Most Popular Stories
- A 'mobile help desk' in every pocket, from Salesforce.com
- Apple co-founder Wozniak sings Android's praises
- Four ways to better manage IT sales calls
- Section 508 web accessibility rule to change
- Survey finds many users blow by SharePoint security
- How hackers can eavesdrop on prevalent videoconferencing systems
Events
- CIO Healthcare Summit
March 11-14 — Scottsdale, AZ - Gartner CIO Leadership Forum 2012
March 25-27 — Scottsdale, AZ - Ready to meet the next-generation of business?
March 4-6 2012 — San Francisco, CA - The AIIM Conference 2012
March 20-22, 2012 — San Francisco, CA
Sponsored Links
Free Newsletter
HOT TOPICS >> The tech world's top flops and fiascos of 2011 | Top 8 features in Windows 8 | Paul's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Five Tips to Get IT Auditors Off Your Back
- Reporting 2.0 – The next evolutionary step in web based business reporting
- The Shortcut Guide to Secure, Managed File Transfer
- Case Study: ABBYY FineReader® Engine Drives Demand for ECM Software Leader
- The E-discovery Toolbox: What you should look for in a unified e-discovery solution
Researchers hijack computer software update process
An Israeli security firm has found a new vector with which to attack computers on the network. The researchers from Radware did this by targeting the increasingly common process where computer software automatically obtains software patches or updates via the Internet.
They have released a tool called Ippon to do the hijacking, and it works by responding to an update request before the legitimate application update server. In this manner, a malware executable could potentially be downloaded and executed without the user being any wiser. Team leader Itzik Kotler noted that about 100 different applications can be targeted.
This threat vector is particularly potent due to the number of applications that automatically poll for updates from the Internet. In fact, a number of them do not even offer the option to disable automatic updates.
Fortunately, Microsoft's Windows Update is not vulnerable due to the fact that it uses digital certificates. Ultimately, the problem can be nullified with the use of proper authentication methods. For now though, it is an additional step and it will be some time yet before most developers start to incorporate it into their applications. As such, it makes sense to avoid applications that do not use digital certificates and do not have the option to disable automatic updates.
For more on this story:
- check out this article at ZDNet
Related Articles:
Are software maintenance fees worth it?
Microsoft to test Windows 7 auto-update feature
Windows 7 released to manufacturing
Related Stories
- Microsoft addresses many bugs in this month's Patch Tuesday
- Patch Tuesday: Two's company
- Patch Tuesday fixes Word, Outlook, IE
- Microsoft releases Windows XP SP3 beta
- Vista SP1 beta gets reviewed
- Microsoft releases five Vista updates
- Vista SP1 to arrive in Q1 2008
- Patch Tuesday brings critical IE, Windows fixes
- Windows XP SP3 in testing, coming in early 2008
- Vista not-quite-SP1 service packs officially released
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




