ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/registration.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    PDF and Flash files under threat from cryptic code

Disguised or hard to understand code is become more of a threat to Web 2.0 websites as criminals taking advantage of JavaScript.

By Asavin Wattanajantra, 24 Sep 2008 at 11:29

PDF and Flash files are under attack by criminals using ‘code obfuscation’ and the latest Web 2.0 techniques, according to a report by Finjan.

The new report claimed that malicious ‘obfuscated code’ - meaning source code or intermediate code which is very hard to read or understand - has now evolved into a serious threat.

It looked at examples where obfuscated code had not only been embedded in HTML web pages on legitimate websites, but also in rich-content files thanks to the use of JavaScript.

“Since JavaScript is the most-used scripting language for communication with web browsers, third-party applications such as Flash players, PDF readers and other multimedia applications have added support for JavaScript as part of their application,” said Yuval Ben-Itzhak, chief technology officer of Finjan.

Ben-Itzhak said this offered crimeware authors ways to inject malicious code into rich-content files used by ads and user-generated content for Web 2.0 websites.

Obfuscated code has been around a while; it has been reportedly been used since 2005 as a weapon for propagating malicious code. It was able to bypass the traditional signature-based solutions which had been used by security vendors.

Finjan claimed code obfuscation utilities and other encoding methods allowed cybercriminals to plant ‘invisible’ malicious code, which infected a user’s machine every time they visited the malicious site.

Last year IT PRO looked at the threat provided by ‘dynamic code obfuscation’.

Email to a friend

Print this page

Social Bookmark this article: What is this?

Be the first to comment on this article

You need to Login or Register to comment.

advertisement
advertisement

    Latest News Videos in Security

    White papers

Want more background on today's hottest IT trends?

Visit IT PRO's white paper library for more on virtualisation, encryption and other topics.

    Register for IT PRO

You'll get exclusive member benefits including free white papers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Advertisement