Most Popular Stories
- Samsung unveils long-awaited Galaxy Tab Internet tablet
- Google Chrome 7 will come with GPU acceleration
- Apple refreshes iPod Touch, adds dual camera
- Motorola warns against downloading unofficial Android 2.2 upgrade for Droid X
- Surprising lessons from a Florida college's iPad deployment
- Samsung unveils teaser of Galaxy Tab tablet
Events
- SharePoint Technology Conference
October 20 - 22 — Boston, MA - Register for The Security Standard 2010
September 13 - 14 — New York, NY - Northwestern University Master of Science in Information Systems (MSIS)
- Register for IT Roadmap Dallas 2010
September 14 — Dallas Convention Center
Sponsored Links
HOT TOPICS >> Q2 Earnings Roundup | Cloud Computing | Tablets | Security Vulnerabilities and Exploits
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Durable Smart Devices for Mobile Field Forces: Selection and Evaluation Criteria
- The Shortcut Guide to Secure, Managed File Transfer
- Enterprise Digital Assistant Leverage in the Emerging Mobile Enterprise
- Cloud Computing: How To Make Your Own Silver Lining
- Reporting 2.0 – The next evolutionary step in web based business reporting
We never sell or give away your contact information. Our reader's trust comes first.
Researchers hijack computer software update process
An Israeli security firm has found a new vector with which to attack computers on the network. The researchers from Radware did this by targeting the increasingly common process where computer software automatically obtains software patches or updates via the Internet.
They have released a tool called Ippon to do the hijacking, and it works by responding to an update request before the legitimate application update server. In this manner, a malware executable could potentially be downloaded and executed without the user being any wiser. Team leader Itzik Kotler noted that about 100 different applications can be targeted.
This threat vector is particularly potent due to the number of applications that automatically poll for updates from the Internet. In fact, a number of them do not even offer the option to disable automatic updates.
Fortunately, Microsoft's Windows Update is not vulnerable due to the fact that it uses digital certificates. Ultimately, the problem can be nullified with the use of proper authentication methods. For now though, it is an additional step and it will be some time yet before most developers start to incorporate it into their applications. As such, it makes sense to avoid applications that do not use digital certificates and do not have the option to disable automatic updates.
For more on this story:
- check out this article at ZDNet
Related Articles:
Are software maintenance fees worth it?
Microsoft to test Windows 7 auto-update feature
Windows 7 released to manufacturing
Related Stories
- Microsoft addresses many bugs in this month's Patch Tuesday
- Windows XP SP3 available now
- Patch Tuesday: Two's company
- Patch Tuesday fixes Word, Outlook, IE
- Microsoft releases Windows XP SP3 beta
- Vista SP1 beta gets reviewed
- Microsoft releases five Vista updates
- Vista SP1 to arrive in Q1 2008
- Patch Tuesday brings critical IE, Windows fixes
- Windows XP SP3 in testing, coming in early 2008
Comments
Radware has "released" this malware? I hope the justice department reads this article. What kind of scumbag company would do this and then issue a press release bragging about it?
Post new comment
Home
| Subscribe | Advertise | RSS |
Privacy
| Site MapTHE FIERCEMARKETS NETWORKFierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceVoIP | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2010 FierceMarkets. All rights reserved. |
![]() |







