Most Popular Stories
- 3 ways for CIOs to become business leaders
- Chrome 17's new features enhance speed, security
- Spotlight: Intel launches 520 Series solid-state drive
- FBI insists cloud providers meet strict security requirements
- Bug in Trendnet webcams exposes them to public viewing
- Multiple monitors makes some multitasking faster, easier
Events
- CIO Summit
March 18- 21 — Miami, FL - Northwestern University Master's in Information Systems
- Ready to meet the next-generation of business?
March 4-6 2012 — San Francisco, CA - Customer Engagement Technology World
March 28-29, 2012 — San Francisco
Sponsored Links
Free Newsletter
HOT TOPICS >> Tech world's top flops and fiascos of 2011 | Windows 8 slideshow | Cybersecurity | Caron's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
FierceCIO provides CIOs with IT best practices, business intelligence, and forward-looking IT strategies. Join 32,000+ industry insiders who get FierceCIO twice a week via email and save time.
About | View Sample | Privacy
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Virtual Game Changer
- Because Hope Is Not A Strategy: Business Continuity/Disaster Recovery Planning
- Attracting best-in-class clients with best-in-class OCR
- Results of a Survey on DevOpsTrends
- Cloud Computing: Threat or opportunity for VARs and MSPs? Special focus on cloud collaboration and messaging
A new way to steal your online credentials
This week in Las Vegas, researchers at a computer security conference will unveil a new type of Web site file that lets users upload their own images and in the process allow intruders to circumvent security systems and take over a Web surfers' accounts.
"We've been able to come up with a Java applet that for all intents and purposes is an image," John Heasman, vice president of research at NGS Software. told Infoworld.com. He said the file looks exactly like a .gif file to the Web server. But a browser's Java virtual machine will open it as a Java Archive file and then run it as an applet, giving the attacker an opportunity to run Java code in the victim's browser.
The browser treats the malicious applet as though the Web site's developers wrote it. The attack could work on any site that allows users to upload files like Facebook, or possibly Web sites that are used to upload banking card photos. There are ways to deter this threat, and ultimately, say the researchers, browser makers will have to make some fundamental changes to their software.
For more:
- see this InfoWorld article
Related Stories
- Who's responsible for spam and malware?
- Intrusion protection: Best of breed or integrated solution?
- The Millennial generation poses a security risk at work
- Tips for keeping DDoS attacks at bay
- Q&A: Finance firm deploys message elimination system
- Avoid the pitfalls of 'empowered business-technology'
- How to secure your security budget
- Experts: RSA's data breach highlights need for companies to tighten up security
- Q&A: Indiana University's key to safeguarding confidential data
- How to know if you've been breached
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




