Fortify
  • Fortify 360
  • Fortify Software
  • Fortify® Software
  • gadgets
  • Google
  • Google Chrome
  • green computing
  • green IT
  • IBM
  • Infosec
  • Infosec Europe 2009
  • Infosecurity Adviser
  • Infosecurity Europe
  • Infosecurity Europe 2009
  • Internet privacy
  • iStorage
  • iStorage diskGenie
  • iStorage Ltd.
  • Juniper Networks
  • Lakeland
  • Lapdesk
  • LLC
  • Logitech
  • malware
  • ManageEngine
  • McAfee International Ltd
  • MI6
  • MI6 data loss
  • Microsoft
  • MiFi™ 2352
  • Mio
  • Mobile Broadband
  • MS Office
  • National Cybersecurity Advisor
  • Navman
  • Navman Spirit
  • Netac
  • Novatel
  • Novatel Wireless Intelligent Mobile Hotspot 2352
  • OneClick IntelliPanel Desktop
  • online social media
  • open source
  • OpenOffice.org
  • Optenet
  • Origin Data Locker
  • Origin Storage
  • PNDs
  • product review
  • Red
  • SaaS
  • Sat Nav
  • saving energy
  • Security
  • Shavlik Technologies
  • SIS
  • spam
  • Stonewood Group
  • Storage Area Networks
  • Storage Expo
  • Storage Expo 2009
  • Sun Microsystems
  • Swine Flu
  • Syphan Technologies
  • Throwing Sheep in the Boardroom
  • Tufin Technologies
  • Twitter
  • U256
  • Unisys Security Index
  • USB drives
  • Vektor
  • VisionRacer
  • VisionRacer VR3
  • VMware
  • Weast
  • Web Apps Security
  • WebFilter PC Solution
  • WebSpy
  • XSS-driven attacks

Blog Archive

  • ►  2012 (1)
    • ►  January (1)
  • ►  2011 (67)
    • ►  December (1)
    • ►  April (1)
    • ►  March (14)
    • ►  February (30)
    • ►  January (21)
  • ►  2010 (192)
    • ►  December (20)
    • ►  November (22)
    • ►  October (19)
    • ►  September (5)
    • ►  August (8)
    • ►  July (5)
    • ►  June (22)
    • ►  May (13)
    • ►  April (11)
    • ►  March (13)
    • ►  February (27)
    • ►  January (27)
  • ▼  2009 (240)
    • ►  December (25)
    • ►  November (9)
    • ►  October (21)
    • ►  September (19)
    • ►  August (30)
    • ►  July (35)
    • ▼  June (30)
      • Fortify Software to Collaborate with HP on Applica...
      • Say Hello to Vid: Logitech Introduces Simpler, Str...
      • Bull equips several French Ministries with globull...
      • Survey reveals 20% of IT Cheat on Audits to get th...
      • Finjan’s Research Unveils Botnet Trading Platform ...
      • ASUS Post-Computex 2009 Press Event & Product Launch
      • Finjan’s Research Unveils Botnet Trading Platform ...
      • ISACA Commends EC Plans for Tougher Cybercrime Leg...
      • Terrorists' latest way of information sharing
      • IRONKEY Hardware encrypted USB Device – Product Re...
      • Could "Opera Unite" be a Botmaster's best friend?
      • Kingston Technology First to Market with a Massive...
      • The Sky’s the Limit: Logitech Introduces Its First...
      • Oh Great! Hackers offer T-Mobile data to highest b...
      • ASUS Eee PC: Best Low Power Solution for Developin...
      • Experts say East European ATM sniffing down to poo...
      • SACA Praises Change Your Password Day
      • Low bit levels could compromise encryption
      • Download Your Software instead getting on disc
      • ASUS Eee PC™ T91: A Head-Spinning Nice Touch
      • IT experts say 109,000 pension holder data loss ea...
      • Kingston Technology Launches Fully Compatible Secu...
      • A Help Button Needed on Every Website According to...
      • Twitter's scareware distribution attack signals a ...
      • Experts recommend preparing for withdrawal of Offi...
      • IT services provider, FORT, brings AVG to Irish ma...
      • 3ami MAS v7 bridges the USB data loss gap
      • Experts warn firms for code audit as Windows XP en...
      • 73% of companies believe they are vulnerable to ha...
      • Infosecurity Adviser applauds forensics lab traini...
    • ►  May (21)
    • ►  April (42)
    • ►  March (8)
Powered by Blogger.

About Me

Unknown
View my complete profile