PDF and Flash files under threat from cryptic code
By Asavin Wattanajantra,
PDF and Flash files are under attack by criminals using ‘code obfuscation’ and the latest Web 2.0 techniques, according to a report by Finjan.
The new report claimed that malicious ‘obfuscated code’ - meaning source code or intermediate code which is very hard to read or understand - has now evolved into a serious threat.
It looked at examples where obfuscated code had not only been embedded in HTML web pages on legitimate websites, but also in rich-content files thanks to the use of JavaScript.
“Since JavaScript is the most-used scripting language for communication with web browsers, third-party applications such as Flash players, PDF readers and other multimedia applications have added support for JavaScript as part of their application,” said Yuval Ben-Itzhak, chief technology officer of Finjan.
Ben-Itzhak said this offered crimeware authors ways to inject malicious code into rich-content files used by ads and user-generated content for Web 2.0 websites.
Obfuscated code has been around a while; it has been reportedly been used since 2005 as a weapon for propagating malicious code. It was able to bypass the traditional signature-based solutions which had been used by security vendors.
Finjan claimed code obfuscation utilities and other encoding methods allowed cybercriminals to plant ‘invisible’ malicious code, which infected a user’s machine every time they visited the malicious site.
Last year IT PRO looked at the threat provided by ‘dynamic code obfuscation’.
Related Tags
advertisement
Latest Security Features
How to be a successful online fraudster
Ever wanted to know how easy it is to be an identity thief and earn a fortune? IT PRO reveals all…
- What you need to know about ID cards
- Lessons to learn from a year of data breaches
- Q&A: DNS inventor Paul Mockapetris
- Is the password ill-equipped for the modern world?
- Why is backing up given short shrift?
- Defending Europe against cyber attack
- The present and future of IT security
- I’m an IT manager, get me out of here!
- IT around the world: Russia
Latest Security Reviews
Fortinet FortiGate-3810A
Rating: ![]()
- Clearswift MIMEsweeper Web Appliance ENW
- NetASQ U6000 UTM appliance
- AVG Internet Security SBS Edition 8.0
- Finjan Vital Security Web Appliance NG-6000S
- LogLogic MX2010
- Exclusive: WatchGuard Firebox Core X750e
- Sophos ES4000 Security Appliance
- Microsoft Forefront Security for Exchange and SharePoint
- EXCLUSIVE: Juniper Networks SSG 550 UTM appliance
advertisement
Latest News Videos in Security
Video: Eugene Kaspersky outlines security threats
IT PRO speaks to Eugene Kaspersky, chief executive and founder of Kaspersky Lab.
White papers
Want more background on today's hottest IT trends?
Visit IT PRO's white paper library for more on virtualisation, encryption and other topics.
Register for IT PRO
You'll get exclusive member benefits including free white papers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.



Social Bookmark this article: What is this?